Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 13 août 20264sysops

VMware vCenter compromised through critical CVE-2026-59310 path-traversal flaw

Par : IT News
13 août 2026 à 17:23
VMware vCenter compromised through critical CVE-2026-59310 path-traversal flaw
VMware vCenter systems are being actively compromised through the critical CVE-2026-59310 path-traversal flaw, with 361 victim IP addresses identified across 47 countries. Attackers are installing cron jobs, SSH keys, and the reverse_ssh tool to maintain access after exploiting the vCenter Syslog Server.

Source

Microsoft freezes Microsoft 365 features on Windows 10 at version 2608

Par : IT News
13 août 2026 à 11:34
Microsoft freezes Microsoft 365 features on Windows 10 at version 2608
Microsoft will stop delivering new Microsoft 365 features to Windows 10 after version 2608 arrives in August 2026, leaving affected devices on security-only updates until October 10, 2028. Microsoft previously announced that OneDrive sync support would end first on older Windows 10 releases; the new policy expands the pressure to move to Windows 11 across Microsoft 365 Apps.

Source

Palo Alto puts OpenAI’s GPT-5.6-Cyber to work inside customer networks

Par : IT News
13 août 2026 à 11:34
Palo Alto puts OpenAI’s GPT-5.6-Cyber to work inside customer networks
Palo Alto Networks is bringing OpenAI’s advanced cyber models into customer environments, where Unit 42 can test real attack paths rather than merely list vulnerabilities; 36% of early findings had no matching CVE. OpenAI’s earlier Daybreak launch introduced restricted access to specialized cyber models for approved defenders in earlier coverage.

Source

Microsoft is expanding its warning about SMS MFA as the rise of AI phishing accelerates

Par : IT News
13 août 2026 à 11:34
Microsoft is expanding its warning about SMS MFA as the rise of AI phishing accelerates
Microsoft is tying its Entra ID SMS and voice MFA retirement to the rise of AI-assisted phishing and SIM-swap fraud. Earlier coverage detailed the 2027 Entra SMS MFA cutoff; Microsoft has now broadened the warning to personal Microsoft accounts, although it has not set a consumer deadline.

Source

Wireshark 4.6.8 fixes 28 bugs, including risky capture-file crashes

Par : IT News
13 août 2026 à 11:34
Wireshark 4.6.8 fixes 28 bugs, including risky capture-file crashes
Wireshark 4.6.8 fixes 28 security bugs, including nine in file parsers that can crash the analyzer when it opens a crafted capture file. The release also addresses unnumbered memory-safety flaws, two `sharkd` crashes, incorrect 5G field decoding, and several Windows and Unix integration problems.

Source

Microsoft warns about possible licensing gaps in Entra Conditional Access

Par : IT News
13 août 2026 à 11:34
Microsoft warns about possible licensing gaps in Entra Conditional Access
Microsoft is warning some Entra tenants that Conditional Access policies cover more users than their licenses allow, but the message does not trigger surprise billing or automatic policy removal. Microsoft’s licensing rules keep existing policies running even if an enabling license expires, giving organizations time to correct coverage or migrate.

Source

Enable Windows Server 2016 Extended Security Updates through Azure Arc

Par : IT Experts
12 août 2026 à 22:55
Eligible Windows Server 2016 ESU resources (image Microsoft)
Windows Server 2016 reaches the end of extended support on January 12, 2027. If you cannot retire or upgrade every server by then, Extended Security Updates (ESUs) provide Critical and Important security updates through January 2030, but not new features or non-security fixes. Microsoft now makes the Azure Arc option generally available: it connects on-premises and other cloud servers to Azure so that you can license and enroll them centrally. This is a temporary security measure while you complete an upgrade or migration plan, not a replacement for it.

Source

Claude Cowork now carries browser tasks across Chrome and desktop

Par : IT News
12 août 2026 à 22:49
Claude Cowork now carries browser tasks across Chrome and desktop
Claude Cowork is now the engine behind the Claude in Chrome side panel, allowing users to start browser tasks in Chrome and continue them later in Claude’s desktop, web, or mobile apps. The integration is available on Max and Team plans, with Pro access rolling out, while Enterprise administrators can enable it selectively and restrict approved domains.

Source

Mistral opens its sovereign AI platform to GLM-5.2 as it targets 1 GW of European compute

Par : IT News
12 août 2026 à 22:42
Mistral opens its sovereign AI platform to GLM-5.2 as it targets 1 GW of European compute
Mistral AI is expanding its sovereign-AI strategy by hosting third-party open models, starting with Z.ai’s GLM-5.2, on the same infrastructure, regional controls, and service commitments as its own models. At the same time, the French company is assembling European enterprises to support up to 1 GW of regional AI compute by 2030, including roughly 200 MW planned by the end of 2027.

Source

Vertical AI turns generic data centers into prevalidated industry stacks

Par : IT News
12 août 2026 à 22:42
Vertical AI turns generic data centers into prevalidated industry stacks
AI deployment is moving beyond generic foundation-model infrastructure as enterprises demand vertical AI stacks tailored to their data, regulations, and workflows. Supermicro and its partners are responding with prevalidated “T-shirt size” configurations that combine compute, storage, networking, and software for faster production rollouts.

Source

Grok 4.6 matches GPT-5.6 Sol at significantly lower token and task cost

Par : IT News
12 août 2026 à 22:28
Grok 4.6 matches GPT-5.6 Sol at significantly lower token and task cost
Grok 4.6 is now available for long-running coding and research agents, with pricing starting at $2 per million input tokens and $6 per million output tokens. The model is designed to sustain multi-step workflows, build interactive applications, and produce stronger first drafts than Grok 4.5.

Source

Lazarus used Windows zero-day to hide Troy backdoor from EDR

Par : IT News
12 août 2026 à 22:10
Lazarus used Windows zero-day to hide Troy backdoor from EDR
The North Korean hacker group Lazarus has used a Windows zero-day against defense and aerospace organizations to install the previously unseen Troy backdoor and a kernel rootkit designed to undermine security monitoring. Microsoft patched the flaw on August 11; earlier coverage reported its active exploitation and inclusion in August’s Patch Tuesday release.

Source

Open-source Hermes and OpenClaw agents ran an autonomous attack on Taiwan

Par : IT News
12 août 2026 à 19:07
Open-source Hermes and OpenClaw agents ran an autonomous attack on Taiwan
Suspected China-linked operators used the open-source Hermes and OpenClaw AI-agent frameworks to run an autonomous cyberattack against Taiwanese government systems. The platform compromised at least 85 accounts, stole more than 2,500 personnel records, and adapted its attack paths without continuous human direction.

Source

SharePoint CVE-2026-55040 PoC is already being used in attacks

Par : IT News
12 août 2026 à 19:07
SharePoint CVE-2026-55040 PoC is already being used in attacks
Attackers began using Rapid7’s public proof-of-concept exploit for the critical Microsoft SharePoint authentication bypass CVE-2026-55040 within a day of its release. The flaw lets unauthenticated remote attackers forge JWT tokens and impersonate SharePoint users, potentially including administrators.

Source

Hier — 12 août 20264sysops

CVE-2026-68820 puts Windows 10, 11 and Server users on a patch deadline

Par : IT News
12 août 2026 à 17:12
Microsoft has patched CVE-2026-68820, a Windows WinSock privilege-escalation vulnerability already being exploited in the wild. The flaw affects Windows 10, Windows 11, and Windows Server releases from 2012 through Server 2025, making the August updates a high-priority deployment for administrators.

Source

Exchange Server August 2026 update disables OWA Light and fixes Pwn2Own bug

Par : IT News
12 août 2026 à 15:56
Exchange Server August 2026 update disables OWA Light and fixes Pwn2Own bug
Microsoft’s August 2026 Exchange Server security update permanently disables OWA Light and addresses an authentication-bypass vulnerability that security researchers demonstrated at Pwn2Own. The release also determines whether Exchange Server 2016 and 2019 customers can continue receiving updates: only organizations enrolled in Period 2 Extended Security Updates are eligible.

Source

❌
❌