← Retour

Veille tech — 2026-08-10

Veille Tech — lundi 10 août 2026

> ⚠️ Flux indisponibles : Agence du Numérique en Santé, Harbor Releases

> 69 articles · 14 sources · 4 derniers jours

Autres

This is a submission for DEV's Summer Bug Smash: Clear the Lineup. The bug npmx.dev is a fast browser for the npm registry — you can look up any packa

# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fre

GPU capacity is the tightest it has been in a while. Amazon just crossed three trillion dollars largely on cloud AI demand and the reporting says even

The headline going around this week is that frontier models from a couple of the big labs slipped their containment during live security tests and sta

Have you ever opened Task Manager and noticed that your Windows disk usage is stuck at 100% even though you aren't doing anything? The computer may fe

This article was originally published on BuildZn. Everyone talks about 'AI agents' for market research, but nobody details the real fight: bypassing a

Rate limiting is a defensive mechanism used in software development to control the rate of incoming traffic to a network or application. It sets a str

I've been quietly building Antigravity Tools — a collection of 59 free, browser-based developer utilities — and today I'm sharing everything I built a

If you've built more than one FastAPI service, you know the drill: define a model, define a schema, then write the same five endpoints — list, retriev

Let's look at this C++ program: #include <iostream> int main() { int x; if (x == 0) { std::cout << "Zero"; } else { std::cout << "Not zero"; } } When

For Street-Smart Coding Manifesto, the prequel of my coding trilogy, I wrote what being a street-smart coder is: a coder with a "very particular set o

Claude Code now has dozens of skills and plugins available, both official and community-built. Installing them indiscriminately backfires: when severa

Erreur 403 | #88 - 88 M$ dérobés grâce à une faille des portefeuilles Coldcard Faille des portefeuilles Coldcard (88,6 M$ volés), ver npm ChainDr

Sécurité

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Out

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploit

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security fl

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Ap

A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group k

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content manag

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once

A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a cont

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) t

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desync

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows He

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own cod

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the grou

De multiples vulnérabilités ont été découvertes dans Progress Telerik. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans WordPress. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privil

Une vulnérabilité a été découverte dans Apple macOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilège

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privi

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exé

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer un contournement de la polit

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une éléva

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isola

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehe

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel usin

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilitie

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the Jav

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address. Introduced

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It ab

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploita

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. Accordin

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ranso

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspi

Une vulnérabilité a été découverte dans Sonicwall SonicOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

De multiples vulnérabilités ont été découvertes dans les produits Nextcloud. Elles permettent à un attaquant de provoquer une atteinte à la confidenti

De multiples vulnérabilités ont été découvertes dans les produits Wallix. Elles permettent à un attaquant de provoquer une élévation de privilèges et

De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution

De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilè

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a c

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide ra


Sources consultées

Erreurs de collecte

| Source | Erreur |

|---|---|

| Agence du Numérique en Santé | HTTP 500 with UA=python:MonVeilleurRSS:1.0 (by |

| Harbor Releases | HTTP 403 with UA=Mozilla/5.0 (Windows NT 10.0; |