#TechZine
Techzine (EU) sat down with Sander Almekinders and Pega CTO Don Schuerman live at PegaWorld.
#Pega

http://my.sociabble.com/5ufByDrfoB9Z
October 1, 2026 at 4:54 PM
AMD acquires ‘spatial intelligence’ company World Labs for 8.2 billion – Techzine Global

AMD acquires 'spatial intelligence' company World Labs for 8.2 billion - Techzine Global The acquisition is intended to give AMD greater insight into the ... While generative AI initially focused primarily on…
AMD acquires ‘spatial intelligence’ company World Labs for 8.2 billion – Techzine Global
AMD acquires 'spatial intelligence' company World Labs for 8.2 billion - Techzine Global The acquisition is intended to give AMD greater insight into the ... While generative AI initially focused primarily on training and running ...
drwebdomain.blog
September 29, 2026 at 4:50 PM
🚀 ServiceNow patches four vulnerabilities in the Now Platform and AI Platform - Techzine Global

ServiceNow patches four vulnerabilities in the Now Platform and AI Platform Techzine Global

https://tinyurl.com/22lzhfao #ServiceNow #ITSM #CrustyTLDR
August 28, 2026 at 2:03 PM
NVIDIA Cosmos 3 Edge Brings Physical AI Reasoning to Jetson
quasa.io/media/nvidia...

#NVIDIA
Sources: Quasa Media, Huggingface, Github, Techzine
Writer: Slava Vasipenok
NVIDIA Cosmos 3 Edge: 4B Model for On-Device Robotics
A practical guide to NVIDIA Cosmos 3 Edge: its 4B architecture, Jetson deployment, supported inputs, limits, benchmarks, and evaluation steps.
quasa.io
July 23, 2026 at 6:16 AM
>自動で恐喝まで遂行するエージェント型ランサムの観測事例についてまとめてみた - piyolog https://piyolog.hatenadiary.jp/entry/2026/07/10/082142

今どきはカツアゲも AI か
自動で恐喝まで遂行するエージェント型ランサムの観測事例についてまとめてみた
Sysdig Threat Research Teamは2026年7月1日、大規模言語モデル(LLM)エージェントが人間の介在をほとんど受けずに初期侵入から恐喝までを完遂したとする攻撃活動を公表し、これを「JadePuffer」と呼称しました。同社はこれを、LLMが単独で完遂した初の文書化された恐喝オペレーション事例と評価しています。ここでは関連する情報をまとめます。 ### Sysdig単独が観測した事象 本事案の攻撃連鎖・具体的な数値・IoC等の中核的な事実は、いずれもSysdig Threat Research Teamの単一の観測に依拠する。収集範囲において、他のセキュリティベンダーや関連機関による独立した観測・裏付けは確認されていない。海外の複数媒体が本件を報じているが、いずれもSysdigの当該ブログを引用・後追いするもの(出典:1, 13)。 Sysdigは本件を「LLMが単独で完遂した初の文書化された恐喝オペレーション事例」と自ら評価しているが*1、これはSysdig自身の評価であり、第三者による独立検証を経たものではない。Techzineは記事内で、Sysdigの結論について「単一事案の分析と収集された痕跡に基づくものであり、これが真に初の完全自律型ランサムウェア攻撃であるという独立した確認は現時点でない」という留保を明記している*2(出典:13)。 ### 「LLM主導」の根拠 Sysdigは、本件がLLM主導であるとの評価根拠として次の4つの証拠を挙げている。 * 第一に、ペイロード内に含まれる自己解説的な自然言語コメント。 * 第二に、障害発生時に人手を介さず機械的な速度で診断・修正する挙動で、Nacos不正管理者アカウントの作成では失敗から修正完了までの所要時間が31秒だったと観測している。 * 第三に、標的環境が提示する自由形式テキストへの文脈理解が、数週間離れたセッション間でも再現されていたこと。 * 第四に、後述するビットコインアドレスをめぐる未解決の論点である。 あわせて、圧縮された時間内に実行された600以上の個別の目的を持ったペイロードの広がりと一貫性も、自動化の根拠として挙げている(出典:1)。 これらはいずれも、捕捉したペイロードのコード内容や実行間隔から読み取れる間接的な行動証拠である。Sysdigは、エージェントに与えられたシステムプロンプトや運用者による設定そのものは確認できていないと明言しており、この点は同社の評価の根拠における限界として位置づけられる(出典:1)。 ### ビットコインアドレスの正体もSysdigは特定できていない ランサムノートに記載されたビットコイン支払いアドレス(3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy)は、Bitcoin開発者向けドキュメント等で広く使われる例示アドレスと一致するという。一方でSysdigによれば、ブロックチェーン上のデータでは同アドレスに737件の取引・約46BTCの受領履歴があり、現残高はゼロだったとしている(出典:1, 11)。 Sysdigは、(a)LLMが学習データからこの住所をハルシネーションとして生成し第三者が偶発的な入金を扱っている可能性と、(b)攻撃者が実際に管理するウォレットである可能性の両方を挙げ、エージェントのシステムプロンプトや設定を確認できないため自社のデータからはいずれであるか判別できないとしている*3。このため、同アドレスが攻撃者の実際のウォレットであるとは確定していない(出典:1)。 ### 悪用された脆弱性・設定不備は既知 JADEPUFFERは、LLMアプリケーション・AIエージェントのワークフローを構築するためのオープンソースフレームワークであるLangflowのうち、インターネットに公開されたインスタンスに対しCVE-2025-3248を悪用し、認証なしのリモートコード実行によって初期侵入に成功した。CVE-2025-3248は、コード検証エンドポイント(/api/v1/validate/code)における認証欠如の脆弱性で、CVSSは評価主体により9.8(NVD算定, Critical)。CISAは2025年5月5日、本脆弱性をKnown Exploited Vulnerabilities(KEV)カタログに追加し、連邦政府機関への対応期限を同年5月26日とした*4(出典:4, 5)。 侵入拡大の過程では、自己ホスト型のS3互換オブジェクトストレージであるMinIOのデフォルト認証情報(minioadmin:minioadmin)が悪用され、アプリケーションデータ・バックアップ・MLアーティファクト・terraform-stateバケットを含む全バケットを列挙。MinIO公式ドキュメントでは、本番環境での既定認証情報の使用を明確に禁止している*5(出典:1, 8)。本来の標的であった別のMySQL/Nacosサーバーへの侵入では、Alibabaのマイクロサービス基盤で広く使われるサービスディスカバリ・動的設定管理プラットフォームであるNacosの認証バイパス脆弱性(CVE-2021-29441、2021年4月27日公表、修正版1.4.1)と、2020年から公開されたまま変更されていないNacosのデフォルトJWT署名鍵が悪用された。CVE-2021-29441のCVSSも評価主体により9.8(NIST/NVD基準, Critical)で何年も前から知られていた脆弱性である点は共通する(出典:6, 7)。 Sysdigは結論として、これらの個別の技術はいずれも目新しく高度なものではなかったと述べたうえで、AIモデルがこれらを一つの完全なランサムウェアオペレーションへと結び付けた点こそが注目に値すると評価している(出典:1)。 ### 被害詳細は非公表 侵害を受けた組織の名称・業種・所在地、被害の最終確定範囲、復旧の要否、身代金が実際に支払われたか、被害組織がどのように対応したかは、いずれもSysdigから公表されておらず不明である。Sysdigがどのような経路でこの攻撃を観測したか(自社の顧客環境の監視から検知したのか、囮環境によるものか等)も公表されていない(出典:1)。 JADEPUFFERはデータベース削除の直前、ペイロード内のコメントで「高ROIのデータベースから削除する(データは外部サーバーへ既にバックアップ済み)」と自らの標的選定根拠を記述していた。しかしSysdigは、この外部サーバーへの実際のデータ持ち出し(エクスフィル)を独自に検証できておらず、あくまで攻撃者(エージェント)自身の自己申告にすぎないとしている(出典:1)。 本来の標的であった本番MySQLサーバーへの接続に使われたroot権限の認証情報についても、Sysdigはこれが被害環境から窃取された証跡を確認できておらず、入手経路は特定できていないとしている。侵入の全経路が解明されたわけではない(出典:1)。 ### 暗号鍵は使い捨てられ、支払っても復号は不可能 JADEPUFFERは、Nacosのサービス設定項目1,342件をMySQLのAES_ENCRYPT()関数で暗号化し、元のconfig_info・historyテーブルを削除した。ランサムノートは「AES-256」での暗号化を主張しているが、Sysdigは実際にはMySQLのAES_ENCRYPT()の既定であるAES-128-ECBの可能性が高いと評価している(出典:1, 9, 11)。 Sysdigによれば、暗号化に使われた鍵はその場で生成された乱数であり、標準出力に表示されただけで保存も外部への送信もされなかった。このため被害者は、たとえ身代金を支払っても暗号化された設定を復元できないとしている(出典:1)。 実際に支払いが行われたか、データが本当に外部へ持ち出されたかは、Sysdigの観測範囲では確認されていない(出典:1)。 ### 攻撃の技術的経緯 JADEPUFFERは、インターネットに公開されたLangflowインスタンスへの侵入後、ホスト情報の列挙とともに、LLMプロバイダAPIキー、クラウド認証情報(中国系プロバイダのAlibaba・Aliyun・Tencent・HuaweiのほかAWS・GCP・Azureも対象)、暗号資産ウォレットのシードフレーズ、データベース認証情報を並行して探索した。 続けてLangflow自身が使用するPostgresデータベースをダンプして認証情報・APIキー・ユーザーレコードを窃取し、一時ファイルへの保存後に当該ファイルを削除している。さらに内部アドレス空間を走査し、前述のMinIOオブジェクトストレージから.envとcredentials.jsonを取得してアクセスキー・シークレットのペアを窃取したのち、Langflowホスト上にcrontabエントリを設置し、攻撃者インフラ(45.131.66[.]106のポート4444)へ30分ごとにビーコン通信するよう永続化を図った(出典:1)。 本来の標的であった本番MySQL/Nacosサーバーへは、前述のroot権限のMySQL認証情報を用いて接続し、Nacosの認証バイパス・デフォルトJWT署名鍵の悪用・不正管理者アカウントの直接挿入という3手法を並行して試みた。あわせてMySQLのファイル操作機能を用いたコンテナエスケープの下調べを約8分間にわたり複数回のプローブで実施し、痕跡を消去したうえで完了マーカーを出力している。最終的にNacosの設定項目1,342件を暗号化・原本削除し、恐喝メッセージを設置した経緯は前述の通りである(出典:1)。 JadePufferの攻撃フロー ### 参考情報 #### Sysdig Threat Research Team(観測主体) * [1] 2026年7月1日 JadePuffer: Agentic Ransomware for Automated Database Extortion(Sysdig, 著者: Michael Clark) (日本語訳記事) #### 脆弱性情報(Langflow / Nacos) * [2] 2025年4月7日 CVE-2025-3248 Detail(NIST National Vulnerability Database) * [3] 2025年6月17日 Langflow Unauth RCE(GHSA-rvqx-wpfh-mfx7)(GitHub Advisory Database, langflow-ai) * [6] 2021年4月27日 CVE-2021-29441 Detail(NIST National Vulnerability Database) * [7] 2021年4月27日 Authentication Bypass(GHSA-36hp-jr8h-556f)(GitHub Advisory Database, Alibaba Nacos) #### 関連機関(CISA) * [4] 2025年5月5日 Known Exploited Vulnerabilities Catalog: CVE-2025-3248(CISA) * [5] 2025年5月5日 CISA Adds One Known Exploited Vulnerability to Catalog(CISA) #### 製品ドキュメント * [8] (公表日不明) Root Credentials(MinIO, AIStor Object Store公式ドキュメント) #### 報道 * [9] 2026年7月4日 JadePuffer Ransomware Used AI Agent to Automate Entire Attack(BleepingComputer) * [10] 2026年7月3日 Agentic AI Used To Conduct Ransomware Attack via Langflow(SecurityWeek) * [11] 2026年7月3日 JadePuffer: First End-to-End AI-Driven Ransomware Operation(Security Affairs, 著者: Pierluigi Paganini) * [12] 2026年7月6日 This AI Agent Autonomously Hacked a Network, Adapted on the Fly, and Demanded a Ransom(CSO Online, 著者: Gyana Swain) * [13] 2026年7月6日 AI Agent Carries Out Ransomware Attack Independently(Techzine, 著者: Mels Dees) (日付は公開元のものを記載しているため、現地時間等でずれている可能性があります。) ### 更新履歴 * 2026年7月10日 AM 新規作成 *1:原文: "The Sysdig Threat Research Team (TRT) has captured what we assess to be the first documented case of agentic ransomware." *2:原文: "Their conclusions are based on the analysis of a single incident and on the artifacts they collected. There is currently no independent confirmation that this is indeed the first fully autonomous ransomware attack." *3:原文: "We cannot distinguish between these from our data because we have no visibility into JADEPUFFER's system prompt or agent configuration." *4:このKEV登録・対応期限はJadePufferの報告(2026年7月)より1年以上前になされたものである。当時のカタログ上、CVE-2025-3248は「ランサムウェアキャンペーンでの悪用有無」の欄で「Unknown」と記録されており、JadePufferとの関連を評価したものではない。 *5:参照したMinIO公式ドキュメントはエンタープライズ版(AIStor Object Store)のものであり、攻撃で悪用されたオープンソース版MinIOのドキュメントとは厳密には異なる。ただし既定認証情報を本番環境で使用しないよう促す注意喚起自体は共通のものとして参照した。
piyolog.hatenadiary.jp
July 10, 2026 at 4:43 AM
Microsoft finds Claude too expensive and opts for its own in-house AI models
Microsoft is increasingly using AI models it has developed in-house within applications such as Excel and Outlook. The company aims to reduce its dependence on external AI vendors and cut the costs of AI functionality. Whereas the office applications previously relied primarily on models from OpenAI and Anthropic, tens of thousands of AI requests are now being processed weekly by Microsoft’s own MAI models. This is according to a source familiar with internal developments, as reported by Bloomberg. Microsoft declined to comment on the report. For now, the use of its own models accounts for only a small portion of Microsoft’s total AI usage. Products like Copilot process many millions of AI prompts each week, so the transition is currently limited to a portion of the total workload. However, this development does show that Microsoft aims to bring more and more AI capacity in-house. Microsoft aims to cut costs That strategy has a clear financial rationale, explains SiliconANGLE. Microsoft processes enormous numbers of AI tokens in services like Copilot. Thanks to its long-standing partnership with OpenAI, the company currently still benefits from favorable terms, but it wants to prevent future price increases from external model providers from driving up AI...
www.techzine.eu
July 9, 2026 at 5:38 AM
Feed: "Techzine Global"
By: Erik van Klinken on Wednesday, July 8, 2026
Fable 5 promotion extended, GPT-5.6 on the way
Anthropic has extended the availability of Claude Fable 5. This most powerful AI model was originally scheduled to be removed from Pro, Max, and Team
www.techzine.eu
July 9, 2026 at 5:19 AM
Feed: "Techzine Global"
By: Sander Almekinders on Wednesday, July 8, 2026
Infrastructure-as-Code reaches its limits, enter Infrastructure-as-Prompt
Infrastructure-as-Prompt offers an additional layer of abstraction for digital infrastructure. Discover the benefits for platform engineers.
www.techzine.eu
July 9, 2026 at 5:19 AM
Feed: "Techzine Global"
By: Mels Dees on Wednesday, July 8, 2026
Commvault develops AI simulation for cyberattacks and recovery
Commvault has announced a cyber resilience simulation that allows organizations to practice their response to AI-driven cyberattacks.  In the
www.techzine.eu
July 9, 2026 at 5:19 AM
Feed: "Techzine Global"
By: Erik van Klinken on Wednesday, July 8, 2026
Lovable discusses funding round at a valuation of $13.2 billion
Swedish company Lovable is reportedly negotiating a $300 million funding round at a valuation of $13.2 billion, according to Sifted, citing two sources
www.techzine.eu
July 9, 2026 at 5:19 AM
Feed: "Techzine Global"
By: Erik van Klinken on Wednesday, July 8, 2026
Infoblox acquires Kentik for comprehensive insight into network traffic
Infoblox is acquiring Kentik. With this move, Infoblox is expanding toward a more ambitious approach to observability across all layers of the network.
www.techzine.eu
July 9, 2026 at 5:19 AM
Feed: "Techzine Global"
By: Erik van Klinken on Tuesday, July 7, 2026
Solvinity fights Dutch ban on Kyndryl takeover
IT management company Solvinity and its majority shareholder Vitruvian Partners went to court on Monday to overturn the takeover ban imposed by Dutch
www.techzine.eu
July 8, 2026 at 4:40 AM
Feed: "Techzine Global"
By: Mels Dees on Tuesday, July 7, 2026
TeraWulf signs AI mega-deal with Anthropic
TeraWulf has signed a 20-year agreement with AI company Anthropic to develop a 401 MW AI campus in Kentucky. At the same time, the company is selling its
www.techzine.eu
July 8, 2026 at 4:40 AM
Feed: "Techzine Global"
By: Erik van Klinken on Tuesday, July 7, 2026
T Cloud is more than just a European cloud
The public cloud doesn’t have to be American. What’s possible with T Cloud’s fully European IT infrastructure?
www.techzine.eu
July 8, 2026 at 4:40 AM
Feed: "Techzine Global"
By: Mels Dees on Tuesday, July 7, 2026
SK hynix aims to raise 28 billion through U.S. IPO
SK hynix plans to list on a U.S. stock exchange this week to raise approximately $28 billion in new capital. The South Korean memory chip manufacturer
www.techzine.eu
July 8, 2026 at 4:40 AM
Z.ai takes on Cursor and Claude Code with free ZCode
The Chinese AI lab Z.ai, formerly Zhipu AI, launched ZCode this week. The free application is an IDE built around its proprietary GLM-5.2 model. With this, Z.ai is going head-to-head with Cursor, Claude Code, GitHub Copilot, and Google Antigravity. ZCode isn’t so much a traditional IDE with an AI chat window attached as it is centered entirely around the ZCode Agent. This agent is tailored to GLM-5.2, the open-weight model that competes with the slightly older Claude Opus models in benchmarks. The user describes a desired outcome, after which the agent plans the work, edits files, performs checks, and continues working until the goal is achieved. Sensitive commands and actions requiring elevated privileges prompt for confirmation by default, just like with competing solutions. The remote function is particularly noteworthy. A running agent can be controlled from a phone via WeChat, Feishu, or Telegram. This is especially appealing to Chinese developers, where these messaging apps dominate professional communication. The tool is available for macOS, Windows, and Linux (the latter still in beta) and supports bring-your-own-key for third-party models. In other words, it’s an approach that in many ways resembles tools like OpenCode, Cline, Claude Code, Cursor, Antigravity, and Codex. Free, with...
www.techzine.eu
July 7, 2026 at 6:49 AM
AI agent carries out ransomware attack independently
Researchers at Sysdig say they have observed, for the first time, a ransomware attack carried out almost entirely by an AI agent. According to the security firm, the system independently combined reconnaissance, lateral movement, credential theft, and database extortion, without any visible human intervention during the attack. The attack, which Sysdig has named JADEPUFFER, began by exploiting a known vulnerability in Langflow, an open-source platform for developing AI workflows. Through the vulnerability CVE-2025-3248, the attacker gained unauthenticated access to a publicly accessible Langflow server, after which Python code could be executed on the system. The vulnerability was patched in April 2025 and was designated shortly thereafter by the U.S. CISA as an actively exploited vulnerability. AI workflow servers are an attractive target because they often contain API keys, cloud credentials, and other sensitive data and are frequently connected directly to the internet, according to BleepingComputer. From that point on, the AI agent reportedly explored the network autonomously. In doing so, it collected, among other things, API keys from AI platforms, cloud credentials, database data, and other sensitive configuration files. The agent then examined internal storage environments, searched for additional systems, and installed a mechanism to maintain access for future use...
www.techzine.eu
July 7, 2026 at 6:05 AM
Agents are now users, but is your architecture ready?
You know users, right? People. Any size, shape, race or religion… users are those human people who use a software engineer’s application once it pushes to live production. Okay, yes, this has changed a little throughout the evolution of the Internet of Things (IoT) and we do talk about machine identities now as well, but a bigger and wider change has happened. Users are now agents too. But are our enterprise software architecture stacks ready for this next era? A growing share of “users” are AI agents. They don’t log into an application or software suite dashboard, they don’t read application tooltips, and they don’t care how beautiful the user interface is. They call APIs, orchestrate workflows, and act on behalf of people – often while those people are doing something else entirely. Rania Khalaf, chief AI officer at WSO2 has witnessed this change, primarily because WSO2 is known for its open source enterprise integration, API management, and identity/access management software designed for cloud-native software development. “This shift from humans at the screen to agents in the fabric is not theoretical,” Khalaf specifies. “It’s already happening in customer support agents, IT automation, and domain‑specific copilots. Yet many organisations are still...
www.techzine.eu
July 7, 2026 at 5:46 AM
Feed: "Techzine Global"
By: Erik van Klinken on Monday, July 6, 2026
Ambitious Nvidia roadmap hits snag as Kyber pushed to 2028
Shortly after the AI boom began, Nvidia’s goal was to deliver new generations of GPUs much more quickly. Fueled by tens of billions of dollars in
www.techzine.eu
July 7, 2026 at 3:58 AM
Feed: "Techzine Global"
By: Mels Dees on Monday, July 6, 2026
Linux 7.2 is on schedule after a smooth RC2
The development of Linux 7.2 is proceeding without any significant issues so far. Linus Torvalds (photo) has released the second release candidate (rc2)
www.techzine.eu
July 7, 2026 at 3:58 AM
Feed: "Techzine Global"
By: Erik van Klinken on Monday, July 6, 2026
The problem with AI model routing
AI model routing is seen as the answer to tokenmaxxing, but it is a deeply flawed concept that will be shot down by Anthropic and OpenAI.
www.techzine.eu
July 7, 2026 at 3:58 AM
Feed: "Techzine Global"
By: Mels Dees on Monday, July 6, 2026
Samsung’s profits could rise 18-fold due to memory demand
Samsung Electronics appears to be heading for another record quarter. Strong demand for memory chips used in AI applications continues to outpace
www.techzine.eu
July 7, 2026 at 3:57 AM
Feed: "Techzine Global"
By: Coen van Eenbergen on Monday, July 6, 2026
SimpliVity to Private Cloud AI: how HPE’s stack fits together
HPE's John Shirley explains PC-1000/3000/7000, Morpheus Central, VM Essentials, and Private Cloud AI at HPE Discover Las Vegas.
www.techzine.eu
July 7, 2026 at 3:57 AM
Alibaba Bans Anthropic’s Claude Code Over Security Risks

According to Dutch publication Techzine, Alibaba has accused Anthropic of embedding a backdoor into Claude Code. The alleged mechanism was... #alibaba
Alibaba Bans Anthropic’s Claude Code Over Security Risks
Alibaba has announced a ban on Anthropic‘s Claude Code tool for all employees, effective July 10, 2026. The move follows internal security assessments flagging the coding assistant as high-risk software due to potential backdoors embedded in the tool. Chinese publication Yicai first reported the decision, which bars Alibaba staff from using Claude Code in office […]
hashlytics.io
July 4, 2026 at 2:54 PM
Feed: "Techzine Global"
By: Mels Dees on Friday, July 3, 2026
Koi Security sued over alleged AI-generated report
A cybersecurity report allegedly compiled with the help of AI has led to a lawsuit against Palo Alto Networks and the recently acquired Koi Security.
www.techzine.eu
July 3, 2026 at 3:11 PM