← Retour

Veille tech — 2026-07-02

Veille Tech — jeudi 2 juillet 2026

> 83 articles · 6 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases, Le Monde Informatique

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;` — Le flux GitHub Releases de Harbor rejette la requête (403), probablement un blocage anti-bot côté GitHub sur ce User-Agent.

> - Le Monde Informatique : `TimeoutError: The read operation timed out` — Le serveur n'a pas répondu dans le délai imparti lors de la récupération du flux RSS.


Forge logicielle

RFE: Display operating system end of life messages when we are within 6 months of the end of life for Alpine Linux 3.21 - 3.24, CentOS Stream 9 - 10,


Intelligence Artificielle

Let’s start with a game. Open up your chatbot of choice—Claude, ChatGPT, Gemini—and type “Give me a random number between 1 and 10.” You’re going to g

At an event for pharmaceutical executives, biotech founders, and researchers on Tuesday, Anthropic announced Claude Science, a major new product inten

Artificial intelligence is transforming what is possible in agriculture, but industry leaders should be wary of investing in AI without first laying t

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Imagine comi

Enterprise investment in AI is booming. Gartner is calling 2026 an “inflection year” for organizations to align their AI projects with strategic busin


Autres

Step-by-step VPS hardening for Ubuntu — create a sudo user, lock down root, configure UFW, change your SSH port, and set up Fail2Ban. tags: linux, sec

If you ask an LLM for structured output and validate it against a schema, you already know the failure mode: most of the time it is fine, and every so

Build Analyzer series, article 2. In the previous article, I built 16 Android APKs while changing one variable at a time. After that, I had the APK nu

This continues from Part ②. Does any of this sound familiar? After a customer meeting, activity entries in the SFA get missed — materials don't get se

Merging full‑attention and linear‑attention at the head granularity slashes transformer FLOPs without appreciably hurting downstream quality. The tric

Starting a new project should be simple. Clone the repository, install dependencies, run the app, and start building. But in many PHP projects, develo

Want to build an AI assistant that talks to your company documents? First you need to answer one question: which RAG method actually works best on YOU

I Coined a New Word: Breator For years, we've used words like creator, founder, and entrepreneur to describe people who build businesses. But while th

AI is great at writing tests fast, and good at writing tests that look real but verify the wrong thing. Here's the line between useful scaffolding and

The Silent Killer: Why Webhook Idempotency Matters You deploy a webhook handler that charges a customer $50 on every payment.completed event. The paym

A few months ago I built an internal desktop tool for my company using Electron. It runs on machines across every branch office — different cities, di

Article image How to Structure and Bill Clients for Website Maintenance & Renewals Introduction: The Operational Leakage in Agency Renewals For most w

Les explications du comment ça marche ? et une knod box de plus pour jouer. Comments


Sécurité

Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated atta

A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer in

Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part

Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an in

A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet's FortiGuard Labs identified the campa

Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates

Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on a

A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from e

Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic bro

Organizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging.

Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essentia

Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then

Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable

Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI)

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind

Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Ga

Une vulnérabilité a été découverte dans Mozilla Firefox. Elle permet à un attaquant de provoquer une exécution de code arbitraire.

De multiples vulnérabilités ont été découvertes dans Adobe ColdFusion. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

De multiples vulnérabilités ont été découvertes dans les produits Citrix. Certaines d'entre elles permettent à un attaquant de provoquer un déni de se

New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to ma

A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them i

Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner.

Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet ad

The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has

Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic.

The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been bui

An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unrep

Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables

Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from se

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sendin

A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerabili

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer une injection de co

De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à

De multiples vulnérabilités ont été découvertes dans Synology MailPlus Server. Certaines d'entre elles permettent à un attaquant de provoquer un déni

WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion us

Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed

Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities

The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware a

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door

New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-sour

Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will so

A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against

Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font fi

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory cor

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à d

De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non s

De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spéci

Une vulnérabilité a été découverte dans HAProxy. Elle permet à un attaquant de provoquer un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code ar

De multiples vulnérabilités ont été découvertes dans Stormshield Management Center. Elles permettent à un attaquant de provoquer une exécution de code


Sources consultées