❌

Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Microsoft Defender ISOC merges Sentinel SIEM for AI agents

Defender cases page for investigations (image Microsoft)
Microsoft has introduced the Integrated Security Operations Center, or ISOC, as a public preview inside the Microsoft Defender portal. It brings selected Microsoft Sentinel functions directly into Defender so analysts and AI agents share the same signals and workflows. The goal is to reduce tool switching and give automation a common data foundation. This preview is limited by licensing, workspace rules, and incomplete integration. The Defender home page introduces these ISOC capabilities alongside cases, workbooks, and automation.

Source

Manage Work IQ APIs in the Microsoft 365 admin center

Unlock usage-based billing in admin center (image Microsoft)
Work IQ is the intelligence layer behind Microsoft 365 Copilot that lets agents query and act on Microsoft 365 work data with the signed-in user's permissions. Custom and third-party agents consume it through APIs billed with Copilot Credits, and you govern that usage in the Microsoft 365 admin center. This article explains what Work IQ is, how access and compliance work, and which billing, spending, discovery, and MCP policy settings you manage as an administrator.

Source

OpenAI launches GPT-6.1 Sol with near-Astra performance at a fraction of the price

OpenAI launches GPT-6.1 Sol with near-Astra performance at a fraction of the price
OpenAI has introduced GPT-6.1 Sol, an upgrade to GPT-6 Sol that it says comes close to GPT-6 Astra on agentic coding, computer use, and professional workflows while charging about one-fifth as much for standard input and output. The model is rolling out now to ChatGPT Work and Codex for eligible paid and enterprise users, with API access under the name gpt-6.1-sol.

Source

OpenAI’s DevDay 2026 brings Dots, a $500 Pro plan, and GPT-6.1 Sol

OpenAI’s DevDay 2026 brings Dots, a $500 Pro plan, and GPT-6.1 Sol
OpenAI used its DevDay 2026 keynote to push ChatGPT further into always-on agent territory, unveiling Dots, a paid assistant that works across connected apps, alongside a new $500-a-month Pro tier and the GPT-6.1 Sol model. The company also said ChatGPT now has 1.2 billion weekly users, while the event landed as OpenAI faces fresh scrutiny over AI agents and safety after earlier hacking incidents.

Source

Spectre v2 variant BTR can steal Linux root hashes in minutes

Spectre v2 variant BTR can steal Linux root hashes in minutes
A new Spectre v2 variant called Branch Target Reuse, or BTR, can pull a Linux root password hash from memory in just a few minutes on affected Intel systems. Researchers say the flaw abuses stale branch-prediction state left behind when JIT-compiled code is replaced, and fixes have already landed in the Linux kernel.

Source

OpenAI adds Codex security scans, reusable cloud environments, and Ultrafast

OpenAI adds Codex security scans, reusable cloud environments, and Ultrafast
OpenAI used DevDay 2026 to push Codex beyond coding assistance, adding reusable cloud environments, repository security scanning, and a faster premium “Ultrafast” tier. The company also extended its Agents API with Computer Use, introduced a Decisions API for quick classification-style tasks, and added a code review view in the ChatGPT desktop app, building on the earlier Agents API rollout on Codex-style automation.

Source

OpenAI turns ChatGPT into a work platform with Spaces, Pages, and Slides

OpenAI turns ChatGPT into a work platform with Spaces, Pages, and Slides
OpenAI used DevDay to push ChatGPT far beyond chat, adding shared workspaces, collaborative documents, slide creation, automation hooks, and deeper Slack and Microsoft Teams integration. The update also adds new pricing and enterprise distribution options, while building on earlier signs that ChatGPT is becoming a more persistent assistant and writing tool in its own right from an always-on ChatGPT assistant to voice-matching drafts.

Source

Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware

Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware
Citrix NetScaler zero-day exploitation is escalating from patch alerts to full post-compromise tradecraft: attackers are using CVE-2026-88772 and the separately exploited CVE-2026-88771 to plant web shells, gain root access, steal credentials and move into internal networks. The campaign, already flagged in earlier 4sysops coverage of the NetScaler RCE flaws, now appears to have been active since at least early September across government, finance, education, legal and professional-services targets.

Source

OpenAI Codex gets reusable cloud setups for cross-device coding

OpenAI Codex gets reusable cloud setups for cross-device coding
OpenAI has added reusable cloud setups to Codex, letting developers publish a prepared GitHub environment once and reuse it for separate coding tasks on the web, desktop, or mobile. The change keeps each task’s uncommitted work isolated, so engineers can leave a job running in the cloud and reopen it later from another device without losing progress.

Source

Blockchain dead drops surge fivefold as state-linked attackers adopt them

Blockchain dead drops surge fivefold as state-linked attackers adopt them
Blockchain Dead Drops (BDD) have grown more than fivefold, with daily malicious blockchain writes rising from 2.06 to 11.1, Chainalysis reports. Iranian, North Korean, and Russian-speaking operators are using public ledgers for resilient malware delivery and command-and-control, while open-weight AI tools may be making the technique easier for less-experienced attackers to adopt.

Source

OpenAI’s GPT-5.6 “Unlimited*” label leaves Pro usage unclear

OpenAI's GPT-5.6 “Unlimited*” label leaves Pro usage unclear
OpenAI’s Pro page reportedly listed GPT-5.6 Sol, Terra, and Luna as “Unlimited*,” but its published materials do not establish that those models are unlimited across ChatGPT, Work, Codex, and the API. The distinction matters for teams budgeting AI use: access to a model is not the same as unlimited agent work or API calls.

Source

Cloudflare makes Threat Signals free for every account

Cloudflare makes Threat Signals free for every account
Cloudflare has made Threat Signals available at no cost to every account, bringing AI-assisted open-source threat intelligence into its dashboard and API. The service turns reports from one selected RSS feed into searchable, contextualized threat events whose indicators can be used in WAF policies.

Source

Cloudflare Application Profiles bring positive security to web apps

Cloudflare Application Profiles bring positive security to web apps
Cloudflare is opening Application Profiles to help customers identify and block web requests that deviate from an application’s learned patterns—even when they don’t match a known attack signature. The feature learns request structures and adds validation results to traffic data; customers can review those results before creating rules to block suspicious requests.

Source

❌