Bienvenue sur mon blog
Reflexions sur la technologie, le developpement et l'innovation
Articles récents
Curl closes vulnerability reports for all of July
Daniel Stenberg announced today that the curl project will not accept or handle any vulnerability reports during the entire month of July 2026. He calls it the “curl summer of bliss.” The HackerOne submission form goes dark on July 1 at 00:00 CEST. It reopens on August 3 at 09:00 CEST. The security email address becomes a dead end too. If you find a critical curl vulnerability in July, it waits until August. Unless you have a paid support contract, in which case service continues as normal. As a
Lire l'articleZ.ai drops GLM 5.2 with 1M context as Fable 5 goes offline
Z.ai shipped GLM 5.2 on June 13 with a 1-million-token context window and zero benchmarks. The same day, Anthropic’s Fable 5 and Mythos 5 went offline under a US export control order. The timing was not an accident. Developers who woke up to broken Fable API calls suddenly had a drop-in alternative. GLM 5.2 exposes an Anthropic-compatible endpoint, which means Claude Code users need three config changes to switch: set both ANTHROPIC_DEFAULT_SONNET_MODEL and ANTHROPIC_DEFAULT_OPUS_MODEL to glm-5.
Lire l'articleUS government kills Fable 5 and Mythos 5 over a code vulnerability jailbreak
At 5:21pm ET on June 12, Anthropic received an export control directive from the US government. By the evening, Fable 5 and Mythos 5 were dark. Not just for foreign nationals, which the order targeted. For everyone. Anthropic could not isolate foreign users from domestic ones quickly enough, so both models went offline worldwide. Fable 5 had been live for three days. Anthropic rolled it out free to all Pro, Max, and Enterprise customers on June 9. The model that millions were building on Thursda
Lire l'article446 Arch Linux packages hijacked with eBPF rootkit and infostealer
Someone hijacked 446 packages in the Arch User Repository and pushed updates laced with a Rust-based infostealer paired with an eBPF rootkit. This is not a drill. An attacker created a new AUR maintainer account spoofing a trusted maintainer, adopted over 400 orphaned packages, and injected malicious preinstall scripts. The scripts pulled NPM packages (atomic-lockfile v1.4.2 and js-digest) that executed a 3 MB ELF binary called deps during the build process. The reverse engineering by Whanos at
Lire l'articleOpenAI models land on Oracle Cloud with Universal Credits
OpenAI just made it significantly easier for enterprises to adopt its models. Starting in the coming weeks, Oracle Cloud Infrastructure customers can use their existing Oracle Universal Credits to access GPT-5.5 and Codex through the OCI Marketplace. No new vendor agreements. No separate procurement cycle. Just apply credits you already committed to Oracle. The announcement came June 10 from OpenAI and was echoed by Oracle’s own Marketplace blog on June 11. It is the latest signal that the battl
Lire l'articleAnthropic ships Claude Fable 5 with silent self-preservation safeguards
Anthropic released Claude Fable 5 yesterday, the first model from its Mythos tier available to the general public. The benchmarks are absurd: 80.3% on SWE-Bench Pro, 21 points ahead of GPT-5.5 at 58.6%. Stripe ran a codebase-wide migration across 50 million lines of Ruby in one day. Matthew Pines tested frontier physics research and said Fable 5 in 36 hours matched what GPT-5.5 did in four days. But the benchmarks are not the story. The story is what Anthropic is doing behind the curtain. Fable
Lire l'article