← Retour

Veille tech — 2026-08-03

Veille Tech — lundi 3 août 2026

> 68 articles · 6 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Harbor Releases

> - Harbor Releases : `HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0;`

> ⚠️ Le flux RSS de l'ANS (esante.gouv.fr) contient un lien `<link>` mal formé (une balise `<a href="...">` encodée en URL au lieu d'une URL brute). Les liens ci-dessous ont été reconstruits manuellement à partir du `href` interne — à surveiller si le flux source n'est pas corrigé.


Intelligence Artificielle

It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue

Santé numérique

Le feu vert a été donné pour le déploiement de la nouvelle version de FINESS, le répertoire national des établissements sanitaires, sociaux et médico-

Les États membres de l'Union européenne ont adopté deux actes d'exécution majeurs pour le déploiement de MyHealth@EU, l'infrastructure européenne qui

L'Agence du Numérique en Santé (ANS), en lien avec la Délégation au numérique en santé (DNS), a retenu 21 lauréats dans le cadre de la phase explorato

Autres

The Model Context Protocol's 2026-07-28 revision went final on July 28. It's a meaningful one: the lifecycle moves to stateless requests. If you maint

What I Built I built Warm Table, a fictional Taiwanese comfort-soup house inspired by the idea that a warm bowl of soup can make a difficult day feel

git log is one of the most powerful and yet most underused inspection tools in Git. While many developers use it only to view basic commit history, it

Crafting clean code alone won't save you or make you stand out. That's not the real edge. Why this book? When I started, I thought my only job was wri

Hazard pointers are proposed as an alternative to RCU for object reclamation, a race-free O_CREAT|O_DIRECTORY interface is under discussion, and the g

The setup I have a tool site with 6 languages. Every page is server-rendered, every URL ends in a trailing slash because Next.js generates it that way

The All-or-Nothing Bottleneck of SSR For years, Server-Side Rendering (SSR) was the gold standard for React application performance and SEO. In the Ne

The Microservice Domino Effect Modern enterprise applications rarely operate in isolation. Your Laravel backend is likely communicating with a myriad

Every setup I found for letting an AI agent work on a server asked for one of two things. Either I paste a private key somewhere the agent can read it

This article was originally published on Jo4 Blog. I woke up to 47 Slack notifications. All from the same bot. All saying the same thing: "Duplicate o

AI agents get talked about a lot, but most explanations stay abstract. Here's a short, practical breakdown of what actually makes an agent work — plus

The European Union's AI Act will make a new set of transparency obligations enforceable from 2 August 2026. Article 50 requires clear disclosures in s

Il peut être utile de monter rapidement un cluster Kubernetes de laboratoire pour explorer une solution ou faire un POC. Chez OPS, nous avons répondu

Sécurité

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mappe

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation

A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central A

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tr

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the com

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, co

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to a

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autono

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5,

De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indi

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une injection SQL (SQLi), un

Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une éléva

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exé

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une attein

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write ac

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished f

Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intru

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers u

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targe

Erreur 403 | #87 - Deux millions de véhicules exposés par une alarme antivol et campagne russe active contre Zimbra Deux millions de véhicules expo

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerabi

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The mov

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Ma

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à dista

De multiples vulnérabilités ont été découvertes dans Node.js. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à dist

Une vulnérabilité a été découverte dans Ruby on Rails activestorage. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distan

De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaquant de provoquer une exécution

Une vulnérabilité a été découverte dans Cisco Firewall Management Center. Elle permet à un attaquant de provoquer une atteinte à la confidentialité de


Sources consultées