Bienvenue sur mon blog

Reflexions sur la technologie, le developpement et l'innovation

Articles récents

4 Mai

ShinyHunters hits Canvas maker Instructure in breach claiming 275 million records

Instructure, the company behind Canvas, confirmed a data breach this weekend after the ShinyHunters extortion gang claimed it stole data belonging to 275 million people across roughly 9,000 schools worldwide. If the numbers hold up, this is one of the largest education-sector breaches on record. The incident started quietly. On April 30, Instructure reported API disruptions affecting Canvas Data 2, Canvas Beta, and Canvas Test environments. The company initially framed it as a technical issue. B

Lire l'article
3 Mai

Security vendor Trellix confirms attackers accessed its source code

Trellix, the cybersecurity company formed from the 2022 merger of McAfee Enterprise and FireEye, has disclosed that attackers gained unauthorized access to a portion of its internal source code repository. The company said it “recently identified” the compromise and immediately brought in outside forensic investigators. Law enforcement has been notified. According to Trellix’s official statement, the investigation so far has found no evidence that: The source code release or distribution pipeli

Lire l'article
2 Mai

Meta acquires Assured Robot Intelligence to build AI brains for humanoid robots

Meta just bought itself a robotics company. The social media giant acquired Assured Robot Intelligence (ARI), a San Diego and New York-based startup building AI models for humanoid robots. The deal closed Friday. Financial terms were not disclosed. ARI was founded by Lerrel Pinto and Xiaolong Wang, two researchers with serious credentials in robot learning. Pinto previously co-founded Fauna Robotics, the kid-size humanoid startup that Amazon snatched up in March. Wang also worked at Fauna before

Lire l'article
1 Mai

Musk admits xAI distilled OpenAI models to train Grok

#HEADER title=Musk admits xAI distilled OpenAI models to train Grok keywords=xai,distillation,openai trial,grok,elon musk,ai ethics #ENDHEADER Elon Musk testified under oath that xAI used OpenAI models to train Grok. His words: it is standard practice to use other AIs to validate your AI. The admission came during the fourth day of Musk v. Altman in a federal courtroom in Oakland. OpenAI lawyer William Savitt pressed Musk on whether his company had used distillation techniques on OpenAI outputs.

Lire l'article
30 Avril

cPanel zero-day exploited since February, 1.5 million instances exposed

CVE-2026-41940 is a CVSS 9.8 authentication bypass in cPanel and WHM. Attackers have been exploiting it in the wild since at least February 23. The fix only shipped on April 28. That gap is the story. Exploitation attempts were happening more than two months before a patch existed. The vulnerability is a CRLF injection in cPanel’s login and session loading processes. User-controlled input from the Authorization header gets written into server-side session files before authentication and without

Lire l'article
29 Avril

LiteLLM SQL injection exploited 36 hours after disclosure

#HEADER title=LiteLLM SQL injection exploited 36 hours after disclosure keywords=litellm,sql injection,cve-2026-42208,ai security,supply chain,sysdig #ENDHEADER Someone started exploiting CVE-2026-42208 in LiteLLM roughly 36 hours after the advisory went public. No PoC needed. The GitHub advisory and the open-source schema were enough. The vulnerability is a pre-auth SQL injection in LiteLLM’s proxy API key verification. An attacker sends a crafted Authorization header to any LLM API route, hits

Lire l'article

Mots-clés

$40 billion $65 billion 1m context 2.8t parameters 3d AI Agents AI efficiency Application Loader Cross-Platform Cybersecurity DKIM DMARC DeepSeek Development Encryption GPT-5 HTTPS LLM LLM optimization Latency Medusa framework Network Protocols Nuitka Open Source PyInstaller Python Reinforcement Learning Rust SPF Software Distribution Sparse Attention TLS 1.3 Web Performance academic integrity acquisition agentic ai agentic ransomware agents ai ai acquisition ai agents ai alignment ai apps ai chips ai code review ai coding ai compute ai costs ai cybersecurity ai economics ai encyclical ai ethics ai infrastructure ai investment ai kill switch ai layoffs ai model ai models ai office ai overview ai partnership ai pricing ai regulation ai safety ai search ai security ai slop ai spending ai super app ai threat defense ai training data ai ultra ai valuation akamai alexander hanff alibaba alphafold amazon amazon bedrock android anodot anthropic anti-spoofing antitrust anysphere apache 2.0 app store appfigures apple arch linux artificial analysis arxiv ascend ascend 910c ashley macisaac assured robot intelligence async aur authentication bypass automatic translation autoregressive decoding aws aws exfiltration azure badhost benchmarks biometrics biotech bitlocker bypass blackmail botnet bug bounty build 2026 bun caisi canvas cbrs cerebras character.ai chatgpt check point china china ai chips christopher olah cisa cisco class action claude claude code claude fable 5 claude mythos claude opus 5 claude sonnet 4.6 cloud cloud computing cloudflare code security codex coding agent coding agents coding model colorado ai act colossus compute congress consent containment copyright coreweave covert networks cpanel credential theft critical infrastructure csam curl cursor cve cve-2026-35616 cve-2026-39987 cve-2026-41940 cve-2026-42208 cyberattack cybersecurity cybersecurity vendor data breach data center data exfiltration data leak daybreak deepfake deepfake ban deepseek deepseek v4 deepseek-v4 defamation developer tools diffusion language model digital services act digital world conference diplomat directory enumeration distillation distributed inference dma drug discovery dspark duckduckgo dutch court easy-day-js ebpf rootkit ed zitron edge computing edtech education election security elon musk email security ems enterprise ai enterprise browser eu eu ai act european commission exploitarium export control export controls extortion fable 5 fair use financials fingerprints finland fireeye firewall credentials foreign intelligence fortibleed forticlient fortinet four-day-workweek frontier ai fugu gabbard gdpr gemini gemini 3.5 flash gemini nano gemini omni gemini spark gemma 4 generative ai geneva geoffrey hinton gitar gitea github github actions github ban github breach github copilot glm 5.2 godfather of ai google google chrome google deepmind google gemini google i/o 2026 google io 2026 google play government stake gpt-5.5 gpt-5.6 gpt-rosalind gpu capacity gpu pooling gpus in space great american ai act grok grok 4.5 gta 6 hallucination happy oyster hardware healthcare high-risk ai huawei hudson rock hugging face humanoid robots i-dlm industrial-policy inference inference acceleration inference optimization infostealer infrastructure instructure investment ios ipo iroh itron jadepuffer kepler communications kimi k3 lakeview langflow lapd large language model large language models lawsuit layerx layoffs lee jae myung libssh2 life sciences linux malware litellm lithuania llm llm agent llm deception llm inference lockdown mode longcat losses luna magnifica humanitas mai-thinking-1 maia 200 mandiant mastra mcafee enterprise meituan memory mesh llm meta microsoft midterms mini shai-hulud mixture of experts mobile apps model routing moonshot ai mortgage multi-agent systems multimodal musk mythos mythos 5 nasdaq national registry national security ncsc nebius nightmare eclipse noam shazeer non-consensual imagery north korea npm nvidia nvidia gb300 nx console nyc oci odni oidc omnibus open source open source ai open weight open weights openai openai trial opus 4.8 oracle oracle cloud orbital compute orchestration p2p parallel decoding parallel token validation patching bottleneck peer preservation peer review performance phishing detection photo editing piracy police records policy pope leo xiv post-training pre-deployment testing privacy private cloud compute project glasswing project perception project polaris prompt injection public wealth fund pulte pwn2own qwen3.8 raas ransomware reasoning model research robot-tax robotics rockstar games russia rust s-1 sakana ai salesforce sam altman samsung sandbox escape search data search engine sec filing security self-hosting semiconductor semiconductors series h settlement shinyhunters silent safeguards silicon valley siri ai sk hynix smart meters snowflake software development software engineering sol sol ultra sora source code breach south korea space technology spacex spacexai spcx speculative decoding sql injection stargate state preemption state-sponsored hacking student data subagents superapp superintelligence superintelligence labs supply chain supply chain attack swe-bench sysdig tang tan tanstack teampcp tech jobs tech layoffs terminal-bench terra the gentlemen third-party vendor threat intelligence together ai token pricing tokio tpu trade secrets training data trainium transformer tree-based attention trellix trivy trump trump ai order uber uc berkeley us-china user backlash vibe coding voting machines vpn vs code extension vulnerabilities vulnerability vulnerability detection vulnerability disclosure vulnerability reporting wafer-scale engine web hosting web security white house windows 11 windows zero-day wiper wiz workforce automation world model worldleaks wwdc 2026 x xai xdr z.ai zero trust zero-day zig zuckerberg