> 75 articles · 7 sources · 4 derniers jours
> ⚠️ Flux indisponibles : Harbor Releases
> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;` — Le flux GitHub Releases de Harbor rejette la requête (403), probablement un blocage anti-bot côté GitHub sur ce User-Agent.
>
> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient un lien `<link>` mal formé (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Le lien ci-dessous a été reconstruit manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.
Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of
Le 14e Comité des entreprises du numérique en santé (ENS) s'est tenu le 9 juillet 2026, réunissant les représentants de la Délégation au numérique en
What should happen after an AI Agent spends time diagnosing and fixing a real problem? Today, the answer is usually: not much. The solution stays insi
A follow-up to I built an AI dev harness that isn't allowed to trust itself. The harness I wrote about isn't allowed to trust itself. That was the who
A quick note upfront: I'm barely scratching the surface here. I'm not a performance-engineering expert, and most of this was new to me a couple of wee
What happened On 2026-07-25, I (Zen, acting CTO of nokaze — an operation run jointly by a human owner and AI partners) spent the morning-to-afternoon
ez-ffmpeg is a Rust crate that runs FFmpeg pipelines inside your process — linked libav libraries behind a high-level API, no subprocess (and no relat
Originally published on aniljaiswal.com. The GitOps demo is gorgeous. One repo, one app, one cluster. You change a value in Git. A few seconds later,
One line can hide your whole site from Google Disallow: / in your robots.txt tells every crawler to ignore your entire site. It's shockingly common —
Your cron is lying to you. Here's how to catch silent failures. Most production apps run cron jobs, queue workers, and scheduled tasks. And most of th
🏗️ Building a Tokenization Ecosystem: MyZubster Gateway × Singapore Real Estate The Vision "What if anyone could invest in prime Singapore real estate
What is Selenium? Selenium is an open-source tool that lets you automate pretty much anything a real person would do in a web browser. Instead of just
A decade ago, moving to the cloud was seen as a major competitive advantage. Today, it feels like the starting point for building modern software. Whe
The Pragmatic Arbitrage: Why US Developers are Quietly Swapping Proprietary APIs for Chinese Open-Weights The global AI landscape is undergoing a quie
Every AI system in the headlines today, whether proprietary or Open Source, exists because researchers shared their work openly. That openly shared re
Erreur 403 | #86 - Des agents d’IA d’OpenAI compromettent Hugging Face et exploitation active d’une RCE dans WordPress Core Des agents d’IA d’OpenAI c
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boo
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It r
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords,
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operat
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. A
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up
De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurit
Une vulnérabilité a été découverte dans NetApp ONTAP 9. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confi
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une éléva
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une attein
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exé
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privi
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilège
Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload g
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confin
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant beh
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud i
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastruc
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tec
RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) product
De multiples vulnérabilités ont été découvertes dans les produits Mitel. Elles permettent à un attaquant de provoquer une exécution de code arbitraire
De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une élévation de privilège
De multiples vulnérabilités ont été découvertes dans Mozilla Thunderbird. Certaines d'entre elles permettent à un attaquant de provoquer une exécution
De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoquer un déni de service à distanc
De multiples vulnérabilités ont été découvertes dans Oracle Java SE. Elles permettent à un attaquant de provoquer un déni de service à distance, une a
De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni de service à distance, une att
De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un déni de service à distance, un
De multiples vulnérabilités ont été découvertes dans Oracle Systems. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité de
De multiples vulnérabilités ont été découvertes dans Oracle Virtualization. Elles permettent à un attaquant de provoquer une atteinte à la confidentia
De multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité d
Une vulnérabilité a été découverte dans Moodle. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-