Bienvenue sur mon blog
Reflexions sur la technologie, le developpement et l'innovation
Articles récents
ShinyHunters hits Canvas maker Instructure in breach claiming 275 million records
Instructure, the company behind Canvas, confirmed a data breach this weekend after the ShinyHunters extortion gang claimed it stole data belonging to 275 million people across roughly 9,000 schools worldwide. If the numbers hold up, this is one of the largest education-sector breaches on record. The incident started quietly. On April 30, Instructure reported API disruptions affecting Canvas Data 2, Canvas Beta, and Canvas Test environments. The company initially framed it as a technical issue. B
Lire l'articleSecurity vendor Trellix confirms attackers accessed its source code
Trellix, the cybersecurity company formed from the 2022 merger of McAfee Enterprise and FireEye, has disclosed that attackers gained unauthorized access to a portion of its internal source code repository. The company said it “recently identified” the compromise and immediately brought in outside forensic investigators. Law enforcement has been notified. According to Trellix’s official statement, the investigation so far has found no evidence that: The source code release or distribution pipeli
Lire l'articleMeta acquires Assured Robot Intelligence to build AI brains for humanoid robots
Meta just bought itself a robotics company. The social media giant acquired Assured Robot Intelligence (ARI), a San Diego and New York-based startup building AI models for humanoid robots. The deal closed Friday. Financial terms were not disclosed. ARI was founded by Lerrel Pinto and Xiaolong Wang, two researchers with serious credentials in robot learning. Pinto previously co-founded Fauna Robotics, the kid-size humanoid startup that Amazon snatched up in March. Wang also worked at Fauna before
Lire l'articleMusk admits xAI distilled OpenAI models to train Grok
#HEADER title=Musk admits xAI distilled OpenAI models to train Grok keywords=xai,distillation,openai trial,grok,elon musk,ai ethics #ENDHEADER Elon Musk testified under oath that xAI used OpenAI models to train Grok. His words: it is standard practice to use other AIs to validate your AI. The admission came during the fourth day of Musk v. Altman in a federal courtroom in Oakland. OpenAI lawyer William Savitt pressed Musk on whether his company had used distillation techniques on OpenAI outputs.
Lire l'articlecPanel zero-day exploited since February, 1.5 million instances exposed
CVE-2026-41940 is a CVSS 9.8 authentication bypass in cPanel and WHM. Attackers have been exploiting it in the wild since at least February 23. The fix only shipped on April 28. That gap is the story. Exploitation attempts were happening more than two months before a patch existed. The vulnerability is a CRLF injection in cPanel’s login and session loading processes. User-controlled input from the Authorization header gets written into server-side session files before authentication and without
Lire l'articleLiteLLM SQL injection exploited 36 hours after disclosure
#HEADER title=LiteLLM SQL injection exploited 36 hours after disclosure keywords=litellm,sql injection,cve-2026-42208,ai security,supply chain,sysdig #ENDHEADER Someone started exploiting CVE-2026-42208 in LiteLLM roughly 36 hours after the advisory went public. No PoC needed. The GitHub advisory and the open-source schema were enough. The vulnerability is a pre-auth SQL injection in LiteLLM’s proxy API key verification. An attacker sends a crafted Authorization header to any LLM API route, hits
Lire l'article