← Retour

Veille tech — 2026-07-23

Veille Tech — jeudi 23 juillet 2026

> 71 articles · 8 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;` — Le flux GitHub Releases de Harbor rejette la requête (403), probablement un blocage anti-bot côté GitHub sur ce User-Agent.

>

> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient un lien `<link>` mal formé (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Les liens ci-dessous ont été reconstruits manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.


Forge logicielle

RFE: Stop bundling the JUnit, Mailer, Matrix Authorization Strategy, Matrix Project, and OWASP Markup Formatter plugins, reducing the size of jenkins.

Intelligence Artificielle

The conversation about AI often centers on algorithms, computing power, or huge investments in new semiconductor fabrication plants and hyperscale dat

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Over the wee

The next time you apply for a job, AI may screen your résumé before any human sees it. But there’s good reason to question whether AI will judge you f

Santé numérique

la Délégation au numérique en santé (DNS) organisera, le jeudi 8 octobre 2026 de 14 h à 17 h 30, une après-midi dédiée au règlement relatif à l'Espace

Un référentiel modernisé au service des acteurs de la santéLe répertoire national des établissements sanitaires, sociaux et médico-sociaux (FINESS) fr

Les Rencontres de l'ANS reviennent pour une deuxième édition consacrée à l'Europe du numérique en santé !L'Agence du Numérique en Santé vous donne ren

La publication au Journal officiel de l’arrêté relatif au dispositif du Ségur du numérique en santé marque une nouvelle étape dans le déploiement du p

Vitale DAYS 2026 : les inscriptions sont ouvertes !Les 13 et 14 octobre prochains, le GIE SESAM-Vitale réunira au Pathé Le Mans les acteurs du numériq

Les documents préparatoires de la vague 2 du dispositif Logiciels de Gestion d'Officine (LGO) du Couloir Officine du Ségur du numérique en santé sont

Autres

Almost everything written about game networking is about fast games. The classic material covers UDP and client-side prediction, in service of squeezi

Celtrix - A modern flexible CLI tool to scaffold end-end web projects. Today, developers have many tools to build web apps. But setting everything up

The lakehouse community spent this week deciding what belongs in the format and what belongs outside it. Iceberg contributors pushed to retire equalit

The VPN I share with a few other people ran out of traffic for the month. I had an idle OCI ARM instance sitting there doing nothing, so I decided to

Hello world, it's Wednesday, July 22, 2026, and here's what happened This Week in PHP Internals. 20 stories this week, so let's get into it. But first

We have our keys. Now we write the script. By the end of this chapter, you'll understand exactly what the code does and why — line by line, in plain E

In the previous post in my "Claude Code environment" series, automatically pruning zombie agents, I wrote about finding agents that are defined but ne

A browser tool that points your own API key at an adversarial battery and grades every answer with pure predicates — no LLM judge, and your key never

Search is no longer just a box on a website. In many deployments, Manticore Search behaves more like an internal data service: applications query it,

Key Takeaways One codebase. Two platforms. That’s it. Write once, runs on iPhone and Android both. Not a web page dressed up as an app — actual native

How to Handle Overdue Security Alerts Before They Become Breaches A Manager s Guide Back to blog Just How Bad Has the Backlog Problem Gotten? The Hidd

The Hardcoded UI Bottleneck In traditional frontend architecture, the UI layout is hardcoded into the client application. If the marketing team wants

Sécurité

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vul

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right g

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," w

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely u

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries:

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attack

Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affe

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer un déni de s

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Elles permettent à un attaquant de provoquer une exécution de

De multiples vulnérabilités ont été découvertes dans GLPI. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données,

De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermini

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a develo

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash th

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTow

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly wh

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post s

De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécu

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI)

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofin

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smugg

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled securit

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds t

The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already over

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how

A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intell

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonom

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems

Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci p

De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spéci

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des donné

De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distan

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series

Sources consultées