← Retour

Veille tech — 2026-07-16

Veille Tech — jeudi 16 juillet 2026

> 87 articles · 9 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;` — Le flux GitHub Releases de Harbor rejette la requête (403), probablement un blocage anti-bot côté GitHub sur ce User-Agent.

>

> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient un lien `<link>` mal formé (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Le lien ci-dessous a été reconstruit manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.


Forge logicielle

Hi everyone, We’re excited to share that SonarQube Cloud now supports GitHub Enterprise Cloud with data residency (*.GHE.com). If your organization ru

RFE: Move password complexity rule classes from hudson.security to jenkins.security package RFE: humanreadable text Major RFE: Refresh the status icon

Intelligence Artificielle

OpenAI has built an LLM super-hacker called GPT-Red that it uses as a sparring partner to help its other models boost their defenses against cyberatta

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Anthropic—cu

Santé numérique

L'Agence du Numérique en Santé (ANS), en lien avec la Délégation au numérique en santé (DNS), a retenu 21 lauréats dans le cadre de la phase explorato

Autres

B2B software applications must provide security audits to sell to enterprise customers. When moving upmarket, corporate buyers require a detailed hist

Hello Dev Community! 👋 It is officially Day 155 of my software engineering track! Today, I brought the interactive catalog of Tomato — The Food Delive

JavaScript ถือกำเนิดมาพร้อมปรัชญาความยืดหยุ่นสุดขั้ว ตัวแปรตัวหนึ่งสามารถเปลี่ยนชนิดข้อมูลได้ตลอดเวลาโดยไม่มีการเตือนจากตัวภาษาเลยแม้แต่น้อย ในยุคที่เ

I spent the last few days doing something slightly obsessive: I opened every single past challenge on dev.to/challenges, clicked into each one, found

This is a continuation of my "Claude Code environment" series. After the previous post on automating git-config backups, this time I'm tackling a prob

The problem nobody built for Walk into any Indian neighborhood and you'll find one within 200 meters: a kirana store. A shopkeeper who knows your fami

Creating objects is one of the most fundamental operations in Java. Most developers use the new operator every day, but Java also allows objects to be

For over seven years, I have built a deeply rewarding career as a software engineer. I love the code I write and the systems I build. Yet, my true cal

An AI agent can generate a valid tool call and still have no legitimate identity behind the action. Consider a refund tool: { "order_id": "ORD-1042",

Every support team that puts a bot on WhatsApp eventually hits the same wall. The bot handles the easy questions well. Then a customer asks something

Liquid syntax error: Variable '{{% raw %}' was not properly terminated with regexp: /\}\}/

TC Games is a capable Windows-focused way to mirror a real Android phone and play with keyboard and mouse. Its official documentation includes key map

‘Fabrication humaine’ est le slogan d’une génération de créateurs… humains ; leur propos étant la valorisation de l’œuvre humaine. Comments

Dans cette nouvelle version, on peut maintenant collectionner des fragments pour débloquer des contenus. Comments

Outil en JavaScript pur (aucune donnée envoyée au serveur) : 11 options combinables pour générer un .htaccess propre pour WordPress — HTTPS forcé, en-

Locahl est une app de bureau pour gérer son fichier hosts sans passer par le terminal : édition d’entrées, bascule entre environnements dev/staging/pr

Sécurité

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities ar

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model st

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer dat

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no w

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Se

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which

Le 14 juillet 2026, Sonicwall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabil

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à d

De multiples vulnérabilités ont été découvertes dans Microsoft Office. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à

De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution d

De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de c

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à

De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécut

De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoquer un problème de sécurité non s

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans Sonicwall Secure Mobile Access 1000. Elles permettent à un attaquant de provoquer une exécution d

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un contournement de la politique de s

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

Une vulnérabilité a été découverte dans Veeam Backup & Replication. Elle permet à un attaquant de provoquer une élévation de privilèges.

De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécuti

De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio

Une vulnérabilité a été découverte dans Schneider Electric EcoStruxure. Elle permet à un attaquant de provoquer un contournement de la politique de sé

Une vulnérabilité a été découverte dans ESET Inspect Connector. Elle permet à un attaquant de provoquer une élévation de privilèges.

De multiples vulnérabilités ont été découvertes dans Progress LoadMaster. Elles permettent à un attaquant de provoquer une exécution de code arbitrair

Une vulnérabilité a été découverte dans Xen XAPI. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

De multiples vulnérabilités ont été découvertes dans les produits Citrix. Certaines d'entre elles permettent à un attaquant de provoquer une élévation

Une vulnérabilité a été découverte dans Tenable Nessus Agent. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et u

De multiples vulnérabilités ont été découvertes dans Mozilla Firefox. Elles permettent à un attaquant de provoquer un contournement de la politique de

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release cover

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver A

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc a

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow at

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomwa

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments wit

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromise

Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researc

Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is tha

Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email ca

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, a

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you

A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Sm

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. Th

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensio


Sources consultées