← Retour

Veille tech — 2026-07-13

Veille Tech — lundi 13 juillet 2026

> 73 articles · 6 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;` — Le flux GitHub Releases de Harbor rejette la requête (403), probablement un blocage anti-bot côté GitHub sur ce User-Agent.

>

> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient des liens `<link>` mal formés (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Les 3 liens ci-dessous ont été reconstruits manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.


Intelligence Artificielle

The AI firm Anthropic has developed a technique that has given it the clearest glimpse yet at what’s really going on inside large language models as t

Santé numérique

L'Agence du Numérique en Santé (ANS), en lien avec la Délégation au numérique en santé (DNS), a retenu 21 lauréats dans le cadre de la phase explorato

Le 14e Comité des entreprises du numérique en santé (ENS) s'est tenu le 9 juillet 2026, réunissant les représentants de la Délégation au numérique en

La journée des Grandes Tendances de la e-santé revient pour sa 11ème édition, le mardi 26 janvier, à Station F !Elle s'articule autour de quatre temps

Autres

Hello Dev Community! 👋 It is officially Day 145 of my software engineering marathon! Today, I locked down the definitive user document model layer for

FootLegends⚽🤖 Our Passion Project Football is pure passion. The debate over who is the true GOAT (Greatest of All Time) drives endless, heated discuss

Episode 3 covered detection — how a system finds out something broke. Episode 4 is the next link: detection told you something's wrong, now what? Satu

Integrating Specmatic into my NL-to-SQL engine (DATABASE-MANAGER) Submitted for the Specmatic Full Stack AI Engineering Intern challenge. The problem

Hello Dev Community! 👋 It is officially Day 144 of my software engineering marathon! Today, I successfully wireframed and executed the foundational ga

I need to get the disclosure out of the way first, because it is the whole point of this post. The company I work for was founded three days ago. Reve

Lovable is genuinely good at one thing: getting you from a text prompt to a working-looking web app in under an hour. For early-stage validation and i

Every product team ships an API before it ships a UI now. Mobile apps, partner integrations, internal microservices, and the AI agents plugging into y

Раскрытие и доступность: DaoXE — мультимодельный мультипротокольный API-шлюз, который мы эксплуатируем. Он поддерживает OpenAI Chat Completions, OpenA

As developers, we spend a lot of time looking for ways to write better code. We learn new frameworks, study design patterns, and explore the latest to

利益关系与地区说明:DaoXE 是我们运营的多模型、多协议 API 网关,支持 OpenAI Chat Completions、OpenAI Responses、Anthropic Messages(Claude 协议)以及兼容的图片生成接口。DaoXE 不向中国大陆提供服务;本文仅供服务条款允许地

I message myself things on MS Teams so I won't forget them. A feature to add, a bug to fix, some idea I want to try. Then I forget them anyway. The me

Sécurité

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026,

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations underta

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitra

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm regist

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers,

Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully expl

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cyb

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of complet

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking to

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics peo

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to e

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet soft

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring

De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Certaines d'entre elles permettent à un attaquant de provoquer une élév

Une vulnérabilité a été découverte dans NetApp ONTAP 9. Elle permet à un attaquant de provoquer un déni de service à distance et une atteinte à l'inté

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans Suricata. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l

De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une éléva

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exé

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une attein

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer un déni de servi

De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non s

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories,

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destruct

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wan

AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait,

Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software a

Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The

Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content,

Erreur 403 | #84 - Un agent IA de GitHub détourné pour exfiltrer des dépôts privés Prompt injection GitLost exfiltrant des dépôts privés via u

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the find

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's compu

Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residenti

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans Wireshark. Elles permettent à un attaquant de provoquer un déni de service à distance et une atte

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confiden

De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurit

De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une

De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer u

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non s


Sources consultées