← Retour

Veille tech — 2026-06-25

Veille Tech — jeudi 25 juin 2026

> 68 articles · 7 sources · 4 derniers jours


Forge logicielle

RFE: Accept ECDSA and Ed25519 private keys for access to the Jenkins command line interface. RFE: Decrease padding for experimental UI details bar.


Intelligence Artificielle

AI is booming. New use cases are emerging each day. To capitalize on the technology's potential, enterprises require data at scale.

Jos Benschop is climbing a ladder to get to the top of his newest machine. It's a bit of a schlep. The contraption is the size of a double-decker bus.

This story originally appeared in The Algorithm, our weekly newsletter on AI. For those of you following the drama around AI and the US government, there are now several competing storylines.


Autres

I'm not a software engineer. For over a decade, I worked in the local hospitality scene in Kanagawa, Japan — bartending, managing. AI changed everything.

OpenAI trained Whisper on 680,000 hours of audio, and the small models that came out of it run on a laptop CPU in real time.

Honestly, I didn't expect to be writing this fourth entry so quickly.

OpenAI's Whisper model runs accurate speech-to-text on a laptop GPU, and the C++ port runs it without Python or a cloud account.

The Cerebras stock plunge after its first earnings report is a good reminder that the AI chip business runs on margins, not hype.

When you invite a cloud notetaker to a call, a bot joins, records everyone, and ships the audio to a vendor's servers.

Most FastAPI tutorials end at "it works in English." But the moment you ship to users in Germany, Brazil, or Japan, you realize FastAPI has no built-in i18n.

Your editor, your terminal scripts, and half the AI tools you installed last month all speak the same protocol: the OpenAI HTTP API.

A modern laptop GPU can run a capable language model and read text off a screenshot in the time it takes you to switch windows.

The GPU in a modern laptop can run the same image models that power paid services like Midjourney.

The Model Context Protocol lets an AI assistant talk to your tools through a standard interface, and the spec is open.

Your GPU cluster is maxed out. Not because you're running inference at scale — because that "simple" web UI you deployed eighteen months ago is quietly accumulating state.

The OSI is pleased to announce the launch of the Open Source AI Fellowship at UN Open Source Week.

Pas axé logiciel libre mais très bon article de ce blog au sujet des indicateurs de performance.

Ma recherche d'une alternative à Sweepy pour les tâches ménagères de la maison en vue de le mettre à disposition sur une tablette tactile en auto-hébergement.

TypeScript 7 est en Release Candidate. Et pour une fois, le gros changement n'est pas une nouvelle syntaxe. Tout le compilateur a été réécrit en Go.


Sécurité

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000.

A coordinated law enforcement operation, in partnership with Bitdefender, Bitsight, ESET, and Microsoft, has resulted in 27 million stolen credentials recovered.

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.

We are standing at the end of an era we never thought to mourn: the era of human-speed threats.

The U.S. Department of Justice announced the seizure of a cloud computing account used by subsidiaries of Cambodia-based corporation for money laundering.

Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager and Unified CM SME.

De multiples vulnérabilités ont été découvertes dans Tenable Identity Exposure. Certaines permettent une exécution de code arbitraire à distance.

De multiples vulnérabilités ont été découvertes dans cURL et libcurl. Certaines permettent un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux.

A Russian-speaking initial access broker driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed.

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents.

President Trump signed an executive order setting hard deadlines for federal agencies to move high-value assets to post-quantum cryptography by 2030.

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks.

Every weapon begins as an extension of the hand that holds it. The bow sent the point flying without the thrower's arm following. Agentic AI is the next step.

Cybersecurity researchers have discovered a set of malicious npm packages designed to deliver a Windows-based remote access trojan (RAT).

Direct messages sent via WhatsApp are being used to distribute malicious VBScript files that lead to the installation of legitimate RMM software.

OpenAI is releasing an improved version of its GPT-5.5-Cyber model to trusted defenders as part of the Daybreak initiative.

De multiples vulnérabilités ont été découvertes dans Moodle. Certaines permettent un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans Squid. Elles permettent une atteinte à la confidentialité des données.

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official repository.

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including credentials or session tokens, to any client.

Cybersecurity researchers have disclosed four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars.

Cybersecurity researchers have disclosed a new campaign that delivers CastleStealer via a previously unreported malware loader dubbed OXLOADER.

Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries.

A blind spot most security programs are still not accounting for: legacy infrastructure that becomes an attack surface for AI agents.

This week's threat list: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools.

Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear on Canadian soil to neutralize two botnets.

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network.

A new report from INTERPOL reveals a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization.

Une vulnérabilité dans PaperCut Print Deploy Client permet une exécution de code arbitraire.

Une vulnérabilité dans CPython pour Windows permet une atteinte à la confidentialité des données.

De multiples vulnérabilités ont été découvertes dans Microsoft Edge.

De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent une atteinte à la confidentialité des données.

De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent un déni de service à distance et un problème de sécurité.


Sources consultées