Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 15 août 20264sysops

Microsoft makes threat modeling central to post-quantum migration

Par : IT News
15 août 2026 à 11:10
Microsoft makes threat modeling central to post-quantum migration
Microsoft is warning that post-quantum cryptography cannot be deployed safely by simply swapping encryption algorithms. Threat modeling must first uncover hidden cryptographic dependencies, ownership gaps, and architecture limits that automated scanners may miss. Scanners cannot see the whole cryptographic picture

Source

Claude’s invisible text watermark is global

Par : IT News
15 août 2026 à 11:10
Claude’s invisible text watermark is global
Anthropic is applying Claude’s invisible text watermark globally, not only in the European Union, while withholding a public detector for now. The system subtly steers Claude toward statistically favored “inconsequential” words, creating a signal that can identify likely AI involvement across sufficiently long passages without visibly changing the text. Word choices carry the signal

Source

Windows 11 may reboot three times during Secure Boot updates

Par : IT News
15 août 2026 à 11:10
Windows 11 may reboot three times during Secure Boot updates
Microsoft has clarified why Windows 11 and Windows 10 PCs can reboot repeatedly during the ongoing Secure Boot certificate rollout: the process may stage changes, write them into UEFI firmware, and then boot with a newly signed bootloader. The behavior expands on multiple reboots during large Windows 11 updates and can be followed by additional restarts for pending firmware or driver updates. Secure Boot changes require several boot phases

Source

Microsoft retires standalone MDTI, integrates threat intelligence into Defender XDR and Sentinel

Par : IT Experts
14 août 2026 à 22:59
MDTI capabilities across Defender and Sentinel (image Microsoft)
Microsoft retired the standalone Microsoft Defender Threat Intelligence (MDTI) experience on August 1, 2026. Its threat intelligence capabilities now appear in the Microsoft Defender portal for Microsoft Defender XDR and Microsoft Sentinel. For administrators, this is mainly a portal and licensing change, but verify where your security team accesses intelligence before removing an existing MDTI subscription.

Source

Active attacks exploit macOS Screen Sharing flaw CVE-2026-65400 to gain root access

Par : IT News
14 août 2026 à 22:17
Active attacks exploit macOS Screen Sharing flaw CVE-2026-65400 to gain root access
Attackers are exploiting CVE-2026-65400 in macOS Screen Sharing to obtain root access and install Monero cryptocurrency miners on exposed Macs. A working exploit was reportedly developed from Apple’s patch in about four hours, increasing the risk that more attackers will target systems with TCP port 5900 reachable from the internet. Internet-exposed Macs are at greatest risk

Source

Microsoft delays Exchange Server SE CU1 again, with no release date in sight

Par : IT News
14 août 2026 à 20:11
Microsoft delays Exchange Server SE CU1 again, with no release date in sight
Microsoft has delayed Exchange Server Subscription Edition CU1 beyond its original first-half 2026 target and now says it still cannot provide a firm release date. The team is continuing to fold monthly security fixes into its internal CU1 build and plans to release it when the update reaches a stable point without an immediate security release looming. Security work is taking priority

Source

Windows 11 KB5121003 fixes an exploited zero-day—install it quickly

Par : IT News
14 août 2026 à 19:48
Windows 11 KB5121003 fixes an exploited zero-day—install it quickly
Microsoft has released Windows 11 August 2026 update KB5121003, including a fix for the actively exploited CVE-2026-68820 zero-day. The cumulative update also delivers features from the planned August update, such as TPM-secured KMS activation and expanded controls for local AI components.

Source

ChatGPT Computer History stores Mac activity in unencrypted memory files

Par : IT News
14 août 2026 à 19:48
ChatGPT Computer History stores Mac activity in unencrypted memory files
OpenAI’s Computer History feature can leave users’ recorded Mac activity in unencrypted Markdown files, even though its temporary event data is deleted after 48 hours. The opt-in feature tracks Mac work without screenshots, turning clicks, keystrokes, app switches, and other accessibility events into memories that ChatGPT and Codex can reuse.

Source

GLM-5.3 promises a 50% coding leap, claims to be the best open weights model

Par : IT News
14 août 2026 à 17:35
GLM-5.3 promises a 50% coding leap, claims to be the best open weights model
Zhipu AI says GLM-5.3 delivers a 50% coding improvement through post-training alone, while its cybersecurity skills have advanced enough to uncover thousands of vulnerabilities. Z.ai now claims GLM-5.3 has taken the open-weight coding crown from Alibaba’s competing Qwen 3.8 model.

Source

À partir d’avant-hier4sysops

ChatGPT Computer History tracks Mac work without screenshots

Par : IT News
14 août 2026 à 12:03
ChatGPT Computer History tracks Mac work without screenshots
OpenAI’s new Computer History feature gives ChatGPT a searchable timeline of activity across Mac apps and websites, letting users recover context from earlier work without taking continuous screenshots. It is opt-in and available to Pro, Business, and Enterprise subscribers, but its ability to summarize workplace activity creates an important privacy consideration for organizations.

Source

Akira ransomware’s Safe Mode attack disabled defenses

Par : IT News
14 août 2026 à 11:33
Akira ransomware’s Safe Mode attack disabled defenses
An Akira ransomware affiliate rebooted a victim into Safe Mode to disable Huntress and Microsoft Defender, but the restricted environment also caused Akira’s encryptor to fail. The attackers still stole credentials and data after entering through an MFA-less SonicWall VPN; earlier coverage examined how DeadLock suppresses Windows defenses and complicates recovery in a related ransomware campaign.

Source

Spectre attacks hit commercial RISC-V chips and leak Linux kernel memory

Par : IT News
14 août 2026 à 11:33
Spectre attacks hit commercial RISC-V chips and leak Linux kernel memory
A recent TONTOU attack showed that Spectre v2 defenses on AMD and Intel CPUs could still be bypassed; now researchers have demonstrated major Spectre vulnerabilities on commercial RISC-V processors. The attacks can extract arbitrary Linux kernel memory from a T-Head Xuantie C910 at about 338 bytes per second, overturning the assumption that RISC-V is largely immune.

Source

Cisco says Anthropic’s Mythos is triggering an urgent replacement wave

Par : IT News
14 août 2026 à 11:33
Cisco says Anthropic’s Mythos is triggering an urgent replacement wave
Cisco says Anthropic’s Mythos bug-finding model is triggering an urgent wave of replacements for networking equipment past its last day of support. The company calls this the “Mythos Effect,” as customers move security and networking budgets to replace legacy routers, switches, and other devices before automated vulnerability discovery exposes them.

Source

Microsoft 365 backup gap leaves customers responsible after ransomware

Par : IT News
14 août 2026 à 11:33
Microsoft 365 backup gap leaves customers responsible after ransomware
Microsoft keeps Microsoft 365, Entra ID, and Azure services available, but does not promise to restore a customer’s data to a specific known-good point after an attack. That makes independent, immutable backup increasingly important as stolen identities let attackers reach mailboxes, files, cloud resources, and recovery controls.

Source

Microsoft is urging administrators to prioritise Entra ID over Active Directory

Par : IT News
14 août 2026 à 11:33
Microsoft is urging administrators to prioritise Entra ID over Active Directory
Microsoft is urging IT administrators to make Microsoft Entra ID the strategic identity platform for modern workloads instead of relying exclusively on on-premises Active Directory. The recommended path is incremental: move authentication, access decisions, and governance to the cloud while retaining AD only where legacy applications and devices still require it.

Source

Microsoft Purview DLP reaches Google Workspace, Box and other non-Microsoft platforms

Par : IT News
14 août 2026 à 11:33
Microsoft Purview DLP reaches Google Workspace, Box and other non-Microsoft platforms
Microsoft Purview is the Microsoft 365 tool for finding sensitive information in work emails and files, and then warning or blocking you if you try to share it outside the company or with someone who should not receive it. Data Loss Prevention (DLP) is a feature inside Microsoft Purview that checks work emails, files, chats, and some AI prompts for sensitive information and can stop it from being shared improperly. Microsoft Purview is preparing to apply DLP and auto-labeling to Google Workspace, Box, Dropbox, Salesforce, and other non-Microsoft platforms, but the rollout requires connectors, enterprise licensing, and additional storage charges. Earlier Purview coverage focused on restricting external sharing in Microsoft 365.

Source

Azure IoT gets TLS 1.3, passwordless provisioning, and secure updates

Par : IT News
13 août 2026 à 20:39
Azure IoT gets TLS 1.3, passwordless provisioning, and secure updates
Microsoft is rolling out three Azure IoT security changes with different readiness levels: TLS 1.3 for IoT Hub and managed-identity authentication between Device Provisioning Service and IoT Hub are in public preview, while HTTPS downloads for Device Update are generally available. The earlier Microsoft security overhaul focused on Cloud Solution Providers; this previous coverage addresses a separate Azure IoT security update.

Source

❌
❌