Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Register

Ukraine unveils pickup-transportable jet-powered counter-drone system

Ukraine revealed a fast, lightweight jet-powered counter-drone platform designed for rapid field deployment and compact enough to be moved in a pickup. MSPs and data centre operators should assess how such tactical systems could affect hosted sites and update airspace monitoring, physical security and incident response procedures.

25 Aug 2026 theregister.com
Security BleepingComputer

Large DDoS attack hits Norway's shared government digital infrastructure

A large DDoS campaign that began on Monday disrupted shared online services used by Norway's public agencies, causing outages across government platforms. For MSPs and sysadmins this highlights the need to review DDoS defenses, capacity planning, failover arrangements and monitoring to reduce customer impact.

25 Aug 2026 bleepingcomputer.com
Security The Hacker News

CVE-2026-21962: Active exploitation affecting Oracle WebLogic and HTTP Server

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities list after evidence of active exploitation. The CVSS 10.0 flaw in Oracle HTTP Server and Oracle WebLogic Server can allow unauthenticated attackers to access critical data over HTTP; apply patches, restrict network exposure and monitor logs urgently.

25 Aug 2026 thehackernews.com
Security The Register

Fake OpenAI Codex ads used to push ClickFix to Macs

Attackers are leveraging sponsored search listings and fake OpenAI Codex ads to trick Mac users into downloading ClickFix malware. This developer-focused lure can bypass casual checks, so endpoint protection, download verification and monitoring ad-related traffic should be prioritized by service providers.

25 Aug 2026 theregister.com
Security BleepingComputer

Over 270 Zimbra servers breached in RCE attacks

Attackers exploited a high-severity Zimbra Collaboration Suite flaw to compromise more than 270 Zimbra instances. MSPs and sysadmins should assume mail servers and credentials may be exposed and perform emergency patching, network isolation and log/incident response to determine scope.

25 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Global operation: 263 suspects identified in 22 countries, 58 arrested

Investigations across 22 countries identified 263 suspects and resulted in 58 arrests, with connections to Africa-based organized crime groups. For MSPs and sysadmins this highlights the need to tighten monitoring, review credentials and validate incident response and detection controls against botnets, ransomware and phishing.

25 Aug 2026 bleepingcomputer.com
Security The Register

Sleepwalker backdoor discovered on Windows

Researchers uncovered a Windows backdoor named Sleepwalker that contains a custom command set of 23 operations. The design and instruction complexity point to a planned, resource-backed actor rather than opportunistic malware. MSPs and sysadmins should prioritize detection signatures, network monitoring and incident response.

24 Aug 2026 theregister.com
Security The Hacker News

Weedhack malware spreads via fake Minecraft clients and search-result manipulation

Researchers found Weedhack being distributed to gamers through fake Minecraft clients and search-result manipulation. McAfee Labs blocked over 6,300 access attempts to malicious sites; infected endpoints can be leveraged to pivot into customer networks or join botnets, so MSPs and sysadmins should monitor gamer-facing downloads.

24 Aug 2026 thehackernews.com
Security The Hacker News

Weekly recap: AI-powered PLC attacks, GitLab incidents and Stripe key leaks

AI-driven tools are making it easier to exploit PLCs and industrial devices, while GitLab incidents and leaked Stripe API keys were also reported. Trusted packages and internet-exposed services are common factors; admins should prioritize secrets management, package provenance checks and network segmentation.

24 Aug 2026 thehackernews.com
Security The Hacker News

WordlistLoader and SynkLoader: Amatera delivery and Windows credential phishing

Gen Digital researchers identified two new malware families, WordlistLoader and SynkLoader. WordlistLoader uses ClearFake campaigns with ClickFix (aka FakeCaptcha) to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer), while SynkLoader focuses on phishing Windows credentials. For MSPs, stolen credentials can enable access resale to ransomware actors and client compromise.

24 Aug 2026 thehackernews.com
Security The Hacker News

AI-generated code and dependencies: control remediation debt

AI-assisted code generation is increasing the number of packages and dependencies faster than security teams can review, causing a backlog of vulnerabilities and patch work. For MSPs and sysadmins, using SCA, SBOMs, automation and risk-based prioritization is essential to keep remediation debt under control.

24 Aug 2026 thehackernews.com
Security The Hacker News

Patch released for critical Keycloak password-reset flaw (CVE-2026-18963)

Red Hat and the Keycloak project issued fixes for a severe vulnerability (CVE-2026-18963, CVSS 9.1) that allows unauthenticated attackers to compromise accounts via the password-reset flow. Administrators and MSPs should update Keycloak immediately, limit public exposure of identity endpoints, and apply temporary mitigations until patches are in place.

24 Aug 2026 thehackernews.com
Security The Hacker News

Operation QUICSILVER: QUICAgent targets Myanmar government and IT

Seqrite Labs says Operation QUICSILVER uses fake graduation invitations to target Myanmar government and IT organizations and delivers a backdoor written in Go named QUICAgent. The campaign is linked to a China-associated actor; strengthen email defenses, add detections for QUICAgent and monitor network behavior for Go-based implants.

24 Aug 2026 thehackernews.com
Security BleepingComputer

Calix GS7 XGS (GS5239XG) flaw lets attackers bypass NAT and expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows unauthenticated remote attackers to add port-forwarding rules that bypass NAT and can make internal devices reachable from the internet. MSPs and sysadmins should identify affected units, check for unauthorized forwards, and apply mitigations or coordinate with ISPs immediately.

24 Aug 2026 bleepingcomputer.com
Security The Hacker News

About 5% of enterprise AI super-users pose a major security risk

Akamai research finds that a small group (around 5%) of heavy AI users in enterprises are embedding unvetted AI tools into business workflows, raising security exposure. Their integrations, API keys and automations can broaden the attack surface, so MSPs and sysadmins should monitor and audit high-volume AI adopters and toolchains.

24 Aug 2026 thehackernews.com
Security BleepingComputer

Attacks target auth bypass flaws in miniOrange SAML plugin for WordPress

Attackers are attempting to exploit two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress; the vulnerabilities can be used to create fake SAML responses and obtain administrator access. Servers running the plugin should be updated or protected immediately to prevent full site takeover or malware deployment.

24 Aug 2026 bleepingcomputer.com
Security BleepingComputer

TikTok agrees $400M settlement with U.S. over alleged COPPA violations

The U.S. Department of Justice reached a $400 million settlement with TikTok, ByteDance and affiliates over alleged COPPA breaches. The move underscores regulatory risk around minors' data and signals MSPs and sysadmins should review integrations, consent handling and data retention for client environments.

24 Aug 2026 bleepingcomputer.com
Security The Register

Apollo hit by social engineering; attackers active in cloud for four days

Investment firm Apollo was compromised via social engineering, allowing attackers to operate in its cloud accounts for about four days. For MSPs and sysadmins this underscores the need for strict identity controls, enforced MFA, least-privilege access and continuous monitoring to detect and contain access in client environments.

24 Aug 2026 theregister.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.