← Retour

Veille tech — 2026-06-01

Veille Tech — lundi 1er juin 2026

> 51 articles · 6 sources · 4 derniers jours


Forge logicielle

We are removing the sonar.login property from SonarQube Cloud scanners. This property was deprecated in July 2023.


Intelligence Artificielle

Pope Leo XIV's new encyclical on artificial intelligence includes a statement that warrants serious attention from technologists and policymakers.

It is one thing to say AI will change the world. It is another to expect the class of 2026 to applaud it — when former Google CEO Eric Schmidt spoke, he was booed.


Autres

When building React applications, passing data from one component to another is common. Initially, props work well. But what happens when data needs to travel deeper?

Over the last while I worked out how to make AI assistants answer "who are you?" about a real person — a practical guide to building an entity footprint.

Most AI workflow failures do not happen because the prompt is too short. They happen because the prompt is the only thing holding the process together.

A GitHub Actions workflow that auto-publishes Zenn articles and books daily, with a solution for the UTC timezone pitfalls.

LLM → Prompt : vue d'ensemble de l'architecture Client-Server des systèmes IA et du rôle de la context window.

Gemini 3.5 Flash is Google's new Flash-tier coding model, generally available since May 19. A comparative guide from a Claude user's perspective.

JEPA learns a generalized semantic representation of images by predicting abstract representations rather than pixel-level details.

A deterministic infrastructure foundation in Rust, open-sourced with a focus on the base layer only.

Shopify ships a new GraphQL Admin API version every quarter. The 2025-01 release changed heldBy silently — your query still returns 200 OK but the data is wrong.

A practical guide to every CLI command, flag, and in-session slash command you need to get productive with Claude Code fast.

Extreme KV-Cache Compression and Long-Context Efficiency. Static quantization giving way to rotation-based and context-sensitive schemes.

After a couple of years of AI hype, a professional software engineer argues that good snippets may be faster and more reliable for many workflows.

Erreur 403 #78 — Campagne Megalodon piégeant 5700 dépôts GitHub et nouvelle fuite chez Almerys.


Sécurité

Menaces & incidents

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT.

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation.

Cybersecurity researchers have disclosed a vulnerability in OpenAI ChatGPT that leverages the AI assistant's web summaries as a phishing vector.

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access.

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing attacks targeting Ukraine and Ukraine-related entities.

Shadow AI now means employees building full applications with AI-generated code — exposed, unreviewed, and outside standard security stacks.

A malicious NuGet package masquerades as a C# SDK for Sicoob, one of Brazil's largest banking networks, to steal credentials.

The North Korean state-sponsored threat actor Kimsuky (aka Velvet Chollima) has expanded its arsenal with new tools targeting South Korean entities.

A critical security vulnerability in Gogs, a popular open-source self-hosted Git service, allows an authenticated user to execute arbitrary code.

Threat actors are continuing to exploit a critical, now-patched flaw in FortiClient Endpoint Management Server to deploy credential stealers.

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging researchers to share findings before going public.

Round-up hebdomadaire de menaces : loaders suspects, contournement MFA, élévation de privilèges Azure et escroqueries autour de la FIFA.

A new campaign by a previously undocumented threat actor targets cryptocurrency organizations via fake recruiter lures delivering macOS malware.

The State of AI Usage Report 2026 by LayerX Security reveals the extent of the enterprise AI visibility gap.

Avis CERT-FR

Exécution de code arbitraire à distance. Mise à jour recommandée.

Problème de sécurité non spécifié par l'éditeur.

Élévation de privilèges et autres vecteurs d'attaque identifiés.

Exécution de code arbitraire à distance.

Élévation de privilèges sur les noyaux Ubuntu concernés.

Élévation de privilèges sur les noyaux SUSE concernés.

Élévation de privilèges sur les noyaux Red Hat concernés.

Élévation de privilèges sur les noyaux Debian concernés.

Exécution de code arbitraire à distance dans plusieurs produits IBM.

Problème de sécurité non spécifié par l'éditeur.

Problème de sécurité non spécifié par l'éditeur.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance dans les produits Veeam.

Déni de service à distance et contournement de politique de sécurité dans GitLab.


Sources consultées