Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 24 août 20264sysops

Windows 11 brings back File Explorer previews with a safer “Preview anyway” button

Par : IT News
24 août 2026 à 12:31
Windows 11 brings back File Explorer previews with a safer “Preview anyway” button
Windows 11 is restoring File Explorer previews for internet-downloaded files, but with a new “Preview anyway” override instead of removing the security block. The change builds on recently restored previews for downloaded PDFs and other non-HTML files and should let users view trusted files without first opening Properties or running PowerShell.

Source

Windows 11 Smart App Control drops its clean-install barrier

Par : IT News
24 août 2026 à 12:31
Windows 11 Smart App Control drops its clean-install barrier
Microsoft has removed the clean-install prerequisite for Smart App Control, allowing supported Windows 11 users to try the security feature on existing installations. The Windows 11-exclusive protection can block unsigned or untrusted applications before they run, while potentially using fewer resources than traditional always-on scanning.

Source

Microsoft sets September 2026 deadline to replace Edge MDAG and WIP

Par : IT News
24 août 2026 à 12:31
Microsoft sets September 2026 deadline to replace Edge MDAG and WIP
Microsoft will complete the retirement of Microsoft Defender Application Guard (MDAG) and Windows Information Protection (WIP) support in Microsoft Edge by the end of September 2026. The deadline primarily affects organizations that still depend on these protections in Edge on Windows 10, giving administrators time to find supported replacements.

Source

Microsoft sets 2027 deadline for post-quantum Windows code signing

Par : IT News
24 août 2026 à 12:31
Microsoft sets 2027 deadline for post-quantum Windows code signing
Microsoft will replace the Windows Production PCA 2011 code-signing certificate before it expires on October 19, 2026, then move Windows production signing toward post-quantum cryptography in 2027. The transition described in KB5125813 could break software and deployment processes that hardcode certificate identities, algorithm names, or signature parameters.

Source

Teams rolls out bot controls for meeting recording and AI notetaking

Par : IT News
24 août 2026 à 12:31
Teams rolls out bot controls for meeting recording and AI notetaking
Microsoft is rolling out a Teams meeting-policy control that detects external recording and AI notetaking bots and places them in the lobby for approval. Targeted-release tenants are receiving the feature now, with worldwide availability expected by the end of September 2026, giving administrators a way to prevent unapproved applications from entering confidential meetings.

Source

À partir d’avant-hier4sysops

MCP roadmap targets agent identity, event-driven agents, and smarter tool discovery

Par : IT News
22 août 2026 à 15:40
MCP roadmap targets agent identity, event-driven agents, and smarter tool discovery
The new Model Context Protocol (MCP) roadmap shifts attention from the recently released stateless architecture to the next problems of running AI agents at scale: server-initiated events, agent identity, progressive tool discovery, and clearer tool results. It builds on MCP’s stateless 2026-07-28 release, which removed protocol-level sessions and made remote MCP servers easier to operate behind standard HTTP infrastructure.

Source

Nvidia’s AVO proves that the harness matters more than raw intelligence

Par : IT News
21 août 2026 à 22:06
Nvidia’s AVO harness proves that the harness matters more than raw intelligence
Nvidia’s Agentic Variation Operators (AVO) is a research harness that wraps an AI model with tools, memory, feedback loops, and a supervisory agent. By placing Claude Opus 5 inside this system, Nvidia lifted its score from 30% to 100% on ARC-AGI-3, solving all 183 puzzles across the benchmark’s 25 interactive games. The result suggests that harness design can matter as much as, or more than, changing the underlying model for difficult, long-running agent tasks.

Source

Claude Mythos 5 reaches Enterprise scans, with $35M for open source

Par : IT News
21 août 2026 à 22:06
Claude Mythos 5 reaches Enterprise scans, with $35M for open source
Anthropic is expanding Claude Mythos 5 beyond its limited defender program: Claude Enterprise customers can now use it through Claude Security to scan codebases, identify vulnerabilities, and propose patches. The company is also integrating the model into partner security products and launching a $35 million credit fund for open-source software security, while keeping direct model access restricted.

Source

Microsoft Defender’s signed BTR.sys driver can erase security tools at boot

Par : IT News
21 août 2026 à 21:26
Microsoft Defender’s signed BTR.sys driver can erase security tools at boot
A Microsoft-signed driver built into Defender can be repurposed to remove antivirus and EDR components before they start, giving attackers with administrator-level privileges a powerful boot-time evasion technique. Check Point Research says the approach works from Windows 7 through Windows 11 25H2, bypasses common driver-blocking controls, and is not currently linked to real-world attacks.

Source

SynkLoader turns Microsoft Teams chats into a fake Windows lock-screen trap

Par : IT News
21 août 2026 à 21:26
SynkLoader turns Microsoft Teams chats into a fake Windows lock-screen trap
A newly identified malware family called SynkLoader is being delivered through Microsoft Teams phishing messages that impersonate corporate IT staff. Its most deceptive component displays a fake Windows lock screen to capture passwords, while other modules provide persistence, remote control, network tunneling, and reconnaissance that could support ransomware attacks.

Source

Claude’s invisible watermarks already have several bypasses

Par : IT News
21 août 2026 à 20:45
Claude’s invisible watermarks already have several bypasses
Anthropic’s new invisible watermarks for Claude-generated text are already being circumvented in multiple ways. Within hours of the announcement, Guillaume Meyer published an open-source remover, while other developers demonstrated rewriting, character substitution, sentence reshuffling, and translation-based techniques that can erase or weaken the machine-readable signal.

Source

Cisco fixes nine Crosswork and Secure Workload flaws, five rated 10.0

Par : IT News
21 août 2026 à 15:58
Cisco fixes nine Crosswork and Secure Workload flaws, five rated 10.0
Cisco has added four critical Crosswork vulnerabilities to the five Secure Workload flaws already requiring updates, bringing this security review to nine vulnerabilities overall. Five receive the maximum CVSS score of 10.0, including SQL injection, missing authentication, and access-control issues.

Source

Entra ID will disable custom CSS layouts: admins face an October 2026 deadline

Par : IT News
21 août 2026 à 15:58
Entra ID will disable custom CSS layouts: admins face an October 2026 deadline
Microsoft will retire a range of custom CSS layout and positioning properties in Entra ID company branding on October 26, 2026. Organizations using those properties must update branded sign-in pages before the deadline or risk elements returning to their default positions.

Source

CVSS 10 Entra ID flaw was exploited, but Microsoft needs no customer action

Par : IT News
21 août 2026 à 11:54
CVSS 10 Entra ID flaw was exploited, but Microsoft needs no customer action
Microsoft has disclosed a CVSS 10.0 remote-code-execution vulnerability in Entra ID, its cloud identity service, and confirmed that attackers exploited it in the wild. CVE-2026-69836 has already been fixed within Microsoft’s service, leaving customers with no patches or configuration changes to apply.

Source

Cisco Secure Workload gets five flaws, including two perfect 10.0 CVSS scores

Par : IT News
21 août 2026 à 11:54
CVSS (Common Vulnerability Scoring System) measures the severity and exploitability of security vulnerabilities, with 10.0 representing the highest possible rating. Cisco Secure Workload Software has received fixes for five vulnerabilities, including two access-control bugs rated a perfect 10.0 and another critical flaw scored 9.9, leaving both SaaS and on-premises customers with updates to apply.

Source

GitLab 19.3 puts agentic AI inside the Dedicated AI Gateway

Par : IT News
21 août 2026 à 11:54
GitLab 19.3 puts agentic AI inside the Dedicated AI Gateway
GitLab 19.3 lets GitLab Dedicated customers run the Duo Agent Platform inside the same single-tenant environment and region as their existing workloads, keeping AI processing within their established security boundary. The release follows GitLab 19.2’s autonomous agents with tighter controls for data residency, model selection, spending, secrets, and automated vulnerability fixes.

Source

Cloudflare OAuth now lets users reject unnecessary app permissions

Par : IT News
20 août 2026 à 19:54
Cloudflare OAuth now lets users reject unnecessary app permissions
Cloudflare has introduced optional OAuth scopes, allowing users to approve only the permissions an application needs for a specific task instead of accepting or rejecting the entire request. The change is especially useful for MCP servers and other AI agents that may request broad access but do not need every capability in each session.

Source

Chrome may let Gemini use saved passwords to complete web tasks

Par : IT News
20 août 2026 à 15:22
Chrome may let Gemini use saved passwords to complete web tasks
Google is testing a Chrome feature that would let its Gemini “Spark” agent use selected saved passwords to sign in to websites and complete multi-step tasks. The capability remains experimental and requires users to approve each action, but it would give an AI agent access to credentials that were previously confined to Chrome’s password manager.

Source

❌
❌