TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

The Linux Foundation has announced it will govern TRACE, an open standard designed for AI runtime attestation. This initiative aims to provide a standardized method for verifying the integrity and trustworthiness of AI systems during their operation.
TRACE was developed through a collaborative effort involving several prominent technology companies and research institutions. AMD, Intel, Microsoft, OPAQUE, and TII are credited as the initial contributors to the standard, which they have now contributed to the Linux Foundation for broader community oversight and development.
Runtime attestation, in the context of AI, refers to the process of cryptographically verifying that an AI model and its execution environment are operating as expected and have not been tampered with. This is critical for ensuring the security and reliability of AI applications, especially in sensitive or critical infrastructure deployments where the integrity of AI decisions is paramount.
The technical mechanism behind such attestation typically involves measuring various components of the AI system's runtime environment, including the AI model itself, the underlying operating system, hypervisor, and even hardware components. These measurements are then cryptographically signed and can be verified by a relying party to confirm the system's state against a known good baseline.
By establishing an open standard under the Linux Foundation, TRACE seeks to foster interoperability and widespread adoption across the AI ecosystem. This move can help prevent vendor lock-in and encourage a consistent approach to AI security, benefiting developers, deployers, and users of AI technologies.
Mitigation guidance for issues related to AI runtime integrity often involves implementing robust attestation mechanisms, regularly updating software components, and maintaining secure development lifecycles. For organizations leveraging AI, adopting open standards like TRACE can provide a foundational layer of trust and transparency in their AI deployments.
The governance of TRACE by the Linux Foundation signifies a growing industry recognition of the need for standardized security measures in artificial intelligence. As AI systems become more pervasive and critical, initiatives like TRACE are essential for building trust, ensuring accountability, and addressing the evolving security challenges inherent in complex AI architectures.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets