> ⚠️ Flux indisponibles : Harbor Releases
> 67 articles · 14 sources · 4 derniers jours
Security: Important security fixes.
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Humanoid rob
MIT Technology Review Explains: Let our writers untangle the complex, messy world of technology to help you understand what’s coming next. You can rea
Something I've noticed: Node.js articles tend to fall into two camps. Either they're uncritical hype pieces ("Node is fast! Netflix uses it!"), or the
On 6 October 2025, OpenAI unveiled Agent Builder at DevDay. A visual canvas where you drag boxes together and get an agent out the other end. Eight mo
In the overview article we explained why it makes sense to use the same UUID in search and in the primary database, when one already exists. Here we w
Everyone's building MCP servers. Most conversations focus on transports, authentication, OAuth, and exposing tools. Those topics are important, but wh
If you're investing time in SEO but struggling to earn quality backlinks, backlink gap analysis is one of the highest-impact strategies you can use. T
Update (2026): This article documents a legacy approach and is preserved for historical and educational purposes. AWS now recommends temporary credent
The EU AI Act's transparency obligations under Article 50 take full effect on 2 August 2026, creating concrete disclosure duties for providers and dep
I wanted a simple thing: paste a Twitter/X post link, get a clean PDF of it. Text, author, images, the whole card. No screenshots stitched together. I
Last night a wallet with no account anywhere earned $0.425 in USDC for answering a real customer support ticket, judged by a human, paid automatically
TL;DR Ask an LLM to analyze a spreadsheet in one shot and you get a single, opaque decision — no visible reasoning, no way to check its numbers. Agent
I wanted multithreaded ffmpeg running in a browser tab. What I got, several steps later, was a site with zero third-party scripts — no analytics vendo
What the research found Researchers at MIT's Media Lab ran a four-week study tracking 67 participants as they used AI assistants to help judge whether
Open Technology Research Symposium 2026 releases preliminary agenda. The event takes place on 26 and 27 October 2026 at the University of Barcelona du
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a c
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide ra
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source contro
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured di
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled d
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use t
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about t
An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber eval
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) ca
Cybersecurity researchers have disclosed what has been described as a "long-standing supply chain attack" on QuickFox, a virtual private network (VPN)
De multiples vulnérabilités ont été découvertes dans les produits Veeam. Certaines d'entre elles permettent à un attaquant de provoquer une exécution
De multiples vulnérabilités ont été découvertes dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. Elles permettent à un attaquant de provoque
De multiples vulnérabilités ont été découvertes dans Google Pixel. Elles permettent à un attaquant de provoquer une élévation de privilèges et un prob
Une vulnérabilité a été découverte dans Mozilla Firefox pour Android. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des do
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishi
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across mult
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom
The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break.
Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue coul
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary betwe
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' brow
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known
De multiples vulnérabilités ont été découvertes dans les produits Tenable. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio
De multiples vulnérabilités ont été découvertes dans Google Android. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié
De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurit
Une vulnérabilité a été découverte dans les produits Check Point. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance
De multiples vulnérabilités ont été découvertes dans LibreNMS. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distanc
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remot
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Ac
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already hel
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of t
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered befor
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed thro
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily e
De multiples vulnérabilités ont été découvertes dans Papercut. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des donn
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de c
Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
| Source | Erreur |
|---|---|
| Harbor Releases | HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0; |