Actu - 7 juin 2026
07 juin 2026
Parce que... c'est l'épisode 0x306!
Parce que… c’est l’épisode 0x306!
Shameless plug
- 24 et 25 juin 2026 - Troopers
- 26 et 27 juin 2026 - leHACK
- 30 juin au 2 juillet 2026 - Pass the SALT
- 19 septembre 2026 - Bsides Montréal
- 20 au 26 septembre 2026 - BruCON
- 13 novembre 2026 - DEATHCon
- 16 au 19 novembre - European Cyber Week
- 1 au 3 décembre 2026 - Forum INCYBER - Canada 2026
- 24 et 25 février 2027 - SéQCure 2027
Notes
- IA ou Ghost in the shell
- Mythos
- Anthropic invites EU to access Mythos hacking tech
- Anthropic scales Claude Mythos to critical infrastructure in 15+ countries
- Anthropic Expands Project Glasswing Claude Mythos Preview to 150 New Organizations
- Kevin Beaumont: “Mythos is not great btw. Runni…” - Cyberplace
- Free AI model powers self-spreading worm in enterprise test network
- Instapassword
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
- Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts
- Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
- Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers
- Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
- Kevin Beaumont: “How people hacked Meta account…” - Cyberplace
- Injecte moi ça
- Irresponsable
- AI Agents Get Their Own Directory Built Atop DNS
- Remove all LLM generated commits before people get hurt by this nonsense. · Issue #934 · RsyncProject/rsync
- Amazon Shuts Down Internal AI Leaderboard After Employees Cheated
- Open source project contains hidden instruction for “AI” agents: delete my code
- DOD wants to integrate cyber in all operations, and integrate security into AI
- Trump plan to test AI models has a problem—US security teams were gutted by DOGE
- Kevin Beaumont: “xAI have asked a court to stri…” - Cyberplace
- Commvault says it’s time to rethink resiliency as AI crooks leave victims in a ‘dark, dead’ state
- Attackers Use AI to Automate EDR Evasion Testing
- Pluralistic: Delusion as a service (04 Jun 2026) – Pluralistic: Daily links from Cory Doctorow
- These LLMs are the best at resisting Russian propaganda
- RAG Security and Privacy: Formalizing the Threat Model and Attack Surface
- From Attack Simulation to SIEM Rule: Deterministic Detection-as-Code Synthesis with Probe-Level Traceability
- Will the Agent Recuse Itself? Measuring LLM-Agent Compliance with In-Band Access-Deny Signals
- Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks
- Mythos
- La guerre, la guerre, c’est pas une raison pour se faire mal!
- Souveraineté ou vive le numérique libre!
- Privacy ou cachez ces informations que je ne saurais voir
- The Pentagon Finally Admits That Location Data Is a Battlefield Problem
- Age verification for social media – the beginning of the end for a free internet?
- Privacy isn’t dead: it’s just that tech companies have made it inconvenient
- Amazon-owned Ring should pay Americans for scanning their faces, lawsuit says
- Elon Musk tries again to escape FTC audits of X data handling
- I am the law
- Red ou tout ce qui est brisé
- Cachez ce fiasco que j’ai fait
- Microsoft’s Zero-Day Legal Threats Spark Backlash
- Microsoft Clarifies It Won’t Sue Security Researchers Amid Nightmare-Eclipse Controversy
- Microsoft reaches for olive branch after public dustup with 0-day researcher
- Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
- Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
- Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher
- Just LOL BIN BAS
- Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage
- Dozens of Red Hat packages backdoored through its official NPM channel
- Inspector general finds NIST mistakes have made vulnerability database ineffective
- Sur le serveur X.Org, neuf nouvelles failles de sécurité dont huit débusquées par une IA
- HTTP/2 Bomb : une mini-requête suffit pour faire tomber nginx, Apache ou IIS
- Cachez ce fiasco que j’ai fait
- Blue ou tout ce qui améliore notre posture - An Analysis of GrapheneOS’s Server Infrastructure - Android phones will soon be able to detect spoofed calls and impersonation scams - Kernel-Level Ground Truth: Why eBPF is Replacing User-Space Agents for Security Observability - Dashlane explains how attackers managed to download encrypted password vaults - Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats
- Divers ou parce que j’ai aucune idée où les placer - The Infosec Phrasebook - United Airlines Flight To Spain Pulls U-Turn Over Bluetooth Device Name - Cyber Insurance Rates Are Dropping, but Exclusions Widen - DNS is for people - not for IT infrastructure - The US Military Quietly Turned GPS Into a Global ‘Numbers Station,’ Evidence Suggests - I led the 2014 U.S. CDC Ebola response. An action plan is needed now - Teen social media ban risks strengthening Big Tech dominance: Bluesky
Collaborateurs
Crédits
- Montage par Intrasecure inc
- Locaux réels par Intrasecure inc
Tags: blue, ia, loi, privacy, prp, red, retex, souverainete, war
Tweet












