Mensuel Shaarli

Tous les liens d'un mois sur une page.

June, 2026

Après Tchap et l'ANTS, c'est l'INSEE qui se fait pirater : 12 800 victimes

Un pirate a compromis l'annuaire interne de l'INSEE. Identité et coordonnées professionnelles de 12 800 agents exposées, données sensibles épargnées. La série noire du service public numérique français compte un épisode de plus.

Codex Discovered a Hidden HTTP/2 Bomb - Calif

14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.

LastPass confirms data breach in Klue supply chain attack

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

GreatXML can bypass BitLocker on Windows systems where Defender Offline Scan was used, exposing encrypted drive data.

Surviving the surge of new Linux LPE : Defense in Depth not dead

Surviving the surge of new Linux LPE : Defense in Depth not dead

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk issued security updates for a critical CVSS 9.8 vulnerability in Splunk Enterprise that allows unauthenticated remote code execution.

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk