Parce que… c’est l’épisode 0x306!
Shameless plug
24 et 25 juin 2026 -
Allemagne -
Troopers
26 et 27 juin 2026 -
Paris, France -
leHACK
30 juin au 2 juillet 2026 -
Lille, France -
Pass the SALT
6 au 9 août 2026 -
Las Vegas, USA -
DEFCON 34
19 septembre 2026 -
Montréal Canada -
Bsides Montréal 2026
22 septembre 2026 -
Belgique -
BE-Cyber
24 au 25 septembre 2026 -
Belgique -
BruCON
1er au 3 octobre 2026 -
Krakow, Pologne -
AligatorCon
13 et 14 novembre 2026 -
Worldwide -
DEATHCon
16 au 19 novembre -
Rennes, France -
European Cyber Week 2026
1 au 3 décembre 2026 -
Ottawa, Canada -
Forum inCYBER Canada
I.A. Café - Enquête au cœur de la recherche sur l’intelligence artificielle
Notes
IA ou Ghost in the shell
Mythos
Anthropic invites EU to access Mythos hacking tech
Anthropic scales Claude Mythos to critical infrastructure in 15+ countries
Anthropic Expands Project Glasswing Claude Mythos Preview to 150 New Organizations
Kevin Beaumont: “Mythos is not great btw. Runni…” - Cyberplace
Free AI model powers self-spreading worm in enterprise test network
Instapassword
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
Kevin Beaumont: “How people hacked Meta account…” - Cyberplace
Injecte moi ça
ChatGPT for Google Sheets Exfiltrates Workbooks
New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS
New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration
Irresponsable
Florida sues OpenAI, Sam Altman after multiple ChatGPT-linked murders
School shooting survivor sues AI gun detection firm after system failed to spot weapon
AI Agents Get Their Own Directory Built Atop DNS
Remove all LLM generated commits before people get hurt by this nonsense. · Issue #934 · RsyncProject/rsync
Amazon Shuts Down Internal AI Leaderboard After Employees Cheated
Open source project contains hidden instruction for “AI” agents: delete my code
DOD wants to integrate cyber in all operations, and integrate security into AI
Trump plan to test AI models has a problem—US security teams were gutted by DOGE
Kevin Beaumont: “xAI have asked a court to stri…” - Cyberplace
Commvault says it’s time to rethink resiliency as AI crooks leave victims in a ‘dark, dead’ state
Attackers Use AI to Automate EDR Evasion Testing
Pluralistic: Delusion as a service (04 Jun 2026) – Pluralistic: Daily links from Cory Doctorow
These LLMs are the best at resisting Russian propaganda
RAG Security and Privacy: Formalizing the Threat Model and Attack Surface
From Attack Simulation to SIEM Rule: Deterministic Detection-as-Code Synthesis with Probe-Level Traceability
Will the Agent Recuse Itself? Measuring LLM-Agent Compliance with In-Band Access-Deny Signals
Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks
La guerre, la guerre, c’est pas une raison pour se faire mal!
Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East
Pentagon raised threat of Israeli spying on U.S. to highest level, sources say
Souveraineté ou vive le numérique libre!
EU plots long game against US digital supremacy
OSI welcomes the European Union’s “Tech Sovereignty” package
Cable lobby warns of chaos if FCC doesn’t relax ban on foreign routers
Privacy ou cachez ces informations que je ne saurais voir
The Pentagon Finally Admits That Location Data Is a Battlefield Problem
Age verification for social media – the beginning of the end for a free internet?
Privacy isn’t dead: it’s just that tech companies have made it inconvenient
Amazon-owned Ring should pay Americans for scanning their faces, lawsuit says
Elon Musk tries again to escape FTC audits of X data handling
I am the law
Policy-Compliant Cloud Storage Systems
GrapheneOS user reported to authorities for using GrapheneOS
Red ou tout ce qui est brisé
Cachez ce fiasco que j’ai fait
Microsoft’s Zero-Day Legal Threats Spark Backlash
Microsoft Clarifies It Won’t Sue Security Researchers Amid Nightmare-Eclipse Controversy
Microsoft reaches for olive branch after public dustup with 0-day researcher
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher
Just LOL BIN BAS
Kevin Beaumont: “Wake up babe, new lolbins and …” - Cyberplace
Microsoft’s Coreutils project brings Linux commands to Windows
Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage
Dozens of Red Hat packages backdoored through its official NPM channel
Inspector general finds NIST mistakes have made vulnerability database ineffective
Sur le serveur X.Org, neuf nouvelles failles de sécurité dont huit débusquées par une IA
HTTP/2 Bomb : une mini-requête suffit pour faire tomber nginx, Apache ou IIS
Blue ou tout ce qui améliore notre posture - An Analysis of GrapheneOS’s Server Infrastructure
- Android phones will soon be able to detect spoofed calls and impersonation scams
- Kernel-Level Ground Truth: Why eBPF is Replacing User-Space Agents for Security Observability
- Dashlane explains how attackers managed to download encrypted password vaults
- Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats
Divers ou parce que j’ai aucune idée où les placer - The Infosec Phrasebook
- United Airlines Flight To Spain Pulls U-Turn Over Bluetooth Device Name
- Cyber Insurance Rates Are Dropping, but Exclusions Widen
- DNS is for people - not for IT infrastructure
- The US Military Quietly Turned GPS Into a Global ‘Numbers Station,’ Evidence Suggests
- I led the 2014 U.S. CDC Ebola response. An action plan is needed now
- Teen social media ban risks strengthening Big Tech dominance: Bluesky
Collaborateurs
Nicolas-Loïc FortinCrédits
Montage par Intrasecure inc
Locaux réels par Intrasecure inc