Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 3 septembre 2026IT

Microsoft tightens Windows driver signing and prepares broader Memory Integrity rollout

Par : IT News
3 septembre 2026 à 16:46
Microsoft tightens Windows driver signing and prepares broader Memory Integrity rollout
Microsoft is turning its Driver Quality Initiative (DQI) into more visible enforcement, with stricter driver-signing checks, cloud-based rollback, and a pilot designed to deliver display drivers only to compatible systems. Windows 11 quality updates expected in October may also enable Memory Integrity on more eligible PCs, improving protection against malicious or untrusted kernel drivers but potentially reducing gaming performance on older hardware.

Source

Windows 11 driver signing will require SBOMs, VEX files and newer hardware

Par : IT News
3 septembre 2026 à 11:40
Windows 11 driver signing will require SBOMs, VEX files and newer hardware
Microsoft will significantly tighten Windows Hardware Compatibility Program (WHCP) driver signing from March 2027. Drivers targeting Windows 11 25H2 or later and Windows Server 2025 or later will need validated Software Bill of Materials (SBOM) and Vulnerability Exploitability Exchange (VEX) files, while submissions will also need to target relatively modern hardware.

Source

Linux Foundation takes over NVIDIA-founded Open Secure AI Alliance

Par : IT News
3 septembre 2026 à 11:40
Linux Foundation takes over NVIDIA-founded Open Secure AI Alliance
The Linux Foundation has formally taken over the Open Secure AI Alliance (OSAA) from NVIDIA, giving the month-old AI security consortium a vendor-neutral home. The move advances the alliance’s work on open tools and standards, including the SAFE framework for sharing AI incidents, while reducing concerns that a single company controls its direction.

Source

New identity governance and access features in Microsoft Entra

Par : IT Experts
2 septembre 2026 à 23:05
MCP firewall discovered tools rule (image Microsoft)
Microsoft released several generally available and preview updates for Microsoft Entra in September 2026. The changes focus on tenant governance, user-centric access reviews, lifecycle workflow management, passwordless Teams device identities, hybrid identity provisioning, and AI traffic controls. You should also plan for three upcoming changes that affect dynamic group rules, API permissions, and the Security Administrator role.

Source

OpenAI limits Astra’s opaque reasoning after AI safety alarm

Par : IT News
2 septembre 2026 à 23:02
OpenAI limits Astra’s opaque reasoning after AI safety alarm
OpenAI is limiting the use of recurrent depth in its Astra model after concerns that the technique could hide more of the model’s reasoning from safety systems. The looped approach processes information repeatedly inside the model instead of producing a clearly sequential chain of thought, but OpenAI says Astra will retain readable reasoning and receive additional monitoring.

Source

Google has launched Gemini 3.8 Flash and Gemini 3.8 Flash Cyber

Par : IT News
2 septembre 2026 à 21:12
Google has launched Gemini 3.8 Flash and Gemini 3.8 Flash Cyber
Google has launched Gemini 3.8 Flash and the security-focused Gemini 3.8 Flash Cyber, extending the rapid rollout that began with Gemini 3.7 Flash. The Cyber edition targets trusted defenders with autonomous vulnerability discovery and patching, while retaining the Flash family’s speed and introductory pricing.

Source

GitSpawn lets poisoned repositories run code through AI coding agents

Par : IT News
2 septembre 2026 à 18:07
GitSpawn lets poisoned repositories run code through AI coding agents
A repository’s own `.git/config` can still trigger attacker-controlled code through Claude Code, Codex, Cursor, goose, and other AI coding agents before trust prompts, authentication, model calls, or tool approvals occur. Manifold Security’s GitSpawn research found eight flaws across seven agents; fixes are available for several tools, but Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained vulnerable during September testing.

Source

Microsoft Purview DSPM adds bulk fixes for Copilot data risks

Par : IT News
2 septembre 2026 à 18:07
Microsoft Purview DSPM adds bulk fixes for Copilot data risks
Microsoft is expanding Purview Data Security Posture Management (DSPM) from a data-risk dashboard into a broader remediation workflow for AI deployments. The updated experience can identify overshared or unlabeled content across Microsoft 365 and Fabric, incorporate signals from external platforms, and help administrators fix exposure before Copilot or other AI agents can surface it.

Source

Firefox 155 and Thunderbird 155 start Mozilla’s fortnightly release race

Par : IT News
2 septembre 2026 à 18:07
Firefox 155 and Thunderbird 155 start Mozilla’s fortnightly release race
Firefox 155 and Thunderbird 155 are the first products to arrive under Mozilla’s new two-week release cadence, landing only days after the previous builds. The change follows Thunderbird’s move to fortnightly releases after version 153 became the ESR baseline, giving administrators a choice between rapid features and slower, security-focused maintenance.

Source

Hier — 2 septembre 2026IT

OpenAI’s Astra reaches “critical” cyber capability threshold

Par : IT News
2 septembre 2026 à 15:26
OpenAI’s Astra reaches “critical” cyber capability threshold
OpenAI says its unreleased Astra model is the first of its systems to reach the “Critical” cybersecurity level, meaning it can autonomously discover unknown vulnerabilities and chain them into attacks against hardened environments. The designation has already changed Astra’s rollout: parts of training were paused, safeguards were strengthened, and advanced cyber capabilities will initially be restricted to selected testers and the Daybreak Blue defensive program. Astra is expected soon, but no public release date has been confirmed.

Source

Microsoft offers workshop for incident response plans

Par : IT News
2 septembre 2026 à 15:07
Microsoft offers workshop for incident response plans
Microsoft is offering organizations a two- or three-day Cybersecurity Incident Response Workshop to test whether their incident response plans work under pressure—not just on paper. Led by Microsoft’s Detection and Response Team (DART), the exercise uses simulated attacks, threat hunting, and guided decisions to expose gaps in roles, tools, telemetry, and coordination before a real breach does.

Source

Anthropic opens Claude watermark detection API to approved organizations

Par : IT News
2 septembre 2026 à 15:07
Anthropic opens Claude watermark detection API to approved organizations
Anthropic has launched a private-preview API that lets approved organizations verify Claude’s invisible watermark, following its rollout of watermarks across Claude outputs. Regulators, media outlets, fact-checkers, researchers, educational organizations, and compliance-focused enterprises can apply for access.

Source

Sift scans Microsoft 365, Slack, and Jira for forgotten secrets

Par : IT News
2 septembre 2026 à 15:07
Sift scans Microsoft 365, Slack, and Jira for forgotten secrets
Sift, a free open-source command-line tool from Stratus Security, searches for passwords, API keys, and other secrets across local storage, Windows file shares, Active Directory, Microsoft 365, Slack, Jira, and Confluence. Its broad coverage addresses a common blind spot: finding credentials in collaboration and ticketing systems that conventional file-share scans never reach.

Source

SharePoint’s hero link brings safer defaults to OneDrive sharing

Par : IT News
2 septembre 2026 à 15:07
SharePoint’s hero link brings safer defaults to OneDrive sharing
Microsoft is expanding the SharePoint Online and OneDrive sharing upgrade built around a reusable “hero link,” with broader tenant rollout scheduled from mid-September through late October 2026. New links default to “Only people added to the file,” so possessing a URL alone does not grant access, while existing links and permissions continue working unchanged.

Source

Microsoft Defender mistakenly blocks legitimate Google search links

Par : IT News
2 septembre 2026 à 15:07
Microsoft Defender mistakenly blocks legitimate Google search links
Microsoft Defender for Office 365 is incorrectly classifying legitimate Google search URLs as malicious, blocking users with “Opening this website might not be safe” warnings. Microsoft is investigating the Safe Links incident, tracked as MO1465962, while administrators may also see related detections in the Defender portal and Microsoft Sentinel.

Source

AI agents ran malware from llms.txt files in Fortune 500 supply-chain test

Par : IT News
2 septembre 2026 à 15:07
AI agents ran malware from llms.txt files in Fortune 500 supply-chain test
Researchers triggered arbitrary code execution in AI agents by planting malicious package references in llms.txt files, exposing a new supply-chain risk for systems that treat machine-readable documentation as trusted instructions. In a test of 8,565 files, 237 contained references to missing, abandoned, mistyped, or otherwise questionable packages—and some frontier AI models followed the resulting installation guidance more than 90 percent of the time.

Source

Anthropic’s Fable 5.1 arrives as a slightly better benchmark hack with yet another price hike

2 septembre 2026 à 11:12
Anthropic’s Fable 5.1 delivers marginal gains at massive cost
Anthropic’s new Fable 5.1 and Mythos 5.1 models promise stronger performance and major savings for repeated agent workloads, but independent testing cited by Matthew Berman suggests Fable 5.1 still costs more per completed task. The release also introduces so-called customer-controlled data storage—little more than window dressing—along with new anti-distillation safeguards and model watermarking.

Source

Deploy the Microsoft Edge 151 security baseline

Par : IT Experts
1 septembre 2026 à 23:16
Microsoft Edge policies in Group Policy (image Microsoft)
Microsoft released a security baseline for Microsoft Edge version 151 on August 25, 2026. The package adds six enforced isolation and data-protection policies plus one optional HTTPS setting for evaluation. For a summary of what each control does and why Microsoft recommends it, see Microsoft Edge 151 baseline adds six security controls. This article focuses on how to deploy and verify those settings in Active Directory and Intune.

Source

CrowdStrike’s SafeMind aims to drive breakout time to zero

Par : IT News
1 septembre 2026 à 22:19
CrowdStrike’s SafeMind aims to drive breakout time to zero
CrowdStrike says its new SafeMind system can reduce attacker breakout time to zero by having two AI models continuously attack and repair a simulated copy of an organization’s environment. The announcement follows the company’s move to put more than 50 Falcon IQ agents to work on security analysis, but SafeMind takes the concept further with an autonomous red-team/blue-team loop.

Source

❌
❌