Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
IT Security NachrichtenKI-Agenten hebeln klassisches IT-Asset-Management aus(24.09.2026 um 07:14 Uhr)
••
IT Security NachrichtenMicrosoft erneuert Surface Pro und Laptop mit Snapdragon X2 Plus(24.09.2026 um 07:42 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/shared/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/llms/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/agents/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/core/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vcli-v3.0.65 (24.09.2026)(24.09.2026 um 07:54 Uhr)
•••
IT Security NachrichtenKI-Agenten hebeln klassisches IT-Asset-Management aus(24.09.2026 um 07:14 Uhr)
••
IT Security NachrichtenMicrosoft erneuert Surface Pro und Laptop mit Snapdragon X2 Plus(24.09.2026 um 07:42 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/shared/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/llms/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/agents/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vsdk/core/v0.0.86 (24.09.2026)(24.09.2026 um 07:43 Uhr)
•
IT Security DownloadsGitHub Release: cline/cline vcli-v3.0.65 (24.09.2026)(24.09.2026 um 07:54 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

AAMP vs AdCP: The Two Standards Stacks Racing to Define Agentic Advertising

Eighteen months ago, agent-driven ad buying was a keynote topic. Today it is two competing standards stacks with shipped software, published by two different organizations that are openly not coordinating. If you build adtech, both are…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Eighteen months ago, agent-driven ad buying was a keynote topic. Today it is two competing standards stacks with shipped software, published by two different organizations that are openly not coordinating.



If you build adtech, both are about to show up in your pipes. Here is the short version.






Stack one: IAB Tech Lab's AAMP



AAMP (Agentic Advertising Management Protocols) launched in January 2026 and hit 2.0 in June. The philosophy: build on the rails that already move money. It wires OpenRTB, AdCOM, OpenDirect, and VAST together, with MCP and Google's Agent2Agent protocol as the agent interfaces.



Version 1.0 could only transact direct deals. The 2.0 release added programmatic: a Buyer Agent SDK with a three-layer agent hierarchy (orchestration, channel specialists, functional agents), a Seller Agent SDK that turns a static media kit into a storefront that adapts pricing to the buyer, and a Deals Library as the system of record with OpenDirect 2.1 support. Approval gates and audit logs keep humans at the sign-off points.






Stack two: AAO's AdCP



The Ad Context Protocol launched in October 2025 from a consortium including Yahoo, PubMatic, Optable, Scope3, Swivel, and Triton Digital. It is now governed by AgenticAdvertising.Org (AAO), a trade association with four equally weighted voting classes: brands, agencies, publishers, and technology providers. The reference sell-side implementation lives with the Prebid community.



AdCP was designed agent-native from the start. It is built directly on MCP, runs asynchronously so humans can approve while agents negotiate, and version 3.0 (April 2026) covers the full campaign lifecycle: discovery, media buys, creative production with brand.json, governance, and reporting across 20 media channels. It is in production at Snap, Pinterest, Reddit, Netflix, and Vox Media.






The actual differences





  • Governance. Tech Lab is the incumbent that already maintains VAST and OpenRTB. AAO is a new association built specifically for agentic advertising.


  • Design center. AAMP layers agents onto existing programmatic rails. AdCP defines new MCP-native tasks first and treats legacy systems as integration targets.


  • Coverage. AAMP is deepest at the transaction layer, with ARTF agent containers running inside bidder infrastructure. AdCP is broadest across the lifecycle, planning through reporting.


  • Interfaces. Both name MCP as a core protocol. A tool exposed as an MCP server serves agents on either stack without modification.


  • Verification. Neither stack validates the creative payload. Deal state and context move between agents; the correctness of what ships is out of scope for both specs.






The layer they share



Follow a video buy through either stack and the endpoint is identical: an ad server returns VAST XML. An InLine or Wrapper, MediaFiles, Impression pixels, TrackingEvents. Twenty channels of protocol surface on one side, one XML document on the other.



That document is where delivery fails. A missing Duration, an HTTP media URL on a CTV device that requires HTTPS, a wrapper chain past the player's depth limit: none of it is visible at the protocol layer. The deal confirms cleanly, the agents log success, and the impression dies at runtime with a VAST error code nobody is watching.



Human traffickers used to be the backstop. In an agent-to-agent transaction there is no trafficker. Validation has to be a tool the agent calls before the deal confirms, not a QA pass after launch.






The practical takeaway



You do not need to bet on a winner. MCP is the shared interface: AAMP's Buyer Agent SDK accepts additional MCP tool servers, and AdCP is MCP-native end to end. Anything you expose over MCP works in both stacks today.



That is how we ship vastlint: 187 rules grounded in the IAB VAST, OMID, and SIMID specs, deterministic JSON output, available as a hosted MCP endpoint, CLI, and libraries. Point either stack's agent at it and gate deal confirmation on a clean tag.



The protocols will keep changing. The payload has been VAST for two decades and will still be VAST when the governance questions settle.



The full comparison, with sources, is on the vastlint blog: AAMP vs AdCP: What IAB Tech Lab and AAO Are Each Building for Agentic Advertising.

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - AAMP vs AdCP: The Two Standards Stacks Racing to Define Agentic Advertising
id: 3e7cce06-5c6e-49d7-a3b2-f3c1a9d6ba14
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "AAMP vs AdCP: The Two Standard" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich AAMP vs AdCP: The Two Standards Stacks R.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten AAMP vs AdCP: The Two Standards Stacks Racing to Define Agentic Advertising

Thematisch verwandte Begriffe: AAMP, AdCP, Standards, Stacks · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick