LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

zeroday.news ·

The Linux Foundation has announced it will govern TRACE, an open standard designed for AI runtime attestation. This initiative aims to provide a standardized method for verifying the integrity and trustworthiness of AI systems during their operation.

TRACE was developed through a collaborative effort involving several prominent technology companies and research institutions. AMD, Intel, Microsoft, OPAQUE, and TII are credited as the initial contributors to the standard, which they have now contributed to the Linux Foundation for broader community oversight and development.

Runtime attestation, in the context of AI, refers to the process of cryptographically verifying that an AI model and its execution environment are operating as expected and have not been tampered with. This is critical for ensuring the security and reliability of AI applications, especially in sensitive or critical infrastructure deployments where the integrity of AI decisions is paramount.

The technical mechanism behind such attestation typically involves measuring various components of the AI system's runtime environment, including the AI model itself, the underlying operating system, hypervisor, and even hardware components. These measurements are then cryptographically signed and can be verified by a relying party to confirm the system's state against a known good baseline.

By establishing an open standard under the Linux Foundation, TRACE seeks to foster interoperability and widespread adoption across the AI ecosystem. This move can help prevent vendor lock-in and encourage a consistent approach to AI security, benefiting developers, deployers, and users of AI technologies.

Mitigation guidance for issues related to AI runtime integrity often involves implementing robust attestation mechanisms, regularly updating software components, and maintaining secure development lifecycles. For organizations leveraging AI, adopting open standards like TRACE can provide a foundational layer of trust and transparency in their AI deployments.

The governance of TRACE by the Linux Foundation signifies a growing industry recognition of the need for standardized security measures in artificial intelligence. As AI systems become more pervasive and critical, initiatives like TRACE are essential for building trust, ensuring accountability, and addressing the evolving security challenges inherent in complex AI architectures.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

When the Algorithm Fires You: Uber Faces €825M Fine

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

security

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

patch

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

ddos

Massive DDoS attack disrupts Norway’s government digital services

A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]

breach

Hospital operator Nutex Health says data stolen in cyberattack

Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]

phishing

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands