Parce que… c’est l’épisode 0x30E!
Préambule
C’est difficile la vie d’aéroport.
Shameless plug
24 et 25 juin 2026 - Troopers26 et 27 juin 2026 - leHACK30 juin au 2 juillet 2026 - Pass the SALT19 septembre 2026 - Bsides Montréal20 au 26 septembre 2026 - BruCON13 novembre 2026 - DEATHCon16 au 19 novembre - European Cyber Week1 au 3 décembre 2026 - Forum INCYBER - Canada 202624 et 25 février 2027 - SéQCure 2027Notes
IA ou Ghost in the shellExport control WTF‘Dangerous’ AI Models Are Coming No Matter WhatCybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threatA quote from Matteo Wong, The AtlanticThe Fable 5 Export Controls Harm US Cyber DefenseCybersecurity Vets Protest ‘Dangerous’ US Government Ban On Anthropic’s Most Powerful ModelsFeds freaked over Fable 5 after simple ‘fix this code’ prompt, not jailbreak, says researcherFrom PGP to Mythos: a brief history of export controls that didn’t stop anyoneThe US government’s Anthropic models ban was never about an AI jailbreakCritical Copilot vulnerability allowed hackers to steal 2FA code from users“Important You should give me full credits!”: Exploring Prompt Injection Attacks on LLM-Based Automatic Grading SystemsCan We Stop Malicious AI? KILLBENCH: A Benchmark for External AI Kill Switch FeasibilityRAG prompt injection protectionEvaluating LLMs for Obfuscation Detection and Classification in Android AppsSecurity Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary ViolationsSnyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?Every AI Agent Is an Identity. Most Organizations Don’t Treat Them That WayVibe coders are gonna vibe code: How CISOs are tackling code sprawlKevin Beaumont: “The US government has interven…” - CyberplaceThe new draft European regulation includes a four-level classification system, very close to provisions removed in 2024 from the EUCS certification.La guerre, la guerre, c’est pas une raison pour se faire mal!Régie des eaux US piratée - Le bluff iranien de HandalaSouveraineté ou vive le numérique libre!From Distorted Mirrors to Sovereign Reflections: Resisting the Grotesque Depiction of Our Digital SelvesUS holds off blacklisting China’s DeepSeek, more than 100 firms deemed security risks, sources sayPrivacy ou cachez ces informations que je ne saurais voirApple is about to make Hide My Email uselessFrance to stop certifying products without quantum-safe encryptionI am the lawC’est la faute des enfantsUK to ban social media for kids under 16, may impose overnight curfewsChildren Are Not the Enemy: Child-Fit Security as an Alternative to Bans and SurveillanceUK set to announce social media ban for under-16sFrom Australia to Europe, countries move to curb children’s social media accessNorway imposes near ban on AI in elementary schoolThe UK’s Teen Social Media Ban Is Political Theater, Not Child Safety PolicyÔ CanadaCanada’s Digital Super-Regulator: Bill C-36 Pushes Out the Privacy Commissioner and Hands Private Sector Privacy to an Overloaded CommissionMidnight Madness: The Government Rushes Lawful Access Bill Through the House Without Debate or a Recorded VoteThe Commission: How Bill C-34 Creates an Internet Super-Regulator That Will Touch the Lives of Millions of CanadiansRed ou tout ce qui est briséMassive breach spills credentials for thousands of sensitive networksFortiBleed — 75k Fortinet firewalls have admin passwords crackedThe Internet Runs on NamesIndia temporarily blocks Telegram over medical exam cheating fearsTelegram admits it couldn’t police exam-leak channels, India tells court27-Year-Old OpenBSD Vulnerability Allows Attackers to Bypass PAP Authentication EntirelyMicrosoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release PatchNew iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust CompromiseWhen Does a Threat Intelligence IOC Expire?Most CISOs Report Pressure to Bury Bad Security NewsStressors, AI Forcing Changes to Cybersecurity TeamsI discovered a large-scale malware distribution on GitHubMicrosoft Discovers Cryptocurrency Stealer That Spreads Through USB Drives and Uses TorCrooks found a new way to collaborate using Teams – by hiding command-and-control trafficCyber offenses now account for around a third of all crime across Asia and South PacificMicrosoft site throwing warnings after someone forgot to renew certBlue ou tout ce qui améliore notre posture[curl summer of bliss
daniel.haxx.se](https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/)
Divers ou parce que j’ai aucune idée où les placerAMD FTWUsers cry foul after AMD stripped memory crypto from its consumer CPUsAMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July — TSME is coming back after ‘valuable community feedback’CabalHow the Peter Thiel-Linked Dialog Club Secretly Ranks Its MembersLeak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ SocietyCollaborateurs
Nicolas-Loïc FortinCrédits
Montage par Intrasecure incLocaux réels par YUL