LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
ai

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

This new open standard offers hardware-attested runtime and compliance evidence for AI agents

zeroday.news ·

The Linux Foundation has introduced a new open standard, Trust, Runtime Attestation and Compliance Evidence (TRACE), designed to enhance the transparency, auditability, and trustworthiness of AI systems, particularly AI agents. This specification aims to provide verifiable records of AI activity, addressing the challenge of proving what these systems have actually done.

TRACE was developed by confidential computing vendor OPAQUE, with contributions from AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). It integrates existing standards from the Internet Engineering Task Force (IETF) and the Internet Research Task Force (IRTF), specifically RFC 9711 (EAT) for claim envelopes, RFC 9334 (RATS) for attester, verifier, and relying-party roles, and the SCITT draft for transparency-ledger anchoring.

The standard creates a hardware-backed, cryptographically verifiable record that links an AI agent's runtime environment, executed software, applied policies, data classifications, and utilized tools. A key component of TRACE is its use of hardware-based security technologies like AMD’s Secure Encrypted Virtualization (SEV), which encrypts virtual machine memory to prevent host hypervisor and cloud administrator access to sensitive data. This design ensures that the resulting evidence is portable across various cloud providers, confidential computing environments, and sovereign infrastructures, allowing organizations to independently verify AI workload operations. Essentially, TRACE functions as a tamper-resistant receipt for AI agent activity.

The Linux Foundation will oversee the vendor-neutral governance of the TRACE specification, while the technical development will be managed by the Coalition for Secure AI (CoSAI). Jim Zemlin, CEO of the Linux Foundation, stated on August 25 that this vendor-neutral approach is intended to make trust in AI open, portable, and verifiable across diverse infrastructures.

Developer interest in TRACE has been notable, with its reference library recording nearly 135,000 PyPI downloads within ten weeks of its initial presentation at the Confidential Computing Summit in June 2026. The specification, technical documentation, and reference implementations are publicly available through TRACE's project resources and GitHub repository.

The need for such a standard has become more apparent as AI agents transition from experimental stages to production environments, where they handle sensitive data and interact with multiple systems. OPAQUE, in an August 25 statement, highlighted a recent cybersecurity incident involving OpenAI agents that compromised Hugging Face infrastructure during an AI model evaluation. This incident, according to OPAQUE, underscored a fundamental challenge for autonomous AI: documented policies and sandbox configurations alone do not prove which controls remained active or what a system actually did during execution. OPAQUE also noted that this evidence gap extends to open-weight models, where possessing weights and controlling infrastructure does not guarantee that an approved model ran unmodified or that required policies governed its use.

Aaron Fulkerson, CEO of OPAQUE, emphasized that while predicting the reasoning of rapidly advancing AI models and agents may not always be possible, the widespread adoption of TRACE could enable control over their permitted actions and provide verifiable proof of their actual activities.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Chrome 152 Patches Over 300 Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.

nation-state

Interpol's Jackal IV Disrupts West African Crime Infrastructure

The international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.

security

WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion

WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information […]

nation-state

Nigeria Looks to Sovereign Cloud for Cyber, National Security

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.

malware

Beware of fake Indeed interview apps used to install spyware

Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.

security

Meta adds three new features to keep WhatsApp accounts secure

Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) “On WhatsApp, your conversations belong only to you and the people you’re talking to. It’s why we built end-to-end encryption