🚀 The Gatherer - Veille

Reset (24H)

The Test That Slept and the Test That Never Woke Up

Dev.to 📅 2026-07-30T08:24:37Z ✨ Validé par l'IA

My retry tests took seven seconds each. Not because they did seven seconds of work — because they did...

Object pooling vs instantiate in Godot 4 — when it actually matters

Dev.to 📅 2026-07-31T03:35:02Z ✨ Validé par l'IA

A practical Godot 4 comparison of object pooling and plain instantiate() — what each really costs, the frame-time numbers that decide it, and a small pool you can paste into a bullet-heaven or wave-based game.

Which CLAUDE.md Files Claude Code Actually Loads (and in What Order)

Dev.to 📅 2026-07-31T02:33:16Z ✨ Validé par l'IA

Half of the "Claude Code is ignoring my rules" reports I see have the same root cause: the rule lives...

Mastering Claude Code Configs: `CLAUDE.md` vs `.claude/rules/`

Dev.to 📅 2026-07-31T03:36:07Z ✨ Validé par l'IA

When configuring Claude Code (or Claude-driven AI coding assistants) in your projects, structuring...

Building Scalable APIs with Go: A Startup's Guide to Not Overengineering

Dev.to 📅 2026-07-30T19:44:41Z ✨ Validé par l'IA

Every startup engineering conversation eventually arrives at: "But what if we need to scale?" Here's...

Why AI Agents Lose Their Memory And How MemoFS Solves It

Dev.to 📅 2026-07-30T18:50:09Z ✨ Validé par l'IA

Whether you are using off-the-shelf AI coding tools like Claude Code and Cursor or building custom...

Building a C++ HTTP Server from Scratch (Part 1): Setting Up TCP Sockets

Dev.to 📅 2026-07-30T22:13:40Z ✨ Validé par l'IA

Introduction In this series I will be going through how to build an HTTP Server from...

RevAPK: Reverse engineer Android apps

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

submitted by /u/cronocr [link] [comments]

CVE-2026-62323 Cloudreve WOPI ViewerSessionValidation improper authentication

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A security vulnerability has been detected in Cloudreve up to 4.16.x. This vulnerability is listed as CVE-2026-62323. Upgrading the affected component is recommended.

CVE-2026-63220 | CodeIgniter up to 4.7.3 isSecure information disclosure

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A vulnerability marked as problematic has been reported in CodeIgniter up to 4.7.3. This affects the function IncomingRequest::isSecure. This manipulation causes information disclosure. This vulnerability is tracked as CVE-2026-63220. The attack is possible to be carried out remotely. No exploit ex...

CVE-2026-63220

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as s...

CVE-2026-55497

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocat...

CVE-2026-55502

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and appid values, allowing an OAuth token without Admin.Write to modify storage...

CVE-2026-55499

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, e...

CVE-2026-55495

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUTRELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite fi...

CVE-2026-55496

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or ...

CVE-2026-43833

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Successful exploitation of the vulnerability could allow an authenticated attacker to exploit a stack-based buffer overflow in the upload functionality to conduct code execution...

CVE-2026-43830

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

Successful exploitation of the command injection vulnerability could allow an attacker to execute arbitrary commands during the firmware upgrade file verification process...

CVE-2026-43830 Advantech ADAM-3600 EdgeLink command injection

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A security flaw has been discovered in Advantech ADAM-3600 EdgeLink. This vulnerability is identified as CVE-2026-43830. The affected component should be upgraded.

CVE-2026-43833 Advantech ADAM-3600 EdgeLink Upload Functionality stack-based overflow

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A vulnerability was identified in Advantech ADAM-3600 EdgeLink. This vulnerability is referenced as CVE-2026-43833. You should upgrade the affected component.

CVE-2026-55502 Cloudreve OAuth Signin signin privileges management

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A vulnerability was determined in Cloudreve up to 4.16.x. The identification of this vulnerability is CVE-2026-55502. It is advisable to upgrade the affected component.

CVE-2026-55496 Cloudreve User Search search SearchActive information disclosure

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A vulnerability was found in Cloudreve up to 4.16.x. This vulnerability was named CVE-2026-55496. Upgrading the affected component is advised.

CVE-2026-55495 Cloudreve WOPI PUT_RELATIVE path traversal

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A vulnerability has been found in Cloudreve up to 4.16.x. This vulnerability is uniquely identified as CVE-2026-55495. It is recommended to upgrade the affected component.

CVE-2026-43832 Advantech ADAM-3600 EdgeLink Cookie Parsing buffer overflow

CurrentsAPI 📅 0001-01-01T00:00:00Z ✨ Validé par l'IA

A flaw has been found in Advantech ADAM-3600 EdgeLink. This vulnerability is handled as CVE-2026-43832. Upgrading the affected component is recommended.

Google says AI helped Chrome fix 1,072 security bugs in two releases

GNews 📅 2026-07-30T17:00:00Z ✨ Validé par l'IA

Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI.

Google is rebuilding Chrome security using AI to catch hidden flaws

GNews 📅 2026-07-30T17:00:00Z ✨ Validé par l'IA

Google Chrome is leveraging AI and dynamic patching to discover, triage, and fix security flaws continuously in the background.

Google wants to update Chrome without a full browser restart

GNews 📅 2026-07-30T17:00:00Z ✨ Validé par l'IA

Google today is out with a lengthy post describing the role of AI and LLMs in Chrome security...

Google Tests Doubling Chrome's Security Patch Cadence to Outpace Hackers

GNews 📅 2026-07-30T17:00:00Z ✨ Validé par l'IA

The company is also pioneering a way to update the Chrome browser without requiring a restart.

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

GNews 📅 2026-07-30T17:00:00Z ✨ Validé par l'IA

The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.

Valve has released the CAD design files for the Steam Machine's exterior, leaving us asking: how long before someone makes a GabeCube skin? - Eurogamer.net

NewsAPI 📅 2026-07-29T15:45:38Z ✨ Validé par l'IA

The release, which has been done under a Creative Commons licence, follows Valve's CAD files for the new Steam Controller.