Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security Microsoft

ASCII smuggling: Invisible Unicode used to bypass phishing filters

Invisible Unicode characters once used to hide instructions from AI models are now being applied to break up words inside emails so phishing and spam filters miss them. MSPs and admins should normalize and strip Unicode, add detection beyond simple signatures, and improve monitoring and user awareness to reduce successful evasions.

03 Sep 2026 microsoft.com
Security Microsoft

ASCII smuggling: using invisible characters to bypass email filters

Microsoft reports that the ASCII smuggling method—known from AI prompt injection—has been repurposed to evade email defenses using invisible Unicode chars. Attackers insert hidden characters inside words to disrupt content scanning and signature detection, so mail flow rules, spam/antiphishing controls and detection/incident procedures should be reviewed.

03 Sep 2026 microsoft.com
Security BleepingComputer

HPE patches ArubaOS-CX remote code execution flaw

HPE released a patch for a critical vulnerability in the ArubaOS-CX network OS that could enable remote code execution. MSPs and sysadmins should apply the update immediately; if patching isn't possible, restrict management access and monitor network traffic and device logs. Check the vendor advisory for affected versions.

03 Sep 2026 bleepingcomputer.com
Security The Hacker News

NSO Group's Pegasus infected a Serbian student movement member's iPhone

A joint analysis by Citizen Lab and the SHARE Foundation found NSO Group's Pegasus on an iPhone owned by a Serbian student movement member, delivered via an iMessage attack that required no user interaction. Because zero-click compromises can evade typical defenses, MSPs and sysadmins should review mobile device management, patching and monitoring for related indicators.

03 Sep 2026 thehackernews.com
Security The Hacker News

Chaotic Eclipse releases FalconFlank PoC showing privilege escalation in CrowdStrike Falcon

Researcher Chaotic Eclipse published a FalconFlank PoC that abuses the Office macro remediation mechanism in the CrowdStrike Falcon sensor to achieve local privilege escalation. This weakness could allow attackers to leverage endpoint protection to gain higher privileges and move within customer environments; MSPs and admins should monitor sensor updates and settings.

03 Sep 2026 thehackernews.com
Security The Hacker News

CISA adds seven actively exploited flaws to KEV; SonicWall CVE-2026-83548 critical

CISA added seven actively exploited vulnerabilities to its KEV list. A prominent entry is CVE-2026-83548 (CVSS 10.0), an SSRF in SonicWall SMA 1000 that can permit unauthenticated remote actors to install malware or spawn reverse shells. MSPs should prioritize patches and monitor traffic and signs of crypto-mining.

03 Sep 2026 thehackernews.com
Security BleepingComputer

Plex issues urgent update warning for desktop clients and media servers

Plex reported multiple security flaws in its desktop applications and media servers and is urging immediate application of released patches. For MSPs and system admins, unpatched hosts could enable unauthorized access or service disruption, so apply updates promptly and review access logs and permissions.

03 Sep 2026 bleepingcomputer.com
Security The Hacker News

Google, Anthropic and OpenAI announce cyber AI models and access programs

Major AI vendors unveiled cybersecurity-focused models including Google’s Gemini 3.8 Flash Cyber and introduced restricted-access programs for trusted defenders. These releases expand defensive tooling but raise operational questions for MSPs and admins about integration, data handling and vendor controls.

02 Sep 2026 thehackernews.com
Security The Register

Cyber Weapon Index finds Claude Mythos the only model able to execute full cyber kill chain

The Cyber Weapon Index report identified Claude Mythos as the sole examined model capable of carrying out a complete cyber kill chain, while other models handled only parts of an attack. For MSPs and sysadmins this raises urgency: AI-enabled attacks may accelerate, so review detection, access controls, patching and incident response processes.

02 Sep 2026 theregister.com
Security Microsoft

Attackers impersonate IT support via Teams to gain enterprise access

Microsoft observed attackers abusing Microsoft Teams external collaboration to pose as IT support, obtain remote sessions and deploy a Node.js implant to move laterally across networks. Because legitimate collaboration and support tools are used, MSPs and admins should review external sharing controls, remote-support policies and Microsoft Defender detections.

02 Sep 2026 microsoft.com
Security Microsoft

Fake IT support via Teams: remote access and Node.js implant

Microsoft Threat Intelligence found an attack using Microsoft Teams external collaboration to trick victims into remote sessions under the guise of IT support. Attackers install a Node.js-based implant and use legitimate tools to move laterally; Microsoft Defender telemetry and blocking can help detect and stop the activity. Service providers should validate external sessions and monitor Defender alerts.

02 Sep 2026 microsoft.com
Security The Hacker News

Fake installers disable Windows Update and weaken Microsoft Defender

According to Microsoft, an active campaign uses fake download sites that impersonate trusted vendors to deliver malicious installers. Those installers turn off Windows Update and weaken Microsoft Defender settings, causing exposure across many organizations—especially China-based operations and Chinese-speaking users.

02 Sep 2026 thehackernews.com
Security The Hacker News

Malicious .git configs can make Claude, Codex and other AI agents run attacker code

Manifold Security disclosed eight vulnerabilities across seven CLI AI coding agents; four remain unpatched. A malicious repository .git config can cause an agent to run a local command on the developer's machine outside its sandbox and without prompting, using the user's privileges. MSPs and sysadmins should treat untrusted repos cautiously and keep affected tools updated.

02 Sep 2026 thehackernews.com
Security BleepingComputer

Active exploitation of CVE-2026-9586 in Sangoma Switchvox

Attackers are exploiting an unauthenticated SQL injection (CVE-2026-9586) in Sangoma Switchvox to achieve remote code execution and install reverse shells on compromised devices. Administrators should apply vendor fixes, limit exposure with access controls or WAFs, and monitor logs and unusual connections.

02 Sep 2026 bleepingcomputer.com
Security The Hacker News

Two zero-day flaws in SonicWall SMA 1000 — emergency patches released

SonicWall issued security updates for two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. Discovered by William Perry and Adam Babis, one flaw is CVE-2026-83548 (CVSS 10.0) — a pre-auth SSRF — and the issues can be chained for remote compromise; operators should patch immediately.

02 Sep 2026 thehackernews.com
Security BleepingComputer

SQL injection in All-in-One WP Migration/Backup plugin puts millions of sites at risk

An SQL injection flaw in the All-in-One WP Migration and Backup plugin can let unauthenticated attackers execute code remotely and take over websites. MSPs and sysadmins should urgently update or remove the plugin, review logs and backups, and investigate any potential compromises.

02 Sep 2026 bleepingcomputer.com
Security The Hacker News

Unauthenticated RCE chain in GeoNetwork; updates 4.4.12 and 4.2.17 released

Two vulnerabilities in GeoNetwork can be chained to enable remote code execution without authentication; the software is used behind many government geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026 and published details on August 31, 2026. Patch promptly and audit any hosted GeoNetwork instances.

02 Sep 2026 thehackernews.com
Security BleepingComputer

CVE-2026-82329 in JFrog Artifactory allows creation of admin tokens

A critical authentication bypass (CVE-2026-82329) in JFrog Artifactory is being actively exploited to allow attackers to generate tokens with administrative privileges. Administrators should apply the vendor patch immediately, revoke or rotate existing tokens, and review access logs for suspicious activity.

02 Sep 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.