← Retour

Veille tech — 2026-09-03

Veille Tech — jeudi 3 septembre 2026

> 76 articles · 14 sources · 4 derniers jours

> ⚠️ Flux indisponibles : Le Monde Informatique, Harbor Releases

Forge logicielle

Security: Important security fixes.

Hello, Atlassian is retiring the Connect app platform for Bitbucket Cloud, with full end of support on Dec 31st, 2026. This is Atlassian’s platform de

Intelligence Artificielle

As companies scale, the technology supporting operations can become a liability just as quickly as it becomes an asset. Disconnected systems, site-spe

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. By now you’v

Santé numérique

Après le succès de la première édition, l’ARS et le GRADeS Bourgogne-Franche-Comté organisent la 2ᵉ édition des Journées Régionales de la e-Santé, les

Une édition anniversaire tournée vers l’action : En 2025, vous étiez plusieurs centaines à participer à l’Université de la e-santé, confirmant son rôl

Co-organisé par l'Agence du Numérique en Santé (ANS) et l'institut national de recherche en sciences et technologies du numérique (INRIA), ce meet-up

Autres

What happens when a web server captures an attack in its access logs, but the underlying host system remains completely blind to the actual commands b

This post explains one of the technical and privacy questions behind the project rather than presenting an independent review. A share button seems li

A Cloudflare Worker can't run a multi-minute GPU job, and it can't open the gRPC connection Modal's Python SDK uses to spawn() one. Two hard "no"s — a

Linux: A Timeline of Freedom — IT History Journal Linux began as one student’s side project and grew into the foundation of the modern Internet. Follo

Disclosure: I am involved in the project discussed in this article. I am sharing the content-modeling lessons behind it rather than presenting this as

Teams rarely lose information because they lack documents. They lose it because decisions, rationale, owners, risks, and dates are buried across notes

Context Engineering: Why Your AI Agent Needs a Database, Not a Prompt Published: August 22, 2026 | Focus Keyword: context engineering for AI agents |

Originally published on indiecore.net. For about a year I got better at asking. Longer prompts, worked examples, careful phrasing, a private collectio

Capability discovery is one of those problems that quietly gets solved five different ways in the same company. For AI agents it matters even more: if

I'm an Engineering student from Pune, India. Over the last several months I built WATCHDOG — an AIOps platform that handles the full incident response

I've been building TattooGen.me, an AI-assisted workspace that helps people turn a story, photo, or sketch into a clearer tattoo concept. The most imp

I've been trying out a new Skill that turns Markdown content into narrated videos — and it's surprisingly practical. The workflow is simple. The bigge

Rudéfinitions : quatre cents termes de la tech et du devops, chacun accompagné d’une définition courte, jamais vérifiée et généralement de mauvaise fo

Sécurité

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set o

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while me

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have be

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a fr

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAG

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remot

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coord

De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Elles permettent à un attaquant de provoquer une exécution de code arbitr

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une élévatio

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécutio

De multiples vulnérabilités ont été découvertes dans Curl. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidenti

Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérab

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watc

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietn

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions,

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (A

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in

De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spéci

Une vulnérabilité a été découverte dans Mozilla Firefox pour iOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité

De multiples vulnérabilités ont été découvertes dans JFrog Artifactory. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité

Une vulnérabilité a été découverte dans Kaspersky Endpoint Security Windows. Elle permet à un attaquant de provoquer un contournement de la politique

De multiples vulnérabilités ont été découvertes dans SPIP. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collec

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running t

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant C

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR rout

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carr

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de c

De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une exécution de code arbitrai

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Te


Sources consultées

Erreurs de flux