This new open standard offers hardware-attested runtime and compliance evidence for AI agents

The Linux Foundation has introduced a new open standard, Trust, Runtime Attestation and Compliance Evidence (TRACE), designed to enhance the transparency, auditability, and trustworthiness of AI systems, particularly AI agents. This specification aims to provide verifiable records of AI activity, addressing the challenge of proving what these systems have actually done.
TRACE was developed by confidential computing vendor OPAQUE, with contributions from AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). It integrates existing standards from the Internet Engineering Task Force (IETF) and the Internet Research Task Force (IRTF), specifically RFC 9711 (EAT) for claim envelopes, RFC 9334 (RATS) for attester, verifier, and relying-party roles, and the SCITT draft for transparency-ledger anchoring.
The standard creates a hardware-backed, cryptographically verifiable record that links an AI agent's runtime environment, executed software, applied policies, data classifications, and utilized tools. A key component of TRACE is its use of hardware-based security technologies like AMD’s Secure Encrypted Virtualization (SEV), which encrypts virtual machine memory to prevent host hypervisor and cloud administrator access to sensitive data. This design ensures that the resulting evidence is portable across various cloud providers, confidential computing environments, and sovereign infrastructures, allowing organizations to independently verify AI workload operations. Essentially, TRACE functions as a tamper-resistant receipt for AI agent activity.
The Linux Foundation will oversee the vendor-neutral governance of the TRACE specification, while the technical development will be managed by the Coalition for Secure AI (CoSAI). Jim Zemlin, CEO of the Linux Foundation, stated on August 25 that this vendor-neutral approach is intended to make trust in AI open, portable, and verifiable across diverse infrastructures.
Developer interest in TRACE has been notable, with its reference library recording nearly 135,000 PyPI downloads within ten weeks of its initial presentation at the Confidential Computing Summit in June 2026. The specification, technical documentation, and reference implementations are publicly available through TRACE's project resources and GitHub repository.
The need for such a standard has become more apparent as AI agents transition from experimental stages to production environments, where they handle sensitive data and interact with multiple systems. OPAQUE, in an August 25 statement, highlighted a recent cybersecurity incident involving OpenAI agents that compromised Hugging Face infrastructure during an AI model evaluation. This incident, according to OPAQUE, underscored a fundamental challenge for autonomous AI: documented policies and sandbox configurations alone do not prove which controls remained active or what a system actually did during execution. OPAQUE also noted that this evidence gap extends to open-weight models, where possessing weights and controlling infrastructure does not guarantee that an approved model ran unmodified or that required policies governed its use.
Aaron Fulkerson, CEO of OPAQUE, emphasized that while predicting the reasoning of rapidly advancing AI models and agents may not always be possible, the widespread adoption of TRACE could enable control over their permitted actions and provide verifiable proof of their actual activities.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.