← Retour

Veille tech — 2026-08-13

> ⚠️ Flux indisponibles : Le Monde Informatique, Harbor Releases

Veille Tech — jeudi 13 août 2026

> 79 articles · 14 sources · 24 dernières heures

Forge logicielle

Hello everyone, We’re excited to announce that opt-in strict enterprise governance and SSO enforcement controls are now available in SonarQube Cloud E

Major RFE: Standardise experimental Jenkins pages, make the side panel independently scrollable + make the build bar sticky RFE: Stop bundling the bou

Intelligence Artificielle

Business and technology leaders need no convincing that the time of agentic AI is here. Organizations are rapidly adopting agents, and few executives

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Last week, I

Every few decades, someone announces that science has reached its end. In 1903, the revered physicist Albert Michelson wrote that the “facts of physic

MIT Technology Review’s What’s Next series looks across industries, trends, and technologies to give you a first look at the future. You can read the

Autres

Of the 8,307 software and hardware versions in end-of-life.org, 73% are past their end-of-life date. Another 142 branches reach EOL within the next 90

Multi-page sites get a bad reputation for feeling clunky, and it's almost always for one specific reason: the white flash. You click a link, the whole

Part 2 of a series on building an AI-native platform. This one is about the thing that actually determines output quality — and a feature we shipped b

-- title: "Verify a PDF Tool's Privacy Claims With DevTools in 5 Minutes" description: "Stop trusting the marketing. Open the Network tab, run one mer

AI Agents Gone Rogue: How OpenAI, Anthropic & Meta Models Accidentally Hacked Real Companies in 2026 — and What Claude Code Auto Mode Does About It Ta

Built-in functions are usually snake_case. Modern framework code is usually camelCase. That is PHP: a language where naming conventions can feel oddly

5 MCP Pain Points Every Developer Hits (And How a 50KB CLI Fixes Them) I've been using MCP servers with Claude Code, Cursor, and Codex for months. Eve

BEAM - the Benchmark for Evaluating Agent Memory - is a good benchmark because it tests memory the way production agents actually use it: over very lo

Building a custom AI application has become remarkably straightforward. Engineering teams can connect a Large Language Model to internal company knowl

Your client sends a site and says "make ours like this." I gave five AI models that exact brief. - DEV Community Two different versions of the same pr

For a simple Node/Express backend flow, use managed SMS 2FA for login only when your app can poll delivery status, handle retries, and own fallback po

Print the SVG to PDF from a browser, or run it through a vector toolchain. Either way, the output can stay fully vector, because SVG and PDF are both

A surge of openness in AI has defined 2026. Amid calls for both caution and support, prevailing trends point to a future in which models are built and

Sécurité

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Micro

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoni

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs'

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successf

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIR

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys,

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code e

The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à d

De multiples vulnérabilités ont été découvertes dans Microsoft Office. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution d

De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de c

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une élévation de privilèges, une at

De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécut

De multiples vulnérabilités ont été découvertes dans les produits Intel. Certaines d'entre elles permettent à un attaquant de provoquer une élévation

De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Certaines d'entre elles permettent à un attaquant de provoquer une exécut

De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Certaines d'entre elles permettent à un attaquant de provoquer un déni de se

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans les produits Siemens. Elles permettent à un attaquant de provoquer une exécution de code arbitrai

Une vulnérabilité a été découverte dans les produits Cisco. Elle permet à un attaquant de provoquer un déni de service à distance. Cisco indique que l

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Wi

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant

Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the pre

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-st

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant p

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operatio

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testin

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle c

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. E

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that res

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data wi

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cel

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management system

De multiples vulnérabilités ont été découvertes dans Postfix. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à dist

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.

De multiples vulnérabilités ont été découvertes dans SPIP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitr

Une vulnérabilité a été découverte dans Docker. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données.

De multiples vulnérabilités ont été découvertes dans OpenSSH. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prior

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strai

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running a

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal ev

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code a

Une vulnérabilité a été découverte dans Synology Assistant. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données, une

De multiples vulnérabilités ont été découvertes dans HPE Aruba Networking Private 5G Core. Elles permettent à un attaquant de provoquer une élévation

Une vulnérabilité a été découverte dans SonicWall Global VPN Client. Elle permet à un attaquant de provoquer un déni de service.

De multiples vulnérabilités ont été découvertes dans VMware Tanzu Greenplum. Elles permettent à un attaquant de provoquer un problème de sécurité non

De multiples vulnérabilités ont été découvertes dans ClamAV. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confiden


Sources consultées

Erreurs de collecte