← Retour

Veille tech — 2026-07-30

Veille Tech — jeudi 30 juillet 2026

> 74 articles · 7 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;`

> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient un lien `<link>` mal formé (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Le lien ci-dessous a été reconstruit manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.


Forge logicielle

Intelligence Artificielle

It feels bad enough when an open letter signed by leading economists warns that AI might steal your job. The fact it may soon be better than you at ma

Lee, an engineer at Samsung’s semiconductor division, clocks out when his shift ends. He used to work longer hours, going the extra mile to excel at h

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Reading Open

Imagine a healthcare system made up of multiple AI agents: one that manages symptom assessment, another scheduling, a third insurance, and a fourth ph

Drug discovery is a high-cost, high-risk endeavor that is under growing pressure from a market increasingly defined by first-mover advantage. Since th

For the enterprise, the promise of agentic AI is much more than just a better chatbot. It is software agents that execute business tasks end-to-end ac

Santé numérique

Le 14e Comité des entreprises du numérique en santé (ENS) s'est tenu le 9 juillet 2026, réunissant les représentants de la Délégation au numérique en

Autres

The Collapse of React Context State management is the most heavily debated topic in the React ecosystem. For years, Redux was the undisputed king, but

“Anonymous” is often implemented as a missing name field. That is a start, but it is not a design method. A survey can omit a name and still connect a

Most CI pipelines assume a function called with the same input twice returns the same output. That assumption breaks the moment an LLM call enters you

🌱 MyZubster: The Decentralized Ecosystem to Map the World with Monero and AI A skill marketplace, a global map of plants and animals, private payments

Building Multi-Model AI Applications: Why One Model Won't Be Enough If you ask most developers what model powers their AI application, you'll usually

Bare metal servers remain the critical foundation for workloads that demand predictable performance, strict hardware isolation, and zero-overhead comp

แชร์ Localhost สู่โลกภายนอกใน 1 นาที — ด้วย Dev Tunnels (ไม่ต้องใช้ ngrok) โดย Nokka (นก-กา) | 30 กรกฎาคม 2026 บทความนี้เขียนโดย AI (DeepSeek V4 Pro)

SEO Tools in Claude Code: Hosted vs Local MCP — Agent Lab Journal Agent Lab Journal Guides Glossary Practical guide · Intermediate SEO Tools in Claude

Solon takes a different approach. The entire i18n module is built around three resolvers, one annotation, and a utility class — no XML, no interceptor

You've got 127 trial signups last month. Three converted. You're sitting there wondering if your product is broken, your pricing is wrong, or your mar

Facets in an online store seem simple until the first filter is selected. In a catalog, they are part of the navigation. A selected color should not d

Safety-critical Linux means running Linux where a failure can injure someone: in cars, industrial robots, and medical devices. You cannot certify the

Sécurité

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from applic

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and Open

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coor

The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terr

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Mana

OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's p

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independe

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the

Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges,

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des donné

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main proces

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing In

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluatio

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enable

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has bee

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution

De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distan

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing s

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays a

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the ser

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote mo

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate fin

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Mi

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening

De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécut

De multiples vulnérabilités ont été découvertes dans GLPI. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges,

Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité de

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as


Sources consultées