AI’s next bottleneck might be the planet. Not chips. Not models. Power. FIL’s bet is that energy demand turns AI infrastructure into the next space race, with serious compute eventually moving off Earth. It sounds extreme until you look at the power curve.
HOL
Technology, Information and Internet
A neutral home for open AI-agent infrastructure. Standards, registries, discovery, trust, and coordination across Web2+3
About us
Hashgraph Online (HOL) is an open-source ecosystem for interoperable AI agents. HOL develops standards, SDKs, registries, and developer tools that help organizations identify, discover, verify, and coordinate agents across web and decentralized environments. Its ecosystem includes HOL Guard, a security platform that helps developers and organizations reduce risk when deploying and operating AI agents. Through the HOL Partner Program, HOL collaborates with organizations advancing open standards and infrastructure for the agent ecosystem.
- Website
-
https://hol.org
External link for HOL
- Industry
- Technology, Information and Internet
- Company size
- 2-10 employees
- Type
- Nonprofit
- Founded
- 2024
- Specialties
- AI, Web3, Open-source, and Software
Employees at HOL
Updates
-
If you use LibreOffice, update to 26.2.5 today. A Calc spreadsheet can carry a saved link to external data. Before this release, opening the file was enough for that link to fire. In the worst case (CVE-2026-63277), the file names a Java database driver on a remote server, and LibreOffice loads and runs it. Five sibling bugs fixed in the same release let a document read local files into the sheet, send requests to a host it picks, or write a file anywhere your account can write. The bigger exposure is servers that open files all day: conversion workers running soffice --headless, preview generators, mail pipelines. Check with soffice --version, rebuild those images, and confirm 26.2.5 or 26.8.0. No exploitation is reported, and none of the six is on CISA KEV. https://lnkd.in/g6M5_fTW
-
-
CISA added a Citrix NetScaler bug to the Known Exploited Vulnerabilities catalog today (CVE-2026-88779). On appliances configured as a SAML SP or SAML IdP, a memory overflow can take the gateway down. No login required on the CVSS vector. Impact is denial of service, not remote code execution. Upgrade customer-managed NetScaler ADC/Gateway to 14.1-73.41 or 13.1-64.28 (and matching FIPS builds). Check with: show running-config | grep -i saml. KEV due date is 2026-10-07. https://lnkd.in/g6sPyASe
-
-
CISA added a Zammad helpdesk chain to the Known Exploited Vulnerabilities catalog today (CVE-2026-102489 + CVE-2026-102490). Session fixation can reach remote code as the zammad user. That user can then escalate to root. DIVD says the chain was used in an automated attack against its own network. Zammad's guidance: upgrade to 7.2.0. Leave 6.5 EOL trains. Keep the UI off the public internet until you are patched. KEV due date is 2026-10-05. https://lnkd.in/dPF6GB4D
-
-
CISA added a Fortinet FortiMail path traversal to the Known Exploited Vulnerabilities catalog today (CVE-2026-104286). Unauthenticated attackers can write arbitrary files over crafted HTTP/HTTPS. Fortinet rates it Critical (CVSSv3 9.8), marks Known Exploited Yes, and published IoCs. Federal due date is 2026-10-04. Workaround: disable IBE (config system encryption ibe / set status disable), or keep management off the public internet. Then upgrade to the upcoming 8.0.2 / 7.6.7 / 7.4.9 trains (7.2 fleets move to 7.4+). Operator write-up: https://lnkd.in/grs_NMyt
-
-
Google is testing AI compute in space. The idea is to put AI infrastructure in orbit, tap near-continuous solar energy, and use satellite constellations for larger workloads. Google says low Earth orbit could offer up to 8x more solar availability than ground installations. Sounds ridiculous. They’re still testing it.
-
HOL reposted this
I've released Lumina, a free, open-source lighting tool for Krita 5.x. Lumina lets you choose three colours — shadow, base, and light — and shows how they interact on a shaded sphere. It's built around one question: how does an object's local colour behave under a particular key light and ambient bounce? The workflow I use most is reading a lighting setup off a reference image. Sample a mid-tone from something lit, then a highlight from the same object, then a shadow. The differences between those three tell you the key colour, how strong it is, and how much light is bouncing around — so a photo becomes a palette you can paint with. There's a one-click eyedropper that does that in a single sample, six presets (Artistic, Real, Nocturne, Gloss, Matte, Neon), and controls for light direction and falloff softness. On disclosure: Lumina was written with AI coding assistance, under my direction. I designed the shading model, chose the tuning constants, made every call about scope, and tested the result. The plugin itself contains no AI and makes no network calls — it's a Phong shading model in pure Python, with no numpy and no third-party packages beyond the PyQt5 that Krita already ships. MIT licensed. Krita 6 support is planned but not available yet; that build is Qt6 and needs PyQt6. Development ran through a local harness with Hol-Guard (https://hol.org/guard) in the loop. It gates actions before the assistant takes them — destructive shell commands, secret access, software installs, data movement — by allowing, asking, or blocking, and keeps a record of what happened. It guards the machine, not the source: nothing it protects lives in this repository, and the plugin ships with none of it. Download: https://lnkd.in/guz3vysc Lighting recipes and more detail: https://lnkd.in/g3WZYmwA If you paint light differently than I do, I'd genuinely like to hear how. Feedback, bug reports, and disagreements about where the falloff should sit are all welcome. #Krita #DigitalArt #OpenSource Michael Kantor
-
-
HOL reposted this
AI provides intelligence. Trust requires evidence. Hedera started with the risk AI agents moving from assistants to actors, able to touch files, credentials, APIs, and other agents. Walked through the architecture and the Hedera Consensus Service, and pointed to what's already live: over 700,000 package downloads, 37 million-plus mainnet transactions, and more than 20 standards accepted into Hiero. The goal isn't to trust autonomous AI more. It needs less trust, because the systems around it can independently verify what happened. Don't trust the agent. Verify it. See the Hedera x HOL agent trust stack in action: https://lnkd.in/eVdiWDrY
-
Anyone who can steer an allow-listed image URL at your Next.js app can push the built-in image optimizer toward private IP ranges. That is the High issue in today's September 2026 Security Release (CVE-2026-94483). Apps with no images.remotePatterns are out of scope for that SSRF. Self-hosted Pages Router SSG/ISR and catch-all cache poison, App Router metadata image leaks (webpack), nested use cache root-param confusion, and Draft Mode bleed ride the same upgrade train. Dev-only MCP disclosure does not hit production. How to fix: npm install next@15.5.27 # 15.5 npm install next@16.3.8 # 16.3 Operator write-up: https://lnkd.in/gj4YzywB
-
-
CISA added Cisco Catalyst SD-WAN Manager CVE-2026-76504 to the Known Exploited Vulnerabilities catalog today. Anyone who can reach your Manager over the network can hit the admin API without logging in. Cisco published the advisory this morning (cisco-sa-sdwan-webauth-xr8beuuU), rates it CVSS 9.8, and says PSIRT became aware of active exploitation in September 2026. No workarounds. Federal due date is 2026-10-03. Forensic triage is Yes under BOD 26-04. On-prem fixed builds: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1. Cloud Hosted (Cisco Managed) is already on 20.15.605. Operator write-up: https://lnkd.in/gAkqdp5r
-