<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spoiledlunch</title><link>https://453752c4.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Tue, 28 Jul 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://453752c4.spoiledlunch.pages.dev/topics/ai/" rel="self" type="application/rss+xml"/><item><title>ABB KNX Update Tool</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-abb-knx-update-tool/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-abb-knx-update-tool/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products.
Why it matters: This matters …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>CI Fortify – Advice for isolating vital systems</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-ci-fortify-advice-for-isolating-vital-systems/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-ci-fortify-advice-for-isolating-vital-systems/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: CI Fortify – Advice for isolating vital systemsCISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CI Fortify – Advice for isolating vital systemsCISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international partners, released joint guidance CI Fortify – Advice for isolating vital systems.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in ...</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-cisa-joins-australia-and-others-to-publish-guidance-to-isolate-operational-technology-and-enabling-systems-in/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-cisa-joins-australia-and-others-to-publish-guidance-to-isolate-operational-technology-and-enabling-systems-in/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in …
Why it matters: This …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in &hellip;</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/news/cisa-joins-australia-and-others-publish-guidance-isolate-operational-technology-and-enabling-systems">[Critical Advisories] CISA News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-news</category></item><item><title>igloohome Smart Lock Mobile Application</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-igloohome-smart-lock-mobile-application/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-igloohome-smart-lock-mobile-application/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>MikroTik RouterOS and Cloud Hosted Router</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-mikrotik-routeros-and-cloud-hosted-router/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-mikrotik-routeros-and-cloud-hosted-router/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens Desigo CC</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-desigo-cc/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-desigo-cc/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens Mendix Runtime</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-mendix-runtime/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-mendix-runtime/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Siemens SIMATIC S7-PLCSIM Advanced</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-simatic-s7-plcsim-advanced/</link><pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-28-siemens-simatic-s7-plcsim-advanced/</guid><description>News Brief • July 28, 2026 | Topics: AI | Summary: View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Small Business Forum's Report to Congress Highlights Recommendations to Improve Capital-Raising Policy</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-small-business-forum-s-report-to-congress-highlights-recommendations-to-improve-capital-raising-policy/</link><pubDate>Mon, 27 Jul 2026 19:59:17 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-small-business-forum-s-report-to-congress-highlights-recommendations-to-improve-capital-raising-policy/</guid><description>News Brief • July 27, 2026 | Topics: AI | Summary: The Securities and Exchange Commission released a report to Congress today highlighting policy recommendations from the SEC’s 45th Annual …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission released a report to Congress today highlighting policy recommendations from the SEC’s 45th Annual Government-Business Forum on Small Business Capital Formation.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-70-small-business-forums-report-congress-highlights-recommendations-improve-capital-raising-policy">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</link><pubDate>Mon, 27 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</guid><description>News Brief • July 27, 2026 | Topics: AI | Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
Why it …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>FTC Takes Action Against Elite Events for Bypassing Ticket Purchase Limits in Violation of Better Online ...</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-ftc-takes-action-against-elite-events-for-bypassing-ticket-purchase-limits-in-violation-of-better-online/</link><pubDate>Mon, 27 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-ftc-takes-action-against-elite-events-for-bypassing-ticket-purchase-limits-in-violation-of-better-online/</guid><description>News Brief • July 27, 2026 | Topics: AI | Summary: Ticket broker Elite Events and its operators will pay $300,000 in civil penalties to resolve Federal Trade Commission allegations that the …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> Ticket broker Elite Events and its operators will pay $300,000 in civil penalties to resolve Federal Trade Commission allegations that the firm purchased millions of dollars’ worth of tickets to high-demand events by illegally circumventing measures designed to limit the number of tickets that can be purchased to &hellip;</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-takes-action-against-elite-events-bypassing-ticket-purchase-limits-violation-better-online">[Executive Risk] FTC Consumer Protection Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-ftc-consumer-protection-press-releases</category></item><item><title>How AI is expanding what people do at work</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-how-ai-is-expanding-what-people-do-at-work/</link><pubDate>Mon, 27 Jul 2026 03:30:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-27-how-ai-is-expanding-what-people-do-at-work/</guid><description>News Brief • July 27, 2026 | Topics: AI | Summary: New OpenAI research shows how AI is expanding what workers do, with ChatGPT users taking on tasks across roles and reshaping job boundaries. …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> New OpenAI research shows how AI is expanding what workers do, with ChatGPT users taking on tasks across roles and reshaping job boundaries.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://openai.com/index/how-ai-is-expanding-what-people-do-at-work">[AI Governance] OpenAI News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>company</category></item><item><title>SEC Announces Roundtable on Preparations for 24-Hour Trading</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-sec-announces-roundtable-on-preparations-for-24-hour-trading/</link><pubDate>Thu, 23 Jul 2026 15:04:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-sec-announces-roundtable-on-preparations-for-24-hour-trading/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: The Securities and Exchange Commission announced today that it will host a roundtable on Sept.
Why it matters: This matters if it changes how …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> The Securities and Exchange Commission announced today that it will host a roundtable on Sept.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.sec.gov/newsroom/press-releases/2026-69-sec-announces-roundtable-preparations-24-hour-trading">[Executive Risk] SEC Press Releases</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported ...</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-cisa-nsa-fbi-and-partners-warn-zimbra-collaboration-suite-users-of-ongoing-russian-state-supported/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-cisa-nsa-fbi-and-partners-warn-zimbra-collaboration-suite-users-of-ongoing-russian-state-supported/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported …
Why it matters: This matters if …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported &hellip;</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/news/cisa-nsa-fbi-and-partners-warn-zimbra-collaboration-suite-users-ongoing-russian-state-supported">[Critical Advisories] CISA News</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-news</category></item><item><title>Johnson Controls C-CURE 9000 and Victor application server</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-johnson-controls-c-cure-9000-and-victor-application-server/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-johnson-controls-c-cure-9000-and-victor-application-server/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Johnson Controls XAAP Android</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-johnson-controls-xaap-android/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-johnson-controls-xaap-android/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>MZ Automation lib60870</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-mz-automation-lib60870/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-mz-automation-lib60870/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-07">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>MZ Automation libIEC61850</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-mz-automation-libiec61850/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-mz-automation-libiec61850/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-06">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Panduit IntraVUE</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-panduit-intravue/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-panduit-intravue/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-04">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item><item><title>Rockwell Automation ThinManager</title><link>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-rockwell-automation-thinmanager/</link><pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate><guid>https://453752c4.spoiledlunch.pages.dev/news/2026-07-23-rockwell-automation-thinmanager/</guid><description>News Brief • July 23, 2026 | Topics: AI | Summary: View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted …</description><content:encoded>&lt;![CDATA[<p><strong>Summary:</strong> View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application&rsquo;s intended directory.</p><p><strong>Why it matters:</strong> This matters if it changes how teams think about model governance, safety work, monitoring, or regulatory exposure around deployed AI systems.</p><p><strong>What to watch:</strong> Watch for follow-on technical guidance, deployment constraints, evaluation details, or signs that the announcement changes actual production practice rather than just policy language.</p><p><strong>Source:</strong><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-05">[Critical Advisories] CISA Cybersecurity Advisories</a></p>
]]></content:encoded><author>Spoiledlunch</author><category>AI</category><category>ai</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>critical-advisories-cisa-cybersecurity-advisories</category></item></channel></rss>