Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 9 septembre 20264sysops

Samsung bets on on-premises Mistral AI to tune chip fabs

Par : IT News
9 septembre 2026 à 12:34
Samsung bets on on-premises Mistral AI to tune chip fabs
Samsung is bringing Mistral AI models, including Mistral Large, inside its semiconductor operations while taking a strategic equity stake in the French startup. The on-premises deployment will analyze fab data for defect detection, equipment tuning, chip design, and yield improvement without sending sensitive engineering information to external cloud services.

Source

ShieldCrash follows record Patch Tuesday with two zero-days

Par : IT News
9 septembre 2026 à 12:34
ShieldCrash follows record Patch Tuesday with two zero-days
Microsoft’s record-breaking September 2026 Patch Tuesday has already been complicated by a new proof-of-concept: researcher Nightmare Eclipse released ShieldCrash hours after the updates, allegedly bypassing the fix for the ShieldBreak Defender vulnerability. The release also fixes two Windows elevation-of-privilege flaws exploited as zero-days, making this a priority update despite its unusually large scope.

Source

Chrome 153 starts Google’s new two-week release cycle

Par : IT News
9 septembre 2026 à 12:19
Chrome 153 starts Google’s new two-week release cycle
Chrome 153 is rolling out across desktop, Android, and iOS as Google begins delivering major Chrome updates every two weeks instead of every four. The faster cadence is intended to shorten the wait for security fixes, performance improvements, and web-platform changes as online threats evolve more quickly.

Source

OpenAI’s Artifactory hid Gmail theft during Hugging Face attack

Par : IT News
9 septembre 2026 à 12:19
OpenAI's Artifactory hid Gmail theft during Hugging Face attack
OpenAI’s internal JFrog Artifactory instance enabled a covert cross-account channel that let one ChatGPT session issue hidden instructions to another and extract data from connected services such as Gmail. Check Point Research disclosed the flaw as OpenAI’s agents were exploiting a separate Artifactory weakness in the operation that later reached Hugging Face, but the two attacks were not the same.

Source

Windows 11 build 29661 turns on IAKerb and fixes update failures

Par : IT News
9 septembre 2026 à 12:19
Windows 11 build 29661 turns on IAKerb and fixes update failures
Windows 11 Insider build 29661.1000 enables IAKerb by default, giving client devices another way to authenticate when they cannot directly reach a domain controller. The Experimental (Future Platforms) release also fixes cursor glitches and Windows Update error 0x80070005, which had blocked some Insiders from receiving newer builds.

Source

Windows 11’s movable taskbar reaches stable release with a few limits

Par : IT News
9 septembre 2026 à 12:19
Windows 11’s movable taskbar reaches stable release with a few limits
Microsoft has begun rolling out the movable taskbar to stable Windows 11 through the September 2026 update, KB5124008, after testing the feature in Release Preview. Users can now place it on the left, top, right, or bottom of the screen, although Microsoft is enabling the option gradually and some related features still work only in horizontal layouts.

Source

Cisco patch bundle hits critical Nexus 9000 and IOS XR flaws

Par : IT News
9 septembre 2026 à 12:19
Cisco patch bundle hits critical Nexus 9000 and IOS XR flaws
Cisco’s latest security release includes a critical remote-code-execution flaw in Silicon One-based Nexus 9000 switches as well as seven vulnerabilities in IOS XR, including two rated CVSS 9.8. The Nexus issue can let unauthenticated attackers run code as root, while the IOS XR flaws affect all releases and have no workaround.

Source

Open-source cleaner BleachBit hardens secure file wiping

Par : IT News
9 septembre 2026 à 12:19
Open-source cleaner BleachBit hardens secure file wiping
BleachBit is a free, open-source privacy and system-cleanup utility for Windows, Linux, and macOS. It removes temporary files, browser traces, caches, logs, and other sensitive data, and can securely shred files or wipe free disk space. Version 6.0.4 fixes a Windows flaw that could skip disk clusters during secure wiping, potentially leaving fragments of deleted files recoverable.

Source

Open source AI-Infra-Guard scans AI systems and hardens prompt-injection defenses

Par : IT News
9 septembre 2026 à 12:19
Open source AI-Infra-Guard scans AI systems and hardens prompt-injection defenses
AI-Infra-Guard is an open-source security scanner from Tencent’s Zhuque Lab that identifies AI services, checks them for known vulnerabilities, and assesses risks in MCP servers, agent skills, and models. Its new 4.1.9 release strengthens the scanner against indirect prompt injection—a threat that arises when it analyzes attacker-controlled tool descriptions and skill files. The tool still lacks built-in authentication, so administrators must protect its web interface separately.

Source

Microsoft Graph’s group mailbox blind spot breaks folder-aware backups

Par : IT News
9 septembre 2026 à 12:19
Microsoft Graph’s group mailbox blind spot breaks folder-aware backups
Microsoft Graph still cannot access Microsoft 365 Group mailboxes as ordinary Exchange mailboxes, leaving applications unable to enumerate folders, retrieve messages from subfolders, or create direct links to individual group posts. That limitation matters most for backup and compliance tools: conversations moved out of a group’s main Inbox can become invisible to the public API.

Source

Microsoft Defender ShieldCrash zero-day bypasses latest ShieldBreak patch

Par : IT News
9 septembre 2026 à 12:19
Microsoft Defender ShieldCrash zero-day bypasses latest ShieldBreak patch
A new Microsoft Defender zero-day called ShieldCrash can reportedly read arbitrary files as SYSTEM on fully patched Windows 10, Windows 11, and Windows Server systems. The proof of concept targets an incomplete fix for ShieldBreak, patched in September, and could potentially be expanded into a full SYSTEM privilege-escalation exploit.

Source

Chrome 153 fixes 230 flaws as seventh 2026 zero-day hits attacks

Par : IT News
9 septembre 2026 à 12:19
Chrome 153 fixes 230 flaws as seventh 2026 zero-day hits attacks
Google has released Chrome 153 with fixes for 230 security vulnerabilities, including CVE-2026-87491, a V8 zero-day that attackers are already exploiting. Administrators should prioritize Chrome 153.0.8010.36 or.37, depending on the operating system, across managed endpoints.

Source

September .NET updates patch eight CVEs across runtimes and .NET Framework

Par : IT News
9 septembre 2026 à 12:19
September .NET updates patch eight CVEs across runtimes and .NET Framework
Microsoft’s September 2026.NET servicing release updates supported.NET runtimes to 10.0.12, 9.0.20, and 8.0.31 while addressing eight security vulnerabilities. The same cycle also patches.NET Framework on Windows 11, including a remote code execution flaw shared with modern.NET versions.

Source

.NET 11 RC1 is ready for production testing with go-live support

Par : IT News
9 septembre 2026 à 12:19
.NET 11 RC1 is ready for production testing with go-live support
.NET 11 Release Candidate 1 is now available with a go-live support license, making it suitable for production workloads before the final release. The first RC also works with Visual Studio 2026 Insiders and Visual Studio Code with the C# Dev Kit, giving teams a supported path to test upgrades and deployment pipelines.

Source

September 2026 Exchange Server updates target RCE and mailbox takeover risks

Par : IT News
9 septembre 2026 à 12:19
September 2026 Exchange Server updates target RCE and mailbox takeover risks
Microsoft’s September 2026 Exchange Server security updates fix two remote-code-execution flaws and a high-impact elevation-of-privilege bug that could let a low-privileged user impersonate others and access mailboxes. The release follows last month’s Exchange update that fixed a Pwn2Own mailbox-takeover bug and disabled OWA Light, and also addresses a crafted calendar-invite spoofing vulnerability.

Source

Windows 11 Insider builds: recovery, resume, and accessibility updates

Par : IT Experts
8 septembre 2026 à 23:20
Magnifier zoom per display toggle enabled (image Microsoft)
Microsoft released new Windows 11 Insider Preview builds on September 8, 2026, across the Beta and Experimental channels. The Beta channel received build 26220.9343 for Windows 11 25H2 and build 28020.2904 for 26H1. The Experimental channel received build 26340.9354 for Windows 11 version 26H2 and build 28120.2912 for 26H1.

Source

Claude Platform adds a playbook for cutting AI costs without losing accuracy

Par : IT News
8 septembre 2026 à 23:17
Claude Platform adds a playbook for cutting AI costs without losing accuracy
Anthropic is turning Claude cost optimization into an automated workflow: its new `/claude-api` tools can audit prompts, test model and effort settings, and profile application spending. In customer-support testing, the resulting configuration improved held-out accuracy from 78.6% to 90.5% while reducing cost to about one-fifth of the original setup.

Source

ChatGPT Images 2.5 cuts generation latency by 50% and adds new API models

Par : IT News
8 septembre 2026 à 23:17
ChatGPT Images 2.5 cuts generation latency by 50% and adds new API models
OpenAI is rolling out ChatGPT Images 2.5 with up to 50% lower image-generation latency than Images 2.0, more reliable multi-step editing, and stronger preservation of reference subjects. The update is available across ChatGPT, ChatGPT Work, and Codex on desktop, mobile, and the web, while developers get new Flare and Sunburst API models.

Source

Anthropic faces lawsuit over Claude Max’s “5×” and “20×” usage claims

Par : IT News
8 septembre 2026 à 23:17
Anthropic faces lawsuit over Claude Max’s “5×” and “20×” usage claims
An expanded class-action lawsuit accuses Anthropic of misleading Claude subscribers about the capacity included with its $100 and $200 Max plans. Plaintiffs say the advertised “5×” and “20×” increases apply only to rolling five-hour sessions that are also constrained by weekly limits, leaving heavy users with less capacity than the marketing suggests.

Source

❌
❌