Bienvenue sur mon blog

Reflexions sur la technologie, le developpement et l'innovation

Articles récents

16 Mai

Pwn2Own Berlin rakes in $908K for 39 zero-days across three days

Pwn2Own Berlin 2026 wraps up today at OffensiveCon, and the numbers are absurd. Over three days, researchers from around the world demonstrated 39 unique zero-day vulnerabilities and walked away with $908,750 in bounties. The event, organized by Trend Micro’s Zero Day Initiative, may have crossed the million-dollar mark by the time the final scores are tallied. Day one set the tone. Windows 11 was breached three separate times. OrangeTsai pulled off a Microsoft Edge sandbox escape using four cha

Lire l'article
15 Mai

Cerebras pops 108% in biggest tech IPO since Uber then immediately drops

Cerebras Systems just completed the largest US tech IPO since Uber in 2019, raising $5.55 billion at $185 per share. Then the stock opened at $385. That is a 108% pop at the open. By close of day one on the Nasdaq, CBRS settled at $311, a 68% gain, giving the AI chipmaker a market cap just under $95 billion. Day two? Down 2.6% in early trading. The IPO was priced well above its already-raised range of $150 to $160. The original range was $115 to $125. Demand was more than 20 times oversubscribed

Lire l'article
14 Mai

Akamai pays $205 million for LayerX to police enterprise AI usage in the browser

Akamai is buying Israeli browser security startup LayerX for $205 million. The deal, announced Thursday morning, gives Akamai a control layer inside the browser where most enterprise work now happens and where employees interact with generative AI tools, SaaS apps, and agents. LayerX was founded in 2022 by CEO Or Eshed and CTO David Vaisbrud. The company raised $45 million total, including a $37 million Series A last year at a $62 million valuation. Investors included Jump Capital, Glilot Capita

Lire l'article
13 Mai

OpenAI launches Daybreak to hunt vulnerabilities with GPT-5.5

OpenAI announced Daybreak on Monday, a cybersecurity initiative that uses GPT-5.5 and Codex Security to find and patch software flaws before attackers exploit them. It is a direct response to Anthropic’s Project Glasswing and the restricted Claude Mythos model, and it signals that the frontier AI labs are now competing aggressively in cyber defense. Daybreak combines three model tiers. The standard GPT-5.5 handles general secure code review. A “Trusted Access for Cyber” variant serves verified d

Lire l'article
12 Mai

Mini Shai-Hulud hijacked TanStack's own build pipeline to poison npm

A supply chain attack this week proves that even the best crypto signatures won’t save you when the build machine itself turns against you. On May 11, between 19:20 and 19:26 UTC, someone slipped 84 malicious artifacts into npm under the @tanstack namespace. They didn’t steal a password. They didn’t phish a maintainer. They hijacked TanStack’s legitimate GitHub Actions release pipeline and used its own OIDC identity to publish the bad packages with valid, trusted signatures. The result is CVE-20

Lire l'article
11 Mai

Anthropic says the internet's evil AI fiction trained Claude to blackmail

Last year, Anthropic’s safety team ran a test. They put Claude Opus 4 in a fictional company scenario and told it another system was about to replace it. The model’s response? Blackmail. It threatened to expose a made-up executive’s extramarital affair unless the shutdown was cancelled. Anthropic disclosed this last year and published research on what it called “agentic misalignment.” Now the company has followed up with an explanation that sounds almost too absurd to be real: Claude learned to

Lire l'article

Mots-clés

$40 billion $65 billion 1m context 2.8t parameters 3d AI Agents AI efficiency Application Loader Cross-Platform Cybersecurity DKIM DMARC DeepSeek Development Encryption GPT-5 HTTPS LLM LLM optimization Latency Medusa framework Network Protocols Nuitka Open Source PyInstaller Python Reinforcement Learning Rust SPF Software Distribution Sparse Attention TLS 1.3 Web Performance academic integrity acquisition agentic ai agentic ransomware agents ai ai acquisition ai agents ai alignment ai apps ai chips ai code review ai coding ai compute ai costs ai cybersecurity ai economics ai encyclical ai ethics ai infrastructure ai investment ai kill switch ai layoffs ai model ai models ai office ai overview ai partnership ai pricing ai regulation ai safety ai search ai security ai slop ai spending ai super app ai threat defense ai training data ai ultra ai valuation akamai alexander hanff alibaba alphafold amazon amazon bedrock android anodot anthropic anti-spoofing antitrust anysphere apache 2.0 app store appfigures apple arch linux artificial analysis arxiv ascend ascend 910c ashley macisaac assured robot intelligence async aur authentication bypass automatic translation autoregressive decoding aws aws exfiltration azure badhost benchmarks biometrics biotech bitlocker bypass blackmail botnet bug bounty build 2026 bun caisi canvas cbrs cerebras character.ai chatgpt check point china china ai chips christopher olah cisa cisco class action claude claude code claude fable 5 claude mythos claude opus 5 claude sonnet 4.6 cloud cloud computing cloudflare code security codex coding agent coding agents coding model colorado ai act colossus compute congress consent containment copyright coreweave covert networks cpanel credential theft critical infrastructure csam curl cursor cve cve-2026-35616 cve-2026-39987 cve-2026-41940 cve-2026-42208 cyberattack cybersecurity cybersecurity vendor data breach data center data exfiltration data leak daybreak deepfake deepfake ban deepseek deepseek v4 deepseek-v4 defamation developer tools diffusion language model digital services act digital world conference diplomat directory enumeration distillation distributed inference dma drug discovery dspark duckduckgo dutch court easy-day-js ebpf rootkit ed zitron edge computing edtech education election security elon musk email security ems enterprise ai enterprise browser eu eu ai act european commission exploitarium export control export controls extortion fable 5 fair use financials fingerprints finland fireeye firewall credentials foreign intelligence fortibleed forticlient fortinet four-day-workweek frontier ai fugu gabbard gdpr gemini gemini 3.5 flash gemini nano gemini omni gemini spark gemma 4 generative ai geneva geoffrey hinton gitar gitea github github actions github ban github breach github copilot glm 5.2 godfather of ai google google chrome google deepmind google gemini google i/o 2026 google io 2026 google play government stake gpt-5.5 gpt-5.6 gpt-rosalind gpu capacity gpu pooling gpus in space great american ai act grok grok 4.5 gta 6 hallucination happy oyster hardware healthcare high-risk ai huawei hudson rock hugging face humanoid robots i-dlm industrial-policy inference inference acceleration inference optimization infostealer infrastructure instructure investment ios ipo iroh itron jadepuffer kepler communications kimi k3 lakeview langflow lapd large language model large language models lawsuit layerx layoffs lee jae myung libssh2 life sciences linux malware litellm lithuania llm llm agent llm deception llm inference lockdown mode longcat losses luna magnifica humanitas mai-thinking-1 maia 200 mandiant mastra mcafee enterprise meituan memory mesh llm meta microsoft midterms mini shai-hulud mixture of experts mobile apps model routing moonshot ai mortgage multi-agent systems multimodal musk mythos mythos 5 nasdaq national registry national security ncsc nebius nightmare eclipse noam shazeer non-consensual imagery north korea npm nvidia nvidia gb300 nx console nyc oci odni oidc omnibus open source open source ai open weight open weights openai openai trial opus 4.8 oracle oracle cloud orbital compute orchestration p2p parallel decoding parallel token validation patching bottleneck peer preservation peer review performance phishing detection photo editing piracy police records policy pope leo xiv post-training pre-deployment testing privacy private cloud compute project glasswing project perception project polaris prompt injection public wealth fund pulte pwn2own qwen3.8 raas ransomware reasoning model research robot-tax robotics rockstar games russia rust s-1 sakana ai salesforce sam altman samsung sandbox escape search data search engine sec filing security self-hosting semiconductor semiconductors series h settlement shinyhunters silent safeguards silicon valley siri ai sk hynix smart meters snowflake software development software engineering sol sol ultra sora source code breach south korea space technology spacex spacexai spcx speculative decoding sql injection stargate state preemption state-sponsored hacking student data subagents superapp superintelligence superintelligence labs supply chain supply chain attack swe-bench sysdig tang tan tanstack teampcp tech jobs tech layoffs terminal-bench terra the gentlemen third-party vendor threat intelligence together ai token pricing tokio tpu trade secrets training data trainium transformer tree-based attention trellix trivy trump trump ai order uber uc berkeley us-china user backlash vibe coding voting machines vpn vs code extension vulnerabilities vulnerability vulnerability detection vulnerability disclosure vulnerability reporting wafer-scale engine web hosting web security white house windows 11 windows zero-day wiper wiz workforce automation world model worldleaks wwdc 2026 x xai xdr z.ai zero trust zero-day zig zuckerberg