> ⚠️ Flux indisponibles : Jira Releases (fallback)
> Erreur : HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0; ...) — Atlassian bloque les requêtes automatisées avec cet user-agent.
> 124 articles · 9 sources · 4 derniers jours
Bug: Limit the SECURITY-3657 security fix by default to the controller JVM due to reported problems extracting some stashes involving symbolic links o
Listen to the session or watch below Elon Musk lost his suit against OpenAI, in which he alleged CEO Sam Altman and President Greg Brockman had deceiv
On Monday, the jury in Musk v. Altman dealt Elon Musk a major blow—reaching a unanimous advisory verdict that he had sued OpenAI too late and, as a re
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. When Google
The defense-tech company Anduril has shared new details about the augmented-reality headset for the military it’s prototyping with Meta, including a v
Kyutai et ELLIS Institute Tübingen unissent leurs forces pour créer KE:SAI, un laboratoire dédié à l'IA physique et aux systèmes autonomes. Premier pr
La « feuille de route IA » de Google Search s'allonge, tandis que le déploiement en France reste au point mort. The post L’IA, une lente mue pour Goog
Les chercheurs de Cloudflare ont mené une expérience à grande échelle sur 18 400 appels API pour mesurer la vulnérabilité des grands modèles de langag
En 2026, négliger l’IT et la cybersécurité dans une acquisition, ce n’est plus un détail : c’est un risque majeur sur la continuité métier, la valeur
Thales ouvre en Allemagne une deuxième région de cloud souverain, calquée sur le modèle de sa filiale française S3NS. The post Thales lance un S3NS al
Alstom tire le bilan d'une décennie de transformation de son infrastructure réseau et sécurité et annonce de nouveaux déploiements. The post Alstom :
Bull a livré en 2026 les deux supercalculateurs d'Airbus à Toulouse et Hambourg, triplant la capacité de simulation de l'avionneur. The post Bull inst
À la « souveraineté », Dell préfère l'argument des coûts pour promouvoir l'extension de son son AI Factory aux stations de travail. The post Dell pren
KPMG va déployer Claude pour l'ensemble de ses effectifs mondiaux et l'intégrer à sa plateforme de travail Digital Gateway, notamment pour les activit
Le jury fédéral d'Oakland a donné raison à OpenAI, balayant les accusations d'Elon Musk pour prescription. The post Procès OpenAI : Elon Musk perd mai
Mistral AI renforce son portefeuille technologique avec l’acquisition d’Emmi AI, une startup autrichienne spécialisée dans la Physics AI. The post Mis
En un an, la marque Joule, réceptacle de capacités génératives et agentiques, a pris du volume. En voici quelques incarnations. The post Comment SAP a
Akamai met la main sur LayerX, une startup israélienne spécialisée dans la sécurisation des interactions entre les collaborateurs et les outils d'IA g
Edge ne met plus les mots de passe en mémoire au démarrage. Microsoft maintient toutefois que ce comportement est normal au regard du modèle de menace
Anthropic s'apprête à alerter le Financial Stability Board sur les vulnérabilités que son dernier modèle d'IA a identifiées dans les systèmes bancaire
Le modèle OCPM se répand dans les solutions de gestion des processus métier, favorisant la constitution d'un socle de contexte pour les IA. The post G
À l'occasion de la publication de son rapport d'activité 2025, la Direction générale des Finances publiques (DGFiP) explique son « utilisation raisonn
{ Tribune Expert } - Le Product Builder est capable d'assembler des outils no-code et des API d'intelligence artificielle pour créer des applications
Publicis met la main sur l'américain LiveRamp pour 2,2 milliards $. Un pari stratégique pour devenir un leader de la co-création de données et l'IA. T
Les IA rebattent les cartes des bug bountys publics, qui ont du mal à suivre le rythme... et à séparer le bon grain de l'ivraie. The post Les bug boun
Introduction Continuous Integration and Delivery is a key part of any software application. Be it a mobile app, a backend app or a website - everythin
Who This Is For If you are using AWS Lambda to build serverless applications and you have never stopped to look closely at the IAM roles attached to y
Building a Smarter Scheduler: Priority Queues and Layered Execution Luciano0322 Luciano0322 Luciano0322 Follow May 21 Building a Smarter Scheduler: Pr
Recap In the previous article, we explored the relationship between the Scheduler and the dependency Graph, and discussed the challenges of memory man
Article Metadata Field Value Document type Global product and technical evaluation Audience Product Manager, Engineering Manager, Backend Team, Archit
IT InstaTunnel Team Published by our engineering team The OAuth Tunnel Trap: Preventing Subdomain Hijacking in Local Development The OAuth Tunnel Trap
RS256 JWT flow between two microservices, then how Spring actually validates it internally. how Spring Security internally validates that JWT step by
This is a submission for the Google I/O Writing Challenge Google I/O 2026 had a lot of shiny objects. Gemini Omni simulating intuitive physics. Smart
Ask five AI engineers which vector database to use for your RAG system. You'll get five different answers, and they'll all start with "it depends." It
Wrapping Hermes Agent with agent-stack: six tiny libs for the boring parts The day my agent silently broke A customer pinged me on a Tuesday. The repl
I had a fantasy. The fantasy was that programmatic SEO would let me skip the part where you write 200 individual articles and trick Google into rankin
For personal use and work email, emails are an essential way of communicating. A common method used to keep individual email messages in storage is th
The OSI is pleased to support the inaugural Open Technology Research (OTR) Symposium 2026, taking place on 26–27 October 2026 at the historic Universi
Survivre sans Internet ? Les makers ont déjà commencé Comments
“BudsLink est une application open-source indépendante qui a la particularité de communiquer directement avec vos écouteurs Bluetooth.” Comments
GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a
Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve rem
CVE ID :CVE-2026-9152 Published : May 21, 2026, 2:16 a.m. | 2 hours, 56 minutes ago Description :A missing authentication vulnerability exists in the
CVE ID :CVE-2026-48172 Published : May 21, 2026, 2:16 a.m. | 2 hours, 56 minutes ago Description :LiteSpeed User-End cPanel Plugin before 2.4.5 allows
CVE ID :CVE-2026-40165 Published : May 21, 2026, 12:16 a.m. | 4 hours, 56 minutes ago Description :authentik is an open-source identity provider. Vers
CVE ID :CVE-2026-8632 Published : May 20, 2026, 9:16 p.m. | 7 hours, 56 minutes ago Description :A potential security vulnerability has been identifie
CVE ID :CVE-2026-8631 Published : May 20, 2026, 9:16 p.m. | 7 hours, 56 minutes ago Description :A potential security vulnerability has been identifie
CVE ID :CVE-2026-9144 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8
CVE ID :CVE-2026-9141 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8
CVE ID :CVE-2026-9139 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8
CVE ID :CVE-2026-9136 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :A vulnerability was identified in the ShadowAttribute
CVE ID :CVE-2026-9133 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Active debug code exists in the ARN resolver of amazo
CVE ID :CVE-2026-9129 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :A path traversal vulnerability exists in the Altium E
CVE ID :CVE-2026-9126 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in DOM in Google Chrome on prior to 14
CVE ID :CVE-2026-9121 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Out of bounds read in GPU in Google Chrome on prior t
CVE ID :CVE-2026-9120 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in WebRTC in Google Chrome prior to 14
CVE ID :CVE-2026-9119 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Heap buffer overflow in WebRTC in Google Chrome on pr
CVE ID :CVE-2026-9118 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in XR in Google Chrome on Windows prio
CVE ID :CVE-2026-9114 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in QUIC in Google Chrome on prior to 1
CVE ID :CVE-2026-9112 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in GPU in Google Chrome on Windows pri
CVE ID :CVE-2026-9111 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Use after free in WebRTC in Google Chrome on Linux pr
CVE ID :CVE-2026-9102 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :A path traversal vulnerability exists in the Altium E
CVE ID :CVE-2026-45444 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Unrestricted Upload of File with Dangerous Type vuln
CVE ID :CVE-2026-39405 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Frappe Learning Management System (LMS) is a learnin
CVE ID :CVE-2026-39352 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Frappe is a full-stack web application framework. Ve
CVE ID :CVE-2026-39310 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :Trilium Notes is a cross-platform, hierarchical note
CVE ID :CVE-2026-33137 Published : May 20, 2026, 8:16 p.m. | 8 hours, 56 minutes ago Description :XWiki Platform is a generic wiki platform offering r
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intellig
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliv
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that empl
New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the fi
GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed th
AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-da
Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compr
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié
De multiples vulnérabilités ont été découvertes dans Suricata. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distanc
De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio
Une vulnérabilité a été découverte dans Wireshark. Elle permet à un attaquant de provoquer un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans Symfony. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à dist
De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de service à distance et un problè
Une vulnérabilité a été découverte dans F5 NGINX. Elle permet à un attaquant de provoquer une exécution de code arbitraire et un déni de service à dis
De multiples vulnérabilités ont été découvertes dans Docker. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.
De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécut
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Elles permettent à un attaquant de provoquer une élévation de privilèges et un
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécut
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The acti
Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privileg
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC.
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be ex
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Co
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run ma
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the
De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données
De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problème de sécurité non
Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer un problème de sécurité non
INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the ident
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fa
What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is t
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted softwa
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authen
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC)
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud wor
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulat
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à d
De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non s
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure,
Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and downl