← Retour

Veille tech — 2026-10-01

Veille Tech — jeudi 1er octobre 2026

> 70 articles · 14 sources · 4 derniers jours

Forge logicielle

We’ve got some exciting news for teams bringing new projects into SonarQube Cloud: starting today, we’re rolling out Scanner CLI automatic configurati

RFE: Honor entry equality and hashcode contracts in PackedMap. RFE: Drop support for Remoting (agent.jar) releases prior to August 2024. Bug: workspac

Intelligence Artificielle

Two months after the bombshell news that a swarm of its agents had broken their containment and hacked into the computers of the AI company Hugging Fa

When customers talk about AI costs, the conversation usually starts with token prices and ends with access to the latest, most capable model in the cl

Listen to the session or watch below The US has spent billions building a “virtual wall” of surveillance towers along its southern border over the pas

This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. Last Wednesd

MIT Technology Review Explains: Let our writers untangle the complex, messy world of technology to help you understand what’s coming next. You can rea

Santé numérique

Garantir la confiance dans le numérique en santé suppose des règles communes, mais aussi de veiller à leur bonne application. Avec le nouveau disposit

L’Association Française des Assistants de Régulation Médicale vous donne rendez-vous les 8 & 9 mars 2027 à Rennes.Le rendez-vous clé de la Régulation

Du 8 au 11 octobre 2026, au Palais des Congrès de Paris, les 74es Journées Francophones de Radiologie réuniront les professionnels de l’imagerie autou

Autres

To save a Fabric.js canvas to a database, send its editable JSON through an API and retrieve that JSON when the user opens the document. With fabricjs

OpenAI DevDay 2026 had one headline: Dots, always-on agents powered by GPT-6 Astra, each running on its own cloud computer with persistent memory and

Introduction & Industry Context For over a decade, continuous integration and continuous deployment (CI/CD) pipelines have operated under a binary exe

Un agente LLM puede parecer muy capaz durante una demostración y volverse dificil de operar cuando empieza a llamar APIs, crear tickets o consultar da

Most "free online tools" work like this: you upload your file to a server, it does the work, you download the result. For many tasks, that round trip

Data without structure is just noise. In this project, I am building a complete, end-to-end Business Intelligence solution for JCars Logistics, a comp

I’ve spent the last few months building projects instead of just following tutorials. And honestly, I’ve learned something important: Building a real

Concourse: 3,767 title matches on the pipeline system that executes your build code A continuous integration system runs code that the organisation wr

Open WebUI is a universal chat interface with connectivity to local or remote LLM providers, custom files, documents, and a knowledge base, with full

Once a coding agent can change the architecture, changing the rules that protect it becomes a different kind of operation. One of the less obvious pro

The strongest argument for humanoid robots has nothing to do with walking, grasping, or looking cool in a demo reel. It is a software engineering conc

Yes, in most cases a UAE company can process customer data in ChatGPT, but compliance depends strictly on three levers you control: your plan tier, ph

Sécurité

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gatewa

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security compan

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. T

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target o

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it rele

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has c

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié

De multiples vulnérabilités ont été découvertes dans HPE Aruba Networking Instant On. Certaines d'entre elles permettent à un attaquant de provoquer u

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer une atteinte à l'intégrité des données.

De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une élévatio

De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à dist

De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des donnée

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in Jun

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows comput

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerabi

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dub

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch,

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training

Une vulnérabilité a été découverte dans les produits Apple. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Apple

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in tar

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technica

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security prod

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy.

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. T

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-so

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised servic

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Expl

[Mise à jour du 30 septembre 2026] Dans un billet de blogue du 29 septembre 2026 (cf. section Documentation), Mandiant et Google Threat Intelligence G

De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un

De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer u

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix co


Sources consultées