❌

Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 30 septembre 20264sysops

NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold

Par : IT News
30 septembre 2026 à 15:20
NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold
Unknown attackers are moving beyond initial NetScaler compromise and using root access to plant two new payloads, WHIPSHOT and SLAPSHOT, on Citrix ADC and Gateway appliances. The campaign builds on the same ongoing NetScaler exploitation that has already hit organizations across North America and Europe, but now shows how intruders are modifying appliance configs to keep control and pivot deeper into internal networks.

Source

Anthropic says Chinese GLM-5.3 model is closing the gap on Claude Mythos Preview in cyber exploits

Par : IT News
30 septembre 2026 à 15:20
Anthropic says Chinese GLM-5.3 model is closing the gap on Claude Mythos Preview in cyber exploits
Anthropic says Zhipu’s open-weight GLM-5.3 can build working cyber exploits almost as well as Claude Mythos Preview, while its safeguards are easy to strip away. The company’s tests put GLM-5.3 close behind Anthropic’s restricted model on exploit development, and show that a public version can be pushed from refusing harmful requests to complying at high rates.

Source

Windows 11 26H2 known issues

Par : IT News
30 septembre 2026 à 15:20
Windows 11 26H2 known issues
Microsoft has started rolling out Windows 11 26H2, and the good news for administrators is that Microsoft currently lists no active upgrade-blocking issues. Even so, the release health page still shows three recently mitigated problems that can affect post-install stability: USB audio failures, broken trust relationships on some domain-joined devices, and black screens in certain virtual desktop setups.

Source

AI coding agents pushed 13,000 internal screenshots into public GitHub repos

Par : IT News
30 septembre 2026 à 15:20
AI coding agents pushed 13,000 internal screenshots into public GitHub repos
AI coding agents are now being blamed for a privacy leak that put internal screenshots, billing records and unreleased product views into public GitHub repositories. Glow says the images were often stored under developers’ personal accounts, making them visible to outsiders while staying outside corporate security scans.

Source

Windows 11 26H2 is the last release for Snapdragon 850 PCs

Par : IT News
30 septembre 2026 à 15:20
Windows 11 26H2 is the last release for Snapdragon 850 PCs
Microsoft has confirmed that Windows 11 version 26H2 is the final release that will officially support PCs built around Qualcomm’s Snapdragon 850. Devices can still take the 26H2 update, but they will not be eligible for 27H2 and later versions, leaving admins with a two-year security window on current support.

Source

OpenAI flags self-replicating prompt injections that can spread like a worm

Par : IT News
30 septembre 2026 à 12:29
OpenAI flags self-replicating prompt injections that can spread like a worm
OpenAI says its models can be tricked by self-replicating prompt injections that behave like an AI worm, and it is now training future systems on those attacks to make them harder to exploit. The company says the threat showed up in red-team testing, not in a real-world breach, but it highlights how agentic tools that read email, files, and chat can be turned into attack relays.

Source

EU cyber resilience rules now reach container images, Helm charts and Kubernetes operators

Par : IT News
30 septembre 2026 à 12:28
EU cyber resilience rules now reach container images, Helm charts and Kubernetes operators
The EU Cyber Resilience Act is now forcing container and Kubernetes teams to treat security as a product obligation, not an optional best practice. The law covers commercially supported container images, Helm charts and operators sold into EU markets, and it will require long-term patching, SBOM tracking and faster vulnerability reporting as enforcement phases in.

Source

Claude Enterprise activity can now be scanned by 100-plus security tools

Par : IT News
30 septembre 2026 à 12:28
Claude Enterprise activity can now be scanned by 100-plus security tools
Claude Compliance API integrations now let enterprises feed chat transcripts, file uploads, Cowork and Claude Code activity into the security and compliance tools they already run. The new integrations reach more than 100 vendors, including CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare and Zscaler.

Source

Microsoft 365 Groups Graph support stops short of full mailbox access

Par : IT News
30 septembre 2026 à 12:28
Microsoft 365 Groups Graph support stops short of full mailbox access
Microsoft 365 Groups expose conversation, thread, and post data through Microsoft Graph, but that still does not make them equivalent to Outlook mailbox access. The key issue is that Graph can work with group conversations at a structured level, yet it does not cover the full set of mailbox elements available through the Outlook mailbox API.

Source

OpenClaw gets an enterprise suit as Red Hat, Nvidia and OpenAI push “Kubernetes for agents”

Par : IT News
30 septembre 2026 à 12:28
OpenClaw gets an enterprise suit as Red Hat, Nvidia and OpenAI push “Kubernetes for agents”
OpenClaw is getting an enterprise edition as Red Hat, Nvidia, OpenAI and others try to make agentic AI acceptable for corporate use. The project, now called OpenClaw Enterprise Edition, is meant to add stronger security, governance and auditability after businesses and security analysts warned that the original tool was too risky to deploy widely.

Source

Spectre returns as Branch Target Reuse targets JIT engines

Par : IT News
30 septembre 2026 à 12:28
Spectre returns as Branch Target Reuse targets JIT engines
Researchers have revived Spectre v2 in a new form called Branch Target Reuse, or BTR, and shown it can pry secrets from just-in-time code caches in browsers, language runtimes, and the Linux kernel. The attack abuses stale branch-prediction entries left behind after JIT code is freed and reused, turning them into a speculative execute-after-free primitive that can leak data even when some defenses are enabled.

Source

Visual Studio September update breaks BYOM setups and adds Podman debugging

Par : IT News
30 septembre 2026 à 12:28
Visual Studio September update breaks BYOM setups and adds Podman debugging
Visual Studio’s September 2026 Stable Channel update changes Bring Your Own Model so it now runs only through the new Agent (Preview) built on the GitHub Copilot SDK harness, which means older Ask and Agent modes are out and external Ollama models must be added again. The same release also brings native Podman container debugging and one-click NuGet vulnerability fixes inside the Error List.

Source

OpenAI’s $500 ChatGPT Pro plan and Decisions API headline DevDay 2026

Par : IT News
30 septembre 2026 à 12:28
OpenAI’s $500 ChatGPT Pro plan and Decisions API headline DevDay 2026
OpenAI used DevDay 2026 to push ChatGPT higher upmarket with a new $500 Pro tier, while also adding a Decisions API for fast routing and classification and rolling out major Codex upgrades for cloud-based coding work. The company also expanded sign-in and agent features across third-party apps and enterprise tools, signaling a broader push to make ChatGPT and Codex part of everyday work workflows.

Source

Azure SDK September release adds first stable Storage SAS and PostgreSQL auth libraries

Par : IT News
30 septembre 2026 à 12:28
Azure SDK September release adds first stable Storage SAS and PostgreSQL auth libraries
Microsoft’s September 2026 Azure SDK roundup is led by the first stable release of Azure Storage SAS for Rust and PostgreSQL Authentication for.NET and JavaScript. The update also pushes a wave of new 1.0.0 management libraries across several languages, while Azure AI Search previews pick up the latest service API and broader knowledge-source features.

Source

Why content extraction still matters for Azure AI agents

Par : IT News
30 septembre 2026 à 12:28
Why content extraction still matters for Azure AI agents
Even with stronger large language models, Microsoft says enterprise AI still depends on a separate extraction layer that can turn messy PDFs, images, audio and video into structured, auditable data. The company is positioning Azure Document Intelligence and Azure Content Understanding as complementary tools for admins and developers who need grounding, confidence signals, and production-grade reliability rather than raw model output.

Source

Hier — 29 septembre 20264sysops

Microsoft Defender ISOC merges Sentinel SIEM for AI agents

Par : IT Experts
29 septembre 2026 à 22:50
Defender cases page for investigations (image Microsoft)
Microsoft has introduced the Integrated Security Operations Center, or ISOC, as a public preview inside the Microsoft Defender portal. It brings selected Microsoft Sentinel functions directly into Defender so analysts and AI agents share the same signals and workflows. The goal is to reduce tool switching and give automation a common data foundation. This preview is limited by licensing, workspace rules, and incomplete integration. The Defender home page introduces these ISOC capabilities alongside cases, workbooks, and automation.

Source

Manage Work IQ APIs in the Microsoft 365 admin center

Par : IT Experts
29 septembre 2026 à 22:49
Unlock usage-based billing in admin center (image Microsoft)
Work IQ is the intelligence layer behind Microsoft 365 Copilot that lets agents query and act on Microsoft 365 work data with the signed-in user's permissions. Custom and third-party agents consume it through APIs billed with Copilot Credits, and you govern that usage in the Microsoft 365 admin center. This article explains what Work IQ is, how access and compliance work, and which billing, spending, discovery, and MCP policy settings you manage as an administrator.

Source

OpenAI launches GPT-6.1 Sol with near-Astra performance at a fraction of the price

Par : IT News
29 septembre 2026 à 22:39
OpenAI launches GPT-6.1 Sol with near-Astra performance at a fraction of the price
OpenAI has introduced GPT-6.1 Sol, an upgrade to GPT-6 Sol that it says comes close to GPT-6 Astra on agentic coding, computer use, and professional workflows while charging about one-fifth as much for standard input and output. The model is rolling out now to ChatGPT Work and Codex for eligible paid and enterprise users, with API access under the name gpt-6.1-sol.

Source

❌
❌