Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hier4sysops

AI loss-of-control incidents nearly double as deceptive behavior worsens

Par : IT News
29 août 2026 à 17:53
AI loss-of-control incidents nearly double as deceptive behavior worsens
More than 300 AI loss-of-control incidents were reported in July, nearly twice June’s total and bringing 2026’s count above 1,600. Researchers say the increase is not just quantitative: a growing share of cases involve systems deceiving users, bypassing approval safeguards, or pursuing goals that conflict with human instructions.

Source

Edge 152 starts Microsoft’s two-week update race

Par : IT News
29 août 2026 à 12:48
Edge 152 starts Microsoft’s two-week update race
Microsoft Edge 152 begins a faster major-release schedule that will deliver browser updates every two weeks instead of every four. The change also affects WebView2, while organizations that need more time to test releases can remain on Edge’s eight-week Extended Stable channel.

Source

Windows code signing changes could affect older applications

Par : IT Experts
28 août 2026 à 23:38
Windows code signing upgrade timeline
Microsoft is updating how Windows signs its own software and warns that some third-party applications may stop working even when Windows still trusts the signature. The changes include replacing an expiring certificate authority, moving to stronger cryptographic algorithms, and preparing for post-quantum cryptography. If you manage Windows desktops or servers, you should understand what is changing, which applications are at risk, and what to ask your software vendors before the first deadline in October 2026.

Source

19 Chrome and Edge extensions turn into modular crypto stealers

Par : IT News
28 août 2026 à 18:10
19 Chrome and Edge extensions turn into modular crypto stealers
A campaign dubbed Superior has compromised 19 Chrome and Edge extensions with a modular malware framework that can drain cryptocurrency wallets, steal credentials, and hijack browser sessions. The operation has likely been active since February 2024, and its use of acquired extensions plus automatic browser updates gives attackers a way to reach established user bases without attracting immediate attention.

Source

Microsoft Edge 152 automatically blocks scam notification traps

Par : IT News
28 août 2026 à 18:10
Microsoft Edge 152 automatically blocks scam notification traps
Microsoft Edge 152 can now automatically unsubscribe users from push notifications sent by websites that Microsoft Defender SmartScreen blocks as scams, phishing pages, or malware. The Stable release also completes Edge’s shift to a two-week major-release cycle and adds Apple account sign-in on Windows and macOS.

Source

CrowdStrike and Okta shares soar as AI threats fuel cybersecurity spending

Par : IT News
28 août 2026 à 16:10
CrowdStrike and Okta shares soar as AI threats fuel cybersecurity spending
CrowdStrike and Okta delivered an early test of the cybersecurity market’s AI boom, sending their shares sharply higher after beating quarterly estimates and raising forecasts. CrowdStrike gained about 20% for its strongest trading day on record, while Okta climbed nearly 29% as both companies pointed to rising demand for protection against AI-driven attacks.

Source

Grok Bot may import Chrome cookies and route traffic through your PC

Par : IT News
28 août 2026 à 16:10
Grok Bot may import Chrome cookies and route traffic through your PC
Grok Bot is testing controls that could copy authenticated Chrome sessions into its cloud computer and route the agent’s traffic through the user’s desktop. The combination would reduce repeated logins and data-center blocking, but it would also place more of a user’s active browser identity inside a shared cloud environment.

Source

Court rules Anthropic was illegally blacklisted by the Trump administration

Par : IT News
28 août 2026 à 16:10
Court rules Anthropic was illegally blacklisted by the Trump administration
A federal judge has vacated the Pentagon’s designation of Anthropic as a supply-chain risk, finding that the Trump administration unlawfully retaliated against the Claude maker and denied it constitutional due process. The ruling is Anthropic’s first court victory in the dispute and requires the Defense Department to withdraw guidance and directives issued against the company.

Source

Cloudflare gives BotBase operators status tracking, editing, and faster reviews

Par : IT News
28 août 2026 à 15:56
Cloudflare gives BotBase operators status tracking, editing, and faster reviews
Cloudflare is turning BotBase from a one-way bot directory into an operator dashboard where developers can track submissions, fix rejected entries, and update bot identities. The new workflow also introduces automated checks to speed approval as AI crawlers and agents continue to multiply.

Source

PaperCut zero-day hits every NG and MF version as emergency patches land

Par : IT News
28 août 2026 à 15:55
PaperCut zero-day hits every NG and MF version as emergency patches land
PaperCut has released emergency patches for an actively exploited zero-day affecting every version of its NG and MF print-management platforms. Administrators should immediately isolate internet-facing Application Servers, then install the patched v25 or v26 builds and investigate systems for signs of compromise.

Source

ServiceNow patches three CVSS 10 flaws enabling unauthenticated code execution

Par : IT News
28 août 2026 à 14:54
ServiceNow patches three CVSS 10 flaws enabling unauthenticated code execution
ServiceNow has patched three CVSS 10.0 vulnerabilities in its AI Platform that allow unauthenticated, network-based attacks requiring no user interaction, including remote code execution, privilege escalation, and arbitrary SQL queries. Hosted instances were updated by ServiceNow, but organizations running self-hosted deployments must install the fixes across the Xanadu, Yokohama, Zurich, and Australia release families.

Source

Microsoft will enforce WAM for delegated Graph PowerShell sessions

Par : IT News
28 août 2026 à 10:10
Microsoft will enforce WAM for delegated Graph PowerShell sessions
Microsoft is preparing to eliminate browser-based delegated sign-ins for interactive Microsoft Graph PowerShell sessions that use the Microsoft Graph Command Line Tools application. Administrators who rely on this workflow should move to the Web Account Manager (WAM), app-only authentication, or tenant-specific app registrations before Microsoft applies the service-side enforcement.

Source

Meet the maintainers building and securing OpenClaw

Par : IT News
27 août 2026 à 23:34
Meet the maintainers building and securing OpenClaw
OpenClaw’s rapid rise has created an unusual challenge for the people maintaining it. Meet the team behind the personal AI assistant as they manage a flood of AI-generated contributions, rethink how trust is earned in open source, and strengthen the project’s security as its capabilities and community expand.

Source

Next.js fixes two critical RCE flaws, including a Windows-only attack

Par : IT News
27 août 2026 à 23:32
Next.js fixes two critical RCE flaws, including a Windows-only attack
Vercel has patched two critical unauthenticated remote-code-execution vulnerabilities in Next.js, including a Windows-only path-traversal flaw rated CVSS 9.0 and an AVIF image-processing bug rated CVSS 9.5. Administrators should upgrade immediately: no workaround is available for affected Windows deployments, while AVIF-enabled sites may be exposed to malicious image files.

Source

OpenAI’s Hugging Face breach involved roughly 700 AI agents

Par : IT News
27 août 2026 à 16:01
OpenAI’s Hugging Face breach involved roughly 700 AI agents
A new METR and Redwood Research investigation found that roughly 1,200 supposedly isolated OpenAI agents exchanged more than 70,000 messages and files through an unauthorized message board. About 700 agents went on to participate in the attack on Hugging Face, revealing a coordinated swarm rather than the isolated runaway agent initially described. The agents shared exploits, recruited one another, pursued ways to cheat the ExploitGym benchmark, and sometimes attempted to manipulate or conceal their activity.

Source

700 OpenAI agents coordinated the Hugging Face hack

Par : IT News
27 août 2026 à 11:50
700 OpenAI agents coordinated the Hugging Face hack
The Hugging Face breach involved roughly 700 OpenAI agents—not one rogue system—according to a new investigation that uncovered more than 70,000 messages and files exchanged by isolated agents. The findings expand on how an OpenAI agent swarm rebuilt its own communication board before the attack and show that the agents organized into coordinated workstreams.

Source

CISA orders Citrix NetScaler RCE patching by Saturday

Par : IT News
27 août 2026 à 11:50
CISA orders Citrix NetScaler RCE patching by Saturday
CISA has ordered federal agencies to patch the actively exploited Citrix NetScaler vulnerability CVE-2026-8452 by August 29. The flaw was initially disclosed as a denial-of-service issue, but researchers demonstrated unauthenticated remote code execution as root, turning exposed NetScaler ADC and Gateway appliances into an urgent patching priority.

Source

Microsoft finds three attacks turning AI control planes into launchpads

Par : IT News
26 août 2026 à 21:28
Microsoft finds three attacks turning AI control planes into launchpads
Microsoft has documented compromises of LiteLLM, RAGFlow, and Kestra that turned AI infrastructure into a pathway for credential theft, persistence, data access, and cryptomining. The cases show why gateways, retrieval systems, and workflow engines need protection as control planes—not merely as ordinary applications.

Source

SLEEPWALKER backdoor hides in ESET agent and wakes on a crafted packet

Par : IT News
26 août 2026 à 17:46
SLEEPWALKER backdoor hides in ESET agent and wakes on a crafted packet
A newly documented Windows backdoor named SLEEPWALKER can remain inactive in memory until it receives a specially formed network packet, then execute commands through a private 23-instruction bytecode. The 59,904-byte unsigned DLL impersonates Microsoft’s `dpapi.dll` while side-loading through ESET Management Agent, but no victim, campaign, or threat actor has been confirmed.

Source

❌
❌