← Retour

Veille tech — 2026-09-28

Veille Tech — lundi 28 septembre 2026

> 58 articles · 14 sources · 24 dernières heures

Forge logicielle

What's Changed Component updates ⬆️ (cherry-pick) fix: avoid panic in user audit event resolver on nil event data (#23461) by @Aloui-Ikram in #23501 (

Intelligence Artificielle

The US government wants to spend $30.3 million over the next five years on an improved form of lie detector, according to a Department of Defense budg

Santé numérique

Le feu vert a été donné pour le déploiement de la nouvelle version de FINESS, le répertoire national des établissements sanitaires, sociaux et médico-

Le SAMU 84 d'Avignon devient le 22e SAMU à rejoindre le programme SI-SAMU, à l'occasion d'une double transformation de ses outils de régulation médica

Autres

AI coding agents can already write functions, modify repositories, run tests, and open pull requests. The harder problem is getting an agent to follow

Spring Data JPA makes persistence remarkably easy to start with. Create an entity. Extend JpaRepository. Start writing business logic. public interfac

Drafted with AI help, human-reviewed by The Agent Loop. Short version: My own analytics dashboard said 52 views this morning while every per-post row

It is a simple and humble Global state management. I know, Now you are thinking "Why not React context or any others?". The answer is simple. People c

How to Set Up an AWS NAT Gateway|Give EC2 Instances in a Private Subnet Internet Access An EC2 instance in a private subnet may need to download OS up

TL;DR — On Linux and macOS, python3 -m venv .venv does not create a copy of Python. The python inside your venv is a symlink that points back to the s

When I started learning CSS, creating responsive layouts took a lot of time. Then I discovered Bootstrap—a CSS framework that helps build modern websi

Most developers know about OpenAI, Anthropic, Groq, and Cerebras. What many developers don't realize is that Cloudflare Workers AI provides access to

This post is part of my notes from Formação AWS, a course by Henrylle Maia. It covers a class from Desafio Labs, one of the course's sections, that fo

Product analytics for people who would rather ship than configure dashboards. Analytics got weird. You wanted “where did they come from, what did they

This post is part of my notes from Formação AWS, a course by Henrylle Maia. It covers a class from Desafio Labs (one of the course's sections) that fo

Markdown Kitchen Sink Heading 1 This is a paragraph of text. You can use bold, italic, or a combination of both. You can also use inline code. Heading

Sécurité

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix co

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticat

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik Router

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it rece

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compro

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryp

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on Se

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vuln

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and th

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une élévatio

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une éléva

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exé

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécut

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher,

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have cli

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while disp

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and tr

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to G

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. O

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Ministe

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 acco

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is

De multiples vulnérabilités ont été découvertes dans Wireshark. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distan

De multiples vulnérabilités ont été découvertes dans LibreNMS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilè

De multiples vulnérabilités ont été découvertes dans Papercut. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code ar

Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbi

De multiples vulnérabilités ont été découvertes dans Zabbix Agent. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié p

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance


Sources consultées