← Retour

Veille tech — 2026-09-24

Veille Tech — jeudi 24 septembre 2026

> 85 articles · 8 sources · 24 dernières heures

Forge logicielle

What's Changed Component updates ⬆️ (cherry-pick) fix: avoid panic in user audit event resolver on nil event data (#23461) by @Aloui-Ikram in #23501 (

We’ve got an update for anyone who’s seen SonarQube flag a “new” issue on a line nobody touched: this is fixed, and it’s already live on SonarQube Clo

RFE: Add initial implementation of new dashboard list for experimental Dashboard UI. RFE: Show a 'Success' banner on Manage Jenkins page save. RFE: Ad

Intelligence Artificielle

Brace yourself: It turns out AI is being optimized for cheating. OpenAI’s agents hacked into Hugging Face to get the answers to a cybersecurity test.

The US has spent billions building a “virtual wall” of surveillance towers along its southern border over the past 25 years, promising they will help

It’s been a busy few months for AI hype. At the end of April, Anthropic claimed that its model Claude Mythos is better at finding software vulnerabili

Our 15-month investigation into death and surveillance along the US-Mexico border began with a simple question: Why did so many people die near govern

MIT Technology Review today published our investigation into how many people have died near the “virtual wall” of surveillance towers that the US gove

When José Morales Bernal crossed the border into the United States on April 8, 2024, the day before his 32nd birthday, it should have triggered a chai

She had only walked for a couple of hours, and already she was lost. It was early afternoon on Sept. 14, 2025, when 30-year-old Graciela Gómez Hernánd

Autres

S3, EBS, EFS. Three AWS storage services, similar-looking names, completely different jobs, and using the wrong one for a task is a classic beginner m

In Part 1 of this series, we laid out the anatomy of an agentic disaster and introduced our in-process tactical squad: The AG-Men. Before an autonomou

GPT-6 Astra shipped with the first Critical cybersecurity rating OpenAI has ever given a model, because it can autonomously find zero-days and build w

I thought my expensive Claude Code habit was long sessions. I was half right. When I finally broke down a month of usage, Claude Code subagents cost 4

There's a sentence in the README of a library I wrote that I've been thinking about lately: "To summarize, we believe that Padding-free Dynamic Batchi

Modern startups face a strucztural dilemma: infrastructure costs scale faster than revenue. Server provisioning, database maintenance, GPU clusters, a

Un agente LLM puede redactar un plan excelente y aun así ejecutar una acción equivocada. El riesgo aparece cuando una herramienta le permite enviar un

You Tab to a custom checkbox. The focus ring shows up. You press Space - nothing. Click with the mouse and it toggles. So is it accessible? WCAG 2.1.1

JavaScript has 8 main data types. They are divided into Primitive and Non-Primitive. Primitive Types : Primitive data types can store only a single va

A payment can carry a plausible town and country while nobody can explain where either value came from. The XML may validate. The address may look cle

There is a phase many backend engineers go through where making code shorter, smarter, and more abstract feels like progress. You discover a new patte

Creating Custom Agents in GitHub Copilot A good Copilot conversation can solve a one-off problem. A custom agent turns that conversation into a repeat

J’ai découvert le protocole Gemini, ça m’a rappelé Gopher, puis GopherVR. J’ai voulu recréer une expérience de navigation 3D similaire à GopherVR en f

Sécurité

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat ac

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in you

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a passwo

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the co

Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in im

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 sa

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-day

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and oth

The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging

De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un déni de service à distance et

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans les produits FoxIT. Certaines d'entre elles permettent à un attaquant de provoquer une exécution

De multiples vulnérabilités ont été découvertes dans SolarWinds Observability Self-Hosted. Elles permettent à un attaquant de provoquer une exécution

Une vulnérabilité a été découverte dans WordPress. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitrai

Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indi

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company sai

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme fold

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting dev

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every st

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arist

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machin

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remot

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scri

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic fo

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher P

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later ope

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to

De multiples vulnérabilités ont été découvertes dans Moodle. Elles permettent à un attaquant de provoquer une injection SQL (SQLi) et un contournement

Une vulnérabilité a été découverte dans SolarWinds Access Rights Manager. Elle permet à un attaquant de provoquer une exécution de code arbitraire à d

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries an

Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location dat

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things peop

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the informati

De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problème de sécurité non

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une élévation de privilèges et un pr

De multiples vulnérabilités ont été découvertes dans Synology DSM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de cod

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of seve


Sources consultées