Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

Google fixes privilege escalation bug in Pixel Cellular Modem (CVE-2026-58704)

Google patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem tracked as CVE-2026-58704. NIST records indicate the issue stems from a logic flaw and there are signs of limited, targeted exploitation. MSPs and sysadmins should ensure employee and customer Pixel devices are updated quickly to reduce risk.

16 Sep 2026 thehackernews.com
Security The Hacker News

Threat intelligence alone doesn't close the exploitation gap

Leaked credentials or published vulnerability notices can be turned into attacks before defenders finish triage; attackers are shortening the time from exposure to breach using AI-assisted techniques. For MSPs and admins this means prioritizing faster patching, automated risk scoring and enforcing MFA to reduce the exposure window.

16 Sep 2026 thehackernews.com
Security The Hacker News

Privilege escalation in Acronis Backup cPanel/WHM plugin (CVE-2026-87886)

Acronis reported that CVE-2026-87886 (CVSS 7.8), a local privilege escalation rooted in insecure file permissions in the Acronis Backup plugin for cPanel & WHM on Linux, is being exploited in targeted attacks. Administrators should apply updates, check file permissions and limit access, and review logs for suspicious activity.

16 Sep 2026 thehackernews.com
Security The Register

Spain reports first AI-assisted cyber attack; data protection bodies warn

Spain has reported its first incident described as AI-assisted, and data protection authorities are calling for an urgent re-evaluation of current data security approaches. MSPs and sysadmins should prioritize updating access controls, backups, monitoring and incident response, and strengthen defences against AI-enabled social engineering.

16 Sep 2026 theregister.com
Security BleepingComputer

Webinar: What to do in the first hours after a Google Workspace breach

Actions taken in the first hours after a Google Workspace breach often determine how much damage occurs and how quickly services recover. This webinar reviews real incidents to show which early response choices limit impact and which worsen outcomes, covering triage, containment, log preservation and stakeholder communication.

16 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Critical ConnectWise ScreenConnect flaw being exploited in the wild

CISA reports a critical-severity vulnerability in ConnectWise ScreenConnect is now being exploited in real attacks. Servers and customer environments using the remote-management software may be at risk. Administrators should apply patches immediately, tighten access controls, and monitor logs closely.

16 Sep 2026 bleepingcomputer.com
Security The Hacker News

KREMLIN steals credentials and session tokens via Chrome and Edge extensions

Elastic Security Labs, tracking the activity as REF9334, uncovered a Brazil-focused banking malware campaign active since at least May 2025 that uses lures impersonating multiple Brazilian banks. Malicious extensions deployed to Chrome and Edge harvest credentials and session tokens, so MSPs and sysadmins should review browser extension policies, token protection and customer access controls.

16 Sep 2026 thehackernews.com
Security The Register

Apple issues record number of security fixes

Apple released an unusually large batch of security fixes affecting multiple products. MSPs and sysadmins should prioritize quick testing, staged rollouts, compatibility checks and reboot planning, and follow Apple's guidance when deploying updates.

15 Sep 2026 theregister.com
Security The Hacker News

Windows malware controlled via Telegram used by Iranian intelligence for surveillance

US, UK and Dutch cyber teams documented a Windows malware linked to Iran's intelligence service. The malware takes commands over Telegram and can exfiltrate emails and chats, capture screenshots and record via the microphone; this creates data-leak and privacy risks for hosted customers and endpoints.

15 Sep 2026 thehackernews.com
Security The Hacker News

BambooToken malware targets Windows and Linux via MQTT

Researchers reported a cross-platform malware campaign called BambooToken that leverages MQTT for command-and-control. First seen in Feb 2023 and observed against organizations in Asia and South America, it underlines the need for MSPs and admins to monitor MQTT endpoints, segment networks and tune detections.

15 Sep 2026 thehackernews.com
Security BleepingComputer

Active LPE in Acronis backup plugin for cPanel/WHM/Plesk

Acronis reported a high-severity Linux local privilege escalation flaw in its backup plugin for cPanel/WHM and Plesk that is being exploited in the wild. Systems where attackers can gain local access are at risk of privilege takeover; MSPs and admins should update the plugin, tighten access controls and check for suspicious activity.

15 Sep 2026 bleepingcomputer.com
Security The Hacker News

Sysdig: Attacker reached SSH bastion from Marimo RCE in 8 seconds

Sysdig observed a threat actor exploit a Marimo notebook RCE and reach an SSH bastion only eight seconds after initial access. The finding underscores the need for rapid patching, stricter bastion/notebook controls, tight access limits and real-time monitoring to detect fast lateral movement.

15 Sep 2026 thehackernews.com
Security The Hacker News

Test attack chains, not just individual techniques

Testing only individual techniques can miss multi-stage attacks. MSPs and sysadmins should validate EDR, SIEM and response workflows with end-to-end attack scenarios to uncover detection gaps and automation failures.

15 Sep 2026 thehackernews.com
Security The Hacker News

Mass-scanning campaign exploiting Vite flaw targets cloud credentials

Per F5 Labs, an automated campaign scanning publicly accessible Vite dev servers aims to harvest AWS and Microsoft Azure credentials, configurations, and infrastructure state files. For MSPs and sysadmins this is critical: secure dev environments, remove secrets from development hosts, restrict access and increase monitoring.

15 Sep 2026 thehackernews.com
Security BleepingComputer

Backdoor in Admin Menu Editor Pro affects ~1,500 WordPress sites

Malicious builds of the Admin Menu Editor Pro plugin were pushed after the maintainer's site was compromised, distributing to customers and installing a hidden administrator account on roughly 1,500 WordPress sites. MSPs and sysadmins should audit plugin versions, remove unknown users, and rotate credentials and keys.

15 Sep 2026 bleepingcomputer.com
Security Cloudflare

Finer access controls and restricted roles for Cloudflare Workers

Cloudflare now supports scoping access at the individual Worker level and assigning narrower Developer Platform roles. Team members, CI tokens and automation agents can be limited to only the permissions needed for debugging, deploying and monitoring, enforcing least-privilege. This helps lower misconfiguration and operational risk.

15 Sep 2026 blog.cloudflare.com
Security BleepingComputer

CenterPoint Energy confirms theft of some customer data

CenterPoint Energy acknowledged a breach after an attacker allegedly leaked data taken from the utility, affecting some customer records. For MSPs and sysadmins this elevates risks like phishing, credential compromise and regulatory notifications; review access logs, permissions and customer communication plans.

15 Sep 2026 bleepingcomputer.com
Security BleepingComputer

CISA: Ransomware gangs exploiting critical VMware vCenter RCE

The U.S. CISA warned that ransomware groups are now exploiting a critical VMware vCenter remote code execution flaw patched in July. Service providers and administrators should confirm patches, review access logs and increase monitoring on management servers for suspicious activity.

15 Sep 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.