🏖️🐻 Les Logiciels Libres de l'été, jour 5
Pangolin : une solution Open Source de reverse proxy intelligent conçue pour exposer et sécuriser vos applications.
Ventoy 1.1.16 is out now to fix a boot issue with old UEFI version firmware when Secure Boot is disabled, the latest Kicksecure boot issue, and an issue causing the VTOY_WIN_UEFI_RES_LOCK option to reset when entering VentoyPlugson https://t.co/0Xp9tS2qX3
#OpenSource#Linux
25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched
Source: https://t.co/U1eqeAcK9G
A critical security flaw lurking in curl for over 25 years has been patched, as part of a record-breaking security release that fixed 18 CVEs, the most ever issued in a single curl version.
The vulnerability, CVE-2026-8932, was first shipped in curl version 7.7 on March 22, 2001, making it the oldest curl security issue ever reported.
curl is not just a command-line tool; it is foundational infrastructure. Running on more than 30 billion devices, it powers data transfers across operating systems, containers, CI/CD pipelines, package managers, SDKs, and automotive systems.
The wave of discoveries began on May 11, 2026, when curl founder and lead developer Daniel Stenberg announced that Anthropic's Mythos AI model had identified a single CVE in curl.
#cybersecuritynews
⚠️⚠️ CVE-2026-20896 (CVSS 9.8): Gitea Docker images default REVERSE_PROXY_TRUSTED_PROXIES=* — with reverse-proxy auth on, any IP can impersonate any user via X-WEBAUTH-USER.
🔗FOFA Link: https://t.co/w2rhVF9HFa
🎯244.5K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="Gitea"
🔖Refer: https://t.co/64ZP4hKcuj
#OSINT #FOFA #CyberSecurity #Vulnerability
PixelSmash – Critical FFmpeg Vulnerability Turns Media Files into Weapons
A critical vulnerability in FFmpeg's MagicYUV decoder leads to remote code execution via a crafted media file
https://t.co/2Wud51mqoK
PostgreSQL 19 is getting graph queries.
With SQL/PGQ, you can query relationships directly in SQL:
→ social networks
→ recommendations
→ fraud detection
→ dependency graphs
Postgres is not just a relational database anymore.
It’s becoming the database for everything.
https://t.co/glzueH8NYf
🔴🚨 France Travail : plus d'un million de personnes potentiellement concernées par une fuite chez AKAOLIFE, éditeur de logiciels RH
Encore des données potentiellement sensibles de Français qui se retrouvent dans la nature.
Les cybercriminels affirment également détenir plus de 14 millions de lignes de données ainsi que près de 60 Go d'archives SQL, issues de plusieurs applications utilisées dans l'écosystème de France Travail.
Les cybercriminels à l'origine de la publication revendiquent notamment la possession de :
👉 966 816 dossiers RH ;
👉 1 003 047 dossiers de mobilité professionnelle ;
👉 38 138 dossiers liés au suivi de santé au travail ;
👉 3 747 dossiers relatifs à des situations de handicap ;
👉 Près de 60 Go de sauvegardes SQL réparties sur 39 bases de données ;
👉 Plus de 10 000 fichiers sources applicatifs.
🚨🇫🇷 https://t.co/E9zh32r4fS dataset allegedly leaked
https://t.co/E9zh32r4fS is the official website of France’s Ordre National des Pédicures-Podologues, the regulatory body overseeing the podiatry profession.
A forum user claims to have leaked an https://t.co/E9zh32r4fS dataset containing 8,048 records, allegedly from June 2026.
Alleged exposed data includes:
• Names
• Gender
• Addresses
• Postal codes
• Cities
• RPPS identifiers
• Detail IDs / URLs
• Telephone tokens
• Search city fields
Details:
• Target: https://t.co/E9zh32r4fS
• Country: France
• Sector: Healthcare / Professional regulator
• Claimed volume: 8,048 records
• Relevance: June 2026
Claim is unverified. Impacted professionals should monitor for phishing, impersonation, and misuse of exposed directory or contact-related data.
🧵1/6
REDasm Disassembler 4.0 BETA1 is available for download.
Version 4 is a complete redesign/rewrite with a brand new engine written in plain C.
- Source Code: https://t.co/rj7lHXiIdY
- Download: https://t.co/RS4giMPiwQ
#reverseengineering#binaryanalysis#opensource
Free open-source Linux GUI to configure gaming mice, from DPI and profiles to LED colors and button mappings, with multiple profiles. Powered by libratbag/ratbagd