Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Anthropic reports that infostealer malware on some users' PCs has exfiltrated active Claude session tokens. Attackers can use those sessions to access accounts and consume usage; admins should invalidate sessions, scan endpoints, reset credentials and review account activity and billing.
Several Chrome Web Store extensions for Google Chrome and Microsoft Edge delivered a modular malware framework that targeted cryptocurrency holdings, sensitive information and browser history, and also injected ClickFix lures. For MSPs and sysadmins this highlights the need to tighten extension vetting, monitor client browsers and block suspicious add-ons.
Wordfence and Patchstack disclosed several critical vulnerabilities affecting WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP that may enable authentication bypass, account takeover and arbitrary code execution. CVE-2026-76581 (CVSS 9.8) is among the high-severity issues; apply patches immediately and scan managed sites for compromise.
A startup secured $7M to develop Spike, a portable drone-interception system that can fit in a backpack or be mounted on vehicles. MSPs and sysadmins should evaluate site protection use cases, integration with security operations, and potential radio/operational impacts on managed infrastructure.
Brave 1.94 introduces 'Email Aliases', allowing users to create disposable email addresses for service registrations. For MSPs and sysadmins this improves user privacy but may complicate email deliverability, authentication, logging and support/account recovery workflows.
Microsoft Threat Intelligence says the TerminalFix ClickFix campaign tricks users with fake CAPTCHA prompts, leverages DLL sideloading in a multistage intrusion, and ultimately sets up a reverse tunnel. For admins this enables remote persistence and covert data tunneling; Microsoft provides detection and hunting guidance.
Microsoft Threat Intelligence reports the campaign tracked as TerminalFix tricks users with fake CAPTCHAs, uses DLL sideloading to load malicious components, then establishes a reverse tunnel for remote access. This enables stealthy, persistent access to servers and customer environments; Microsoft published detection and hunting guidance.
Berlin's state government said it will not pay extortionists after a breach of its state administrative network in August. Forensics uncovered additional data exfiltration affecting the senate department responsible for mobility, transport, climate and environment. MSPs and admins should review access logs, backups and watch for indicators of data leakage in client environments.
Cosmos Labs reported that a critical balance-handling bug in the shared Cosmos EVM module was exploited from August 20–25, 2026 to siphon funds from six blockchains. The issue is tracked as GHSA-7g4w-cg88-2cq2 and no CVE, weakness classification or CVSS score was published; operators should verify affected nodes, apply vendor patches, monitor transactions for anomalies and review key security.
Two chained vulnerabilities in PaperCut NG and MF could allow unauthenticated attackers to run Java code by tampering with the trusted configuration. The vendor released an emergency patch and added hardening. Administrators should deploy the update promptly and restrict access to PaperCut configuration and print services.
Android 17 adds Encrypted Client Hello (ECH) across the OS to stop network operators from seeing which websites users access. Google also announced additional network protections to address cellular weaknesses and bolster home-network privacy. MSPs and admins should expect reduced visibility for network-based filtering and TLS inspection and plan alternative endpoint or logging controls.
CISA added the critical ownCloud flaw CVE-2023-49105 (CVSS 9.8) to its KEV list after a Chinese-speaking actor exploited it to exfiltrate records from a Philippine nuclear research body. MSPs and sysadmins running ownCloud should apply patches immediately, review logs and indicators for compromise, and tighten access controls.
Researchers identified 18 Google Chrome and 1 Microsoft Edge extensions published over the past six months that include components able to exfiltrate browser wallet keys and drain crypto funds. Similar code and tactics point to an organized campaign that may remain active; sysadmins and MSPs should tighten extension policies, use allowlists and block suspicious add-ons.
McKesson reported unauthorized access to third-party applications and that the ShinyHunters group claims to have taken 284 million patient records. Providers and sysadmins should urgently review third-party integrations, access rights, credentials, logging/monitoring, and have incident response and notification procedures ready.
Researcher Olivier Laflamme disclosed two separate root RCE chains affecting the Unitree G1 EDU. Tracked as CVE-2026-76639 and CVE-2026-76640, one route leverages BLE to reach the robot's Locomotion PC while the other abuses chat_go and bashrunner via a network-adjacent vector. This allows full control and potential lateral movement, so operators and MSPs should prioritize isolation and patching.
A US IT specialist pleaded guilty to leaking state secrets after contacting a foreign government shortly after being assigned to a DIA insider-threat unit. Insider risks from staff with privileged access are critical for MSPs and sysadmins; enforce strong access controls, session logging and separation of duties.
Identity Fabric brings together dispersed identity systems to track how identities act across apps, APIs and infrastructure. As cloud services and automated workloads grow, runtime visibility and centralized control become essential; without them unmanaged service accounts and privilege misuse become bigger risks.
ServiceNow released fixes for four vulnerabilities affecting the ServiceNow AI Platform; three are rated CVSS 10.0 and, in certain scenarios, can be exploited by unauthenticated actors to execute code or SQL. The vendor applied updates to hosted tenants and provided patches to partners and self‑managed customers, so unpatched self‑hosted deployments remain exposed.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.