← Retour

Veille tech — 2026-06-11

Veille Tech — jeudi 11 juin 2026

> 102 articles · 7 sources · 4 derniers jours

Forge logicielle

Security: Important security fixes.

Intelligence Artificielle

As adoption of AI agents looks set to surge by as much as 300% in the next two years, leadership teams are carefully considering the implications of a hybrid human-AI enterprise.

At SXSW London last week I gave a talk called "Five things you need to know about AI," in which I shared what I think are the biggest themes in AI right now.

Autres

I scanned 62 Lovable apps in early 2026. 63% had critical or high severity vulnerabilities. The average app had 10 findings.

There is a conversation that happens in security teams constantly, and it almost never goes anywhere useful.

Your users will never read your happy path. They will, however, find every edge case.

The complete set of technical controls, architecture patterns and data handling procedures for LLM and GenAI security.

Five fields, forty wells, five hundred people — a synthetic simulation for AI-driven industrial operations.

What do you build once you've mastered the blinking LED? PIO, sensors and ML on the Pico.

We accidentally built a brain — software that kept reaching for the same trade-offs and architectural patterns.

The reason BoxAgnts' tool system can uniformly manage Rust built-in functions, WASM sandbox components and external tools.

These 8 creators actually teach you something real: from bash scripting to kernel internals.

A reflection on whether "old school" engineering content still resonates with today's developers.

On the importance of psychological safety in developer communities.

A 3-AI pipeline approach to building a design system using Google Stitch, ChatGPT and Claude.

Members Newsletter – June 2026. G7's Vision on AI Openness and the EU's Tech Sovereignty Package.

Réflexion sur les conséquences concrètes des grandes fuites de données françaises (France Travail, Free, FICOBA, etc.) et sur une approche de compartimentation numérique.

Sécurité

The Hacker News — sécurité/cyber

Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors.

Fortinet, Ivanti, and SAP have released security updates to address multiple critical vulnerabilities that could result in arbitrary code execution.

A high-severity unpatched flaw in Langflow, an open-source low-code AI platform, has come under active exploitation for unauthenticated RCE.

The U.S. CISA added three new vulnerabilities to its Known Exploited Vulnerabilities catalog amid active exploitation.

Run automated pentesting long enough, and the new findings start to dry up — but that doesn't mean you're secure.

Microsoft released fixes for a record 206 security vulnerabilities, including three actively exploited zero-days.

Anthropic released Claude Fable 5, its most capable model ever, alongside dedicated cyber safeguards.

ServiceNow has warned of a security incident where unknown threat actors exploited a flaw to gain deeper unauthorized access to customer instances.

Researcher Chaotic Eclipse released a PoC exploit for a Microsoft Defender zero-day granting SYSTEM access on fully updated Windows.

Six vulnerabilities in protobuf.js, a JavaScript/TypeScript implementation of Protocol Buffers, expose Node.js apps to RCE and DoS.

Meta announced it will use information shared by third-party businesses to personalize users' feed and AI responses.

Veeam released patches to address a critical flaw in Backup & Replication that allows domain users to run remote code.

Microsoft temporarily removed some GitHub repositories in response to the Miasma security incident affecting 73 open-source projects.

Two Russia-aligned campaigns continue to exploit a WinRAR flaw to deploy credential stealers against Ukrainian organisations.

University of Toronto researchers built a proof-of-concept AI worm that self-replicates using a locally hosted open-weight LLM.

Google released updates addressing 74 vulnerabilities including one actively exploited V8 zero-day — patch immediately.

Organizations have more visibility than ever, yet the real risk lies in the gaps between security tools.

A malicious website can determine which sites you visit and apps you open using only JavaScript and SSD access timing.

The Miasma supply chain campaign spawned a new wave "Hades" — 37 malicious wheel artifacts across 19 PyPI packages that auto-run a Bun credential stealer.

CISA added a high-severity LiteLLM flaw to its KEV catalog — chains to unauthenticated remote code execution.

Security researchers published a working exploit for a Linux kernel use-after-free allowing unprivileged local users to escalate to root.

Meta detected and blocked spear-phishing attempts linked to NSO Group targeting WhatsApp users, and filed a contempt order.

Check Point warns of active exploitation of a critical flaw in Remote Access VPN and Mobile Access deployments using IKEv1.

AI has turned phishing into a volume machine, overwhelming SOC Tier 1 with alert fatigue.

Last week: poisoned packages, a broken AI helper, and a worm tearing through GitHub repos.

Mythos is real — a threat whose findings are bad enough to shake confidence in a major chunk of the security industry.

China-nexus espionage group VerdantBamboo deploys a BSD variant of the BRICKSTORM backdoor on Linux appliances.

Details of a financially motivated data theft extortion campaign by UNC3753 combining vishing and physical intrusions.

Visual Studio Code will delay extension auto-updates by two hours to reduce the risk of supply chain attacks.

CERT-FR Avis — sécurité/CERT-FR

Élévation de privilèges.

Exécution de code arbitraire à distance.

Élévation de privilèges.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Élévation de privilèges et déni de service à distance.

Exécution de code arbitraire à distance.

Atteinte à la confidentialité des données.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Contournement de la politique de sécurité.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Déni de service à distance et exécution de code arbitraire.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Déni de service à distance.

Élévation de privilèges.

Problème de sécurité non spécifié par l'éditeur.

Problème de sécurité non spécifié par l'éditeur.

Problème de sécurité non spécifié.

Exécution de code arbitraire à distance.

Élévation de privilèges.

Contournement de la politique de sécurité.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Exécution de code arbitraire à distance.

Injection SQL et exécution de code arbitraire à distance.

Problème de sécurité non spécifié.

Problème de sécurité non spécifié.

Déni de service à distance.

Contournement de la politique de sécurité.


Sources consultées