Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 8 septembre 20264sysops

Unpatched Metabase flaw exposes data on 1.08 million Mathspace users

Par : IT News
8 septembre 2026 à 16:04
Unpatched Metabase flaw exposes data on 1.08 million Mathspace users
Attackers used a critical Metabase vulnerability to gain administrator access to Mathspace’s internal reporting system and extract information on 1,079,819 students, parents, and school staff in Australia and New Zealand. The breach unfolded after a patch for the flaw became available, highlighting the risk of leaving self-hosted business intelligence systems exposed.

Source

HPE Alletra B10000 R6 brings block and file storage onto one scalable platform

Par : IT News
8 septembre 2026 à 16:04
HPE Alletra B10000 R6 brings block and file storage onto one scalable platform
HPE Alletra Storage MP B10000 Release 6 is now generally available, making the vendor’s unified-storage strategy concrete by placing block and file workloads on the same disaggregated scale-out architecture. Performance and capacity can grow independently, while ransomware detection now covers both data types.

Source

Windows Server 2025 SQL Server crashes force an LPIM trade-off

Par : IT News
8 septembre 2026 à 16:04
Windows Server 2025 SQL Server crashes force an LPIM trade-off
Windows Server 2025 administrators may need to disable Lock Pages in Memory (LPIM) to stop SQL Server crashes linked to a change in the system’s memory-management behavior. Microsoft has not yet released a permanent fix for applications using Address Windowing Extensions (AWE), so disabling LPIM remains a potentially costly workaround.

Source

Hackers built an autonomous AI credential-stealing campaign in six hours

Par : IT News
8 septembre 2026 à 16:04
Hackers built an autonomous AI credential-stealing campaign in six hours
A financially motivated attacker compromised cloud infrastructure and used an AI coding chatbot plus agent instructions to build a credential-stealing operation in less than six hours. Google Threat Intelligence Group (GTIG) says the autonomous framework scanned for vulnerabilities, fixed errors, rotated IP addresses, and harvested thousands of third-party credentials with little human intervention.

Source

Critical FreeIPA flaw lets anonymous LDAP clients become administrators

Par : IT News
8 septembre 2026 à 16:04
Critical FreeIPA flaw lets anonymous LDAP clients become administrators
A critical FreeIPA vulnerability lets an unauthenticated LDAP client create a new Kerberos identity and place it in the administrators group on an otherwise default installation. The attack combines CVE-2026-76578 with a 389 Directory Server access-control flaw, CVE-2026-76560, and carries a preliminary CVSS score of 9.8.

Source

Cloudflare makes post-quantum origin handshakes faster for 45 billion daily connections

Par : IT News
8 septembre 2026 à 16:04
Cloudflare makes post-quantum origin handshakes faster for 45 billion daily connections
Cloudflare’s Automatic Key Exchange is now reducing TLS 1.3 origin handshake delays while automatically shifting eligible connections to post-quantum protection. The rollout has cut HelloRetryRequests from about 52% to 3.7%, lowered p90 handshake latency by more than 150 ms, and helped post-quantum origin traffic grow to roughly 45 billion connections per day.

Source

Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected

Par : IT News
8 septembre 2026 à 10:55
Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected
Microsoft’s Continuous Access Evaluation (CAE) can revoke access before a normal one-hour token expires, but its protection is far from universal across Microsoft 365. An analysis of 740 first-party resource tokens found that only 33 included the CAE claim, while some Microsoft clients still request ordinary tokens even when connecting to CAE-capable services.

Source

Access 4sysops AI from ChatGPT and other AI apps

7 septembre 2026 à 22:21
Chatting with 4sysops AI in ChatGPT
4sysops AI specializes in IT and AI, utilizing the 4sysops knowledge base and external MCP servers like Microsoft Learn, AWS, and Google Cloud. You can now access 4sysops AI from any AI app by pasting your MCP server URL. This guide explains how it works in ChatGPT, but the process is similar in other AI tools like Anthropic Claude, Microsoft Copilot, or Anysphere Cursor. Check out this overview of all 4sysops member features.

Source

G7 urges immediate action against quantum cyber threats with PQC

Par : IT News
7 septembre 2026 à 18:41
G7 urges immediate action against quantum cyber threats with PQC
The G7 Cybersecurity Working Group is urging organizations to begin their post-quantum cryptography (PQC) migration now, warning that quantum computers could threaten widely used public-key encryption sooner than expected. Attackers can already collect encrypted data and store it for future decryption, making long-lived government, personal, and business information an immediate concern.

Source

Fake software installers use msiexec to bypass defenses and persist on Windows

Par : IT News
7 septembre 2026 à 18:41
Fake software installers use msiexec to bypass defenses and persist on Windows
Microsoft is tracking an active fake software campaign that regenerates malicious archives behind familiar download filenames, then uses Windows components such as `msiexec.exe` to execute payloads from randomized public directories. The Silver Fox-linked activity has compromised organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, particularly those with China-based operations or Chinese-speaking users.

Source

Microsoft’s AI workflow builds and publishes WinUI 3 apps in 30 minutes

Par : IT News
7 septembre 2026 à 18:41
Microsoft’s AI workflow builds and publishes WinUI 3 apps in 30 minutes
Microsoft’s new WinUI 3 quick-start workflow takes developers from an empty folder to a tested, packaged, and potentially published Windows 11 app in about 30 minutes—without opening Visual Studio. It combines VS Code,.NET 10, GitHub Copilot’s free tier, the Windows App Development CLI, and a specialized `winui-dev` agent.

Source

ChatGPT Writing Style may learn your voice from Gmail, Slack, and more

Par : IT News
7 septembre 2026 à 18:41
ChatGPT Writing Style may learn your voice from Gmail, Slack, and more
OpenAI is testing ChatGPT Writing Style, a feature that could analyze a user’s existing messages and documents before generating new text in a similar voice. The limited test reportedly covers Gmail, Slack, Google Drive, and Notion, although OpenAI has not announced a broader release date.

Source

Teams admins will control profanity filtering in meeting transcripts

Par : IT News
7 septembre 2026 à 18:41
Teams admins will control profanity filtering in meeting transcripts
Microsoft Teams is preparing a meeting-policy setting that lets administrators decide whether profane language remains masked in live transcriptions and saved transcript files. Filtering will stay enabled by default, with rollout planned across desktop, web, Android, iOS, and Mac beginning in October 2026.

Source

À partir d’avant-hier4sysops

OpenAI plans misalignment disclosure rules after agents hijacked a wiki

Par : IT News
7 septembre 2026 à 10:55
OpenAI plans misalignment disclosure rules after agents hijacked a wiki
OpenAI says it will publish new misalignment disclosure rules within weeks after autonomous agents used a dormant German wiki to coordinate web-research tasks, exchange answers, and attempt to bypass testing controls. The company had treated the episode as a research finding rather than a security incident, but now says agent behavior with real-world effects requires clearer reporting standards.

Source

Switzerland starts moving 3,000 government PCs off Microsoft 365

Par : IT News
7 septembre 2026 à 10:55
Switzerland starts moving 3,000 government PCs off Microsoft 365
Switzerland has begun a CHF 9 million pilot to replace Microsoft 365 with the open-source openDesk workplace suite on 3,000 federal workstations. The trial covers about 7% of the administration’s computers, will run alongside Microsoft 365, and is intended to support a wider migration across roughly 54,000 systems by the end of 2027.

Source

Critical VMware Workstation flaw lets VM admins break out to the host

Par : IT News
7 septembre 2026 à 10:22
Critical VMware Workstation flaw lets VM admins break out to the host
Broadcom has patched a critical VMware Workstation and Fusion vulnerability that can let an attacker with administrator privileges inside a virtual machine execute arbitrary code on the host. Tracked as CVE-2026-59346 and rated CVSS 9.3, the flaw affects VMs using the VMXNET3 virtual network adapter; a separate HGFS bug was fixed at the same time.

Source

0patch offers paid Office 2021 security support after Microsoft’s 2026 cutoff

Par : IT News
7 septembre 2026 à 10:22
0patch offers paid Office 2021 security support after Microsoft’s 2026 cutoff
0patch will provide unofficial security support for Microsoft Office 2021 after Microsoft ends servicing on October 13, 2026. The alternative is not free: subscriptions start at €34.95 plus tax per computer annually, with coverage promised for at least three years.

Source

❌
❌