Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
The August 27 Windows 11 update is altering cursor customizations and causing false detections in Windows Defender. For MSPs and sysadmins this may mean more helpdesk tickets and the need to validate security alerts; monitor update rollouts and endpoint alerts closely.
Five Venezuelan nationals admitted attempting to use malware to make ATMs dispense cash in a series of jackpotting incidents. The cases underline how malware and remote-access weaknesses threaten cash-dispensing devices and financial infrastructure, highlighting the need for patching, network segmentation and monitoring.
Two zero-day vulnerabilities in PaperCut NG and MF were patched last week. Exploits tied to these flaws have been used to steal data; server admins should apply patches immediately and review access logs and outbound data transfers.
Attacks against healthcare targets have put pacemakers and records for millions of patients at risk. McKesson has confirmed a breach and the actor ShinyHunters is demanding $55.2M. MSPs should reassess medical device segmentation, monitoring, backups and incident response for client environments.
Operators linked to DPRK have extended a recruitment-based insider fraud beyond IT into sales, marketing and medical positions. For MSPs and sysadmins this increases insider risk to customer data and service integrity, so review hiring practices, internal access and monitoring.
This week’s stories include routers shipped with remote access enabled, social-engineering tricks that turn users into installers, and trusted systems collecting traffic and credentials then erasing traces. Misbehaving AI agents, legacy bugs chaining into attacks, and weak default settings raise operational risk for MSPs and sysadmins.
Threat actor Silver Fox is distributing the ValleyRAT backdoor concealed inside a signed Chinese QN Wallpaper adware. The malware runs under a trusted process to evade detection when users add such apps to antivirus exclusions. Kaspersky reported the activity; MSPs and admins should audit AV exclusions, verify signatures and monitor process behavior.
Actors linked to Aurora (Aur0ra) used SpaceX's Cursor coding assistant to breach at least 10 targets, according to examinations of the group's exposed infrastructure by Gambit Security and CloudSEK. The case shows AI-powered developer tools can be abused in intrusions. MSPs and sysadmins should secure exposed assets and monitor tooling access.
Anthropic released Compliance API endpoints to surface Claude Code’s local file access, shell command activity and use of developer machine credentials. The APIs improve visibility for security teams, but logs alone don’t prove whether agent actions are authorized — reinforcing the need for identity governance and local access controls.
The Cronos blockchain resumed activity after a price-manipulation attack on the Tectonic lending platform let an attacker borrow roughly $74 million. The incident highlights risks for node operators, custodial services and MSPs managing clients' exposure to DeFi, emphasizing the need for monitoring, oracle integrity checks and incident response plans. Review alerts, backups and customer communication.
A new ClickFix variant called TerminalFix uses fake Cloudflare verification prompts on compromised sites to trick users into running PowerShell in Windows Terminal. Attackers then establish reverse tunnels for remote access; MSPs and admins should monitor PowerShell activity, watch for unusual outbound tunnels, and inspect affected web servers.
The China-linked Fire Ant actor expanded its campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS authentication servers and Linux management hosts, aiming to steal credentials and disrupt security logging. MSPs should isolate management planes, rotate credentials, audit IOS XR/TACACS configurations and verify log integrity.
Cloudflare's Adaptive Intelligence engine learns from meta-signals in live traffic and automatically generates disposable rules. By increasing the operational cost for attackers who rely on cheap proxies and static detections, it aims to make automated bot campaigns uneconomical. For MSPs and sysadmins this can cut unwanted bot traffic, reduce resource use and lower incident handling overhead.
Two Nigerian suspects were extradited to the United States and charged in connection with sextortion schemes linked to the deaths of two minors in Mississippi and North Carolina. The case underscores the need for MSPs and sysadmins to prioritize account protection, user awareness, and monitoring for extortion attempts.
Microsoft told customers that notifications reporting Defender Antivirus as disabled can appear after a recent Defender update and advised ignoring them. For MSPs and sysadmins, such false alerts can lead to unnecessary incident work and alert fatigue; verify protection status in management consoles and check Microsoft's update guidance.
Microsoft reports a ClickFix variant named TerminalFix that tricks users with fake Cloudflare CAPTCHAs into running malicious commands in Windows Terminal or PowerShell, enabling a reverse-tunnel backdoor. For admins this raises remote-access and persistence risks; avoid pasted commands, enforce endpoint controls and monitor terminal activity.
FulcrumSec says it exfiltrated 86 GB from Manchester Airports Group; BleepingComputer verified one traveler's record. Shared samples contain customer, booking and travel details beyond MAG's initial disclosure. MSPs and sysadmins should review third-party access, notification obligations and affected databases.
A recent poll finds about two-thirds of people in the UK would not trust current or future governments with access to their encrypted private chats. For MSPs and sysadmins this highlights stronger customer expectations around end-to-end encryption, handling legal data requests and opposition to backdoors.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.