Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Google patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem tracked as CVE-2026-58704. NIST records indicate the issue stems from a logic flaw and there are signs of limited, targeted exploitation. MSPs and sysadmins should ensure employee and customer Pixel devices are updated quickly to reduce risk.
go to sourceLeaked credentials or published vulnerability notices can be turned into attacks before defenders finish triage; attackers are shortening the time from exposure to breach using AI-assisted techniques. For MSPs and admins this means prioritizing faster patching, automated risk scoring and enforcing MFA to reduce the exposure window.
Acronis reported that CVE-2026-87886 (CVSS 7.8), a local privilege escalation rooted in insecure file permissions in the Acronis Backup plugin for cPanel & WHM on Linux, is being exploited in targeted attacks. Administrators should apply updates, check file permissions and limit access, and review logs for suspicious activity.
AWS says Iranian strikes overran local redundancy in Bahrain and made one UAE Availability Zone inaccessible. The company warns some resources cannot be recovered; MSPs and sysadmins should promptly review backups, cross-region replication and disaster recovery arrangements.
Spain has reported its first incident described as AI-assisted, and data protection authorities are calling for an urgent re-evaluation of current data security approaches. MSPs and sysadmins should prioritize updating access controls, backups, monitoring and incident response, and strengthen defences against AI-enabled social engineering.
Logitech has released the MX Keypad, a compact shortcut-focused keypad. For sysadmins and MSPs it can speed access to frequent commands, saving time during routine operations and remote management. It may simplify desktop workflows and automation tasks.
Microsoft is investigating a known issue that causes Copilot and Copilot Chat controls to disappear in Classic Outlook for some Windows users. For MSPs and sysadmins this can interrupt customers' access to Copilot features; monitor Microsoft advisories, inform affected users, and consider alternative clients or web access until a fix is released.
Actions taken in the first hours after a Google Workspace breach often determine how much damage occurs and how quickly services recover. This webinar reviews real incidents to show which early response choices limit impact and which worsen outcomes, covering triage, containment, log preservation and stakeholder communication.
CISA reports a critical-severity vulnerability in ConnectWise ScreenConnect is now being exploited in real attacks. Servers and customer environments using the remote-management software may be at risk. Administrators should apply patches immediately, tighten access controls, and monitor logs closely.
Elastic Security Labs, tracking the activity as REF9334, uncovered a Brazil-focused banking malware campaign active since at least May 2025 that uses lures impersonating multiple Brazilian banks. Malicious extensions deployed to Chrome and Edge harvest credentials and session tokens, so MSPs and sysadmins should review browser extension policies, token protection and customer access controls.
Apple released an unusually large batch of security fixes affecting multiple products. MSPs and sysadmins should prioritize quick testing, staged rollouts, compatibility checks and reboot planning, and follow Apple's guidance when deploying updates.
Cornelis (spun out of Intel) and Delos Data are developing open networking approaches to link GPU clusters across racks and lessen dependence on NVLink. For MSPs and sysadmins this may require rethinking infrastructure design, compatibility and cost trade-offs before adopting new hardware or topologies.
AWS introduced an inbox-like feature to gather reports and requests from AI agents. Pizza Bot operates locally and provides an email-style interface for interacting with agents; operators should reassess data governance, integration and filtering for customer environments.
US, UK and Dutch cyber teams documented a Windows malware linked to Iran's intelligence service. The malware takes commands over Telegram and can exfiltrate emails and chats, capture screenshots and record via the microphone; this creates data-leak and privacy risks for hosted customers and endpoints.
Researchers reported a cross-platform malware campaign called BambooToken that leverages MQTT for command-and-control. First seen in Feb 2023 and observed against organizations in Asia and South America, it underlines the need for MSPs and admins to monitor MQTT endpoints, segment networks and tune detections.
Acronis reported a high-severity Linux local privilege escalation flaw in its backup plugin for cPanel/WHM and Plesk that is being exploited in the wild. Systems where attackers can gain local access are at risk of privilege takeover; MSPs and admins should update the plugin, tighten access controls and check for suspicious activity.
Sysdig observed a threat actor exploit a Marimo notebook RCE and reach an SSH bastion only eight seconds after initial access. The finding underscores the need for rapid patching, stricter bastion/notebook controls, tight access limits and real-time monitoring to detect fast lateral movement.
Testing only individual techniques can miss multi-stage attacks. MSPs and sysadmins should validate EDR, SIEM and response workflows with end-to-end attack scenarios to uncover detection gaps and automation failures.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.