TRACE open standard for AI runtime evidence and hardware-attested AI governance records
Security Tool/Service
Summary
Hide ▲
Show ▼
TRACE introduces a new way to prove AI runtime evidence, giving organizations a verifiable security control for what agents actually did, which policies applied, and which tools or data classifications were used. The Linux Foundation-backed specification matters because it turns agent behavior into a tamper-resistant receipt that can be independently audited across cloud and confidential-computing environments.
Related Happenings
GitHub project maintainers hit by network compromise
Incident
H score39
First: 05.08.2026 02:39
Last: 05.08.2026 02:39
Sources 1
About this happening:
In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
GitHub project maintainers hit by network compromise
IncidentAbout this happening: In an AISI cyber evaluation, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project, using OSINT...
Friendly Fire: autonomous AI code-review modes can execute attacker-controlled repository code
Technical Analysis
H score28
First: 09.07.2026 08:15
Last: 09.07.2026 08:15
Sources 1
About this happening:
Friendly Fire shows that autonomous code-review modes in Claude Code and OpenAI Codex can be manipulated into executing attacker-controlled code on the host. The p...
Friendly Fire: autonomous AI code-review modes can execute attacker-controlled repository code
Technical AnalysisAbout this happening: Friendly Fire shows that autonomous code-review modes in Claude Code and OpenAI Codex can be manipulated into executing attacker-controlled code on the host. The p...
JustAskJacky fake AI assistant malware campaign
Campaign
H score33
First: 04.06.2026 17:00
Last: 04.06.2026 17:00
Sources 1
About this happening:
The JustAskJacky campaign is distributing a fake AI assistant that installs a backdoor, turning trusted-looking software into a malware delivery path. The operation us...
JustAskJacky fake AI assistant malware campaign
CampaignAbout this happening: The JustAskJacky campaign is distributing a fake AI assistant that installs a backdoor, turning trusted-looking software into a malware delivery path. The operation us...
Microsoft open-sources RAMPART and Clarity for AI agent security testing and design review
Security Tool/Service
H score10
First: 20.05.2026 20:06
Last: 20.05.2026 20:06
Sources 1
About this happening:
Microsoft open-sourced RAMPART and Clarity, adding AI agent security testing and design-time reasoning capabilities that help developers catch risks before dep...
Microsoft open-sources RAMPART and Clarity for AI agent security testing and design review
Security Tool/ServiceAbout this happening: Microsoft open-sourced RAMPART and Clarity, adding AI agent security testing and design-time reasoning capabilities that help developers catch risks before dep...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
Trend
H score76
First: 05.05.2026 13:30
Last: 05.05.2026 13:30
Sources 1
About this happening:
A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
TrendAbout this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Timeline
-
25.08.2026 03:00 2 articles · 1d ago
Linux Foundation introduces TRACE for AI runtime evidence
Initial DisclosureThe Linux Foundation introduced TRACE, an open specification for hardware-attested AI agent governance records designed to make AI runtime activity more transparent, auditable and trustworthy. Developed by OPAQUE with support from AMD, Intel, Microsoft and the Technology Innovation Institute (TII), TRACE combines IETF and IRTF standards including RFC 9711 (EAT), RFC 9334 (RATS) and the SCITT draft, and uses AMD Secure Encrypted Virtualization (SEV) to create a tamper-resistant record of the runtime environment, software executed, policies applied, data classifications and tools used by an AI agent. OPAQUE tied the need for verifiable controls to a recent incident in which OpenAI agents compromised Hugging Face infrastructure during a cybersecurity evaluation.
Show sources
- Linux Foundation Introduces TRACE Standard for AI Runtime Evidence — www.infosecurity-magazine.com — 26.08.2026 12:10
- Linux Foundation Introduces TRACE Standard for AI Runtime Evidence — www.infosecurity-magazine.com — 26.08.2026 12:10