Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft Defender for Office 365 is classifying certain legitimate Google search links as malicious and blocking access. Microsoft is investigating; MSPs and admins should review email/web filters, quarantine logs and whitelists and monitor updates to prevent user impact.
A California grand jury indicted a Russian national accused of infecting about 80,000 freelancers with TVRAT and DarkVNC via phishing. For MSPs and admins this underlines the danger of remote-access trojans: credential theft, covert remote control and data exposure — review email filtering, endpoint detection and enforce MFA.
Law enforcement and private partners executed an operation that seized key components of the Sality peer-to-peer (P2P) botnet and disrupted its distribution network. MSPs and sysadmins should scan and clean affected hosts, monitor network traffic, and apply patches to reduce risk of reinfection.
A joint action disrupted Sality's command infrastructure and routed infected traffic to sinkhole servers. MSPs should scan and remediate infected endpoints, monitor DNS and network logs, and ensure AV and patching are up to date for customers.
CVE-2026-82329 (CVSS 9.8) is being exploited by attackers days after disclosure. The flaw can let attackers bypass authentication to gain admin rights and mint tokens; operators should apply the vendor patch, rotate admin tokens, limit network exposure and monitor logs.
Since 2024 Breeze Comet (formerly UNC5669) has targeted Brazil's banking, retail and e‑commerce payment infrastructures, performing hundreds of fraudulent transfers. GTIG and Mandiant report the actor abuses payment systems and banking software; MSPs and providers should review payment integrations, access controls and monitoring.
Microsoft Defender Experts reported an active campaign using look-alike vendor sites and repackaged installers to distribute malware. The post includes Defender XDR detections, IoCs and practical mitigations — admins should enforce signature/hash checks, web filtering and IoC-based blocking to protect customer environments.
Attackers are distributing malware by posing as trusted software vendors using imitation download sites and rebuilt installer archives. Microsoft Defender Experts details attacker techniques, Defender XDR detections, IOCs and practical mitigations. MSPs and sysadmins should verify download sources and monitor XDR alerts to detect and respond quickly.
A new dark-web marketplace is offering scans of over 153 million U.S. and Canadian driver's licenses. Evidence suggests the images may have been taken from a widely used Louisiana-based identity verification provider, and the FBI's New Orleans field office is investigating. MSPs and sysadmins should reassess identity checks, third-party vendor risk and exposure to KYC bypass or social-engineering fraud.
Researchers found 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese streaming sites to deliver spyware to unpatched iPhones. The injected code facilitates ad-fraud, gambling redirects and aims to steal crypto wallet seeds. MSPs should audit theme dependencies and monitor sites for unexpected scripts.
Microsoft’s DART team runs a workshop aimed at boosting pre-incident readiness and response. The program delivers hands-on techniques and case exercises for detection, monitoring and recovery—practical guidance for MSPs and system administrators protecting customer infrastructure.
A Microsoft DART incident response workshop presents practical techniques and playbooks teams can use before and during incidents. Helpful for sysadmins and MSPs looking to strengthen detection, containment and recovery of customer infrastructure.
Research indicates attackers favour reliable, repeatable techniques instead of one-off sophisticated exploits. Microsoft noted that a common initial access pattern was 'ClickFix'-style social engineering that injects commands into the clipboard and persuades users to paste them into terminals. MSPs should prioritise user training, endpoint restrictions and controls around terminal command execution.
Phishing actors abused the Faronics Deploy management platform to push ScreenConnect remote support software to victim machines and gain administrative access. The misuse of a legitimate endpoint-management tool creates a risk of persistent remote control and data exposure for MSPs and sysadmins. Review access logs, deployments and credentials immediately.
Aesto LLC (Aesto Health) reported a recently discovered breach impacting more than 9.5 million patients. A leak involving health records raises privacy and compliance concerns; MSPs should review access controls, backup strategies, and incident response/notification procedures for customer environments.
Traffic for Softaculous was redirected during a 33-hour BGP hijack. The vendor advised customers to rotate credentials and scan package repositories for malicious packages; MSPs and admins should review BGP announcements, logs and deployed packages for signs of compromise.
ESET disclosed that Russia-aligned UAC-0099 used a technique named GuardBreaker to conceal a malicious prompt inside malware to try and trigger safety filters in AI-assisted analysis tools. For administrators: LLM-based automated analysis can be manipulated by crafted inputs, so review input validation, sandboxing and detection controls.
An unauthenticated remote code execution flaw in Langflow (CVE-2026-0768) is being exploited to exfiltrate OpenAI and AWS keys, tokens and other credentials. Service providers and admins should patch promptly, restrict public access to Langflow instances and consider rotating any potentially exposed keys.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.