Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Ukraine revealed a fast, lightweight jet-powered counter-drone platform designed for rapid field deployment and compact enough to be moved in a pickup. MSPs and data centre operators should assess how such tactical systems could affect hosted sites and update airspace monitoring, physical security and incident response procedures.
A large DDoS campaign that began on Monday disrupted shared online services used by Norway's public agencies, causing outages across government platforms. For MSPs and sysadmins this highlights the need to review DDoS defenses, capacity planning, failover arrangements and monitoring to reduce customer impact.
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities list after evidence of active exploitation. The CVSS 10.0 flaw in Oracle HTTP Server and Oracle WebLogic Server can allow unauthenticated attackers to access critical data over HTTP; apply patches, restrict network exposure and monitor logs urgently.
Attackers are leveraging sponsored search listings and fake OpenAI Codex ads to trick Mac users into downloading ClickFix malware. This developer-focused lure can bypass casual checks, so endpoint protection, download verification and monitoring ad-related traffic should be prioritized by service providers.
Attackers exploited a high-severity Zimbra Collaboration Suite flaw to compromise more than 270 Zimbra instances. MSPs and sysadmins should assume mail servers and credentials may be exposed and perform emergency patching, network isolation and log/incident response to determine scope.
Investigations across 22 countries identified 263 suspects and resulted in 58 arrests, with connections to Africa-based organized crime groups. For MSPs and sysadmins this highlights the need to tighten monitoring, review credentials and validate incident response and detection controls against botnets, ransomware and phishing.
Researchers uncovered a Windows backdoor named Sleepwalker that contains a custom command set of 23 operations. The design and instruction complexity point to a planned, resource-backed actor rather than opportunistic malware. MSPs and sysadmins should prioritize detection signatures, network monitoring and incident response.
Researchers found Weedhack being distributed to gamers through fake Minecraft clients and search-result manipulation. McAfee Labs blocked over 6,300 access attempts to malicious sites; infected endpoints can be leveraged to pivot into customer networks or join botnets, so MSPs and sysadmins should monitor gamer-facing downloads.
AI-driven tools are making it easier to exploit PLCs and industrial devices, while GitLab incidents and leaked Stripe API keys were also reported. Trusted packages and internet-exposed services are common factors; admins should prioritize secrets management, package provenance checks and network segmentation.
Gen Digital researchers identified two new malware families, WordlistLoader and SynkLoader. WordlistLoader uses ClearFake campaigns with ClickFix (aka FakeCaptcha) to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer), while SynkLoader focuses on phishing Windows credentials. For MSPs, stolen credentials can enable access resale to ransomware actors and client compromise.
AI-assisted code generation is increasing the number of packages and dependencies faster than security teams can review, causing a backlog of vulnerabilities and patch work. For MSPs and sysadmins, using SCA, SBOMs, automation and risk-based prioritization is essential to keep remediation debt under control.
Red Hat and the Keycloak project issued fixes for a severe vulnerability (CVE-2026-18963, CVSS 9.1) that allows unauthenticated attackers to compromise accounts via the password-reset flow. Administrators and MSPs should update Keycloak immediately, limit public exposure of identity endpoints, and apply temporary mitigations until patches are in place.
Seqrite Labs says Operation QUICSILVER uses fake graduation invitations to target Myanmar government and IT organizations and delivers a backdoor written in Go named QUICAgent. The campaign is linked to a China-associated actor; strengthen email defenses, add detections for QUICAgent and monitor network behavior for Go-based implants.
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows unauthenticated remote attackers to add port-forwarding rules that bypass NAT and can make internal devices reachable from the internet. MSPs and sysadmins should identify affected units, check for unauthorized forwards, and apply mitigations or coordinate with ISPs immediately.
Akamai research finds that a small group (around 5%) of heavy AI users in enterprises are embedding unvetted AI tools into business workflows, raising security exposure. Their integrations, API keys and automations can broaden the attack surface, so MSPs and sysadmins should monitor and audit high-volume AI adopters and toolchains.
Attackers are attempting to exploit two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress; the vulnerabilities can be used to create fake SAML responses and obtain administrator access. Servers running the plugin should be updated or protected immediately to prevent full site takeover or malware deployment.
The U.S. Department of Justice reached a $400 million settlement with TikTok, ByteDance and affiliates over alleged COPPA breaches. The move underscores regulatory risk around minors' data and signals MSPs and sysadmins should review integrations, consent handling and data retention for client environments.
Investment firm Apollo was compromised via social engineering, allowing attackers to operate in its cloud accounts for about four days. For MSPs and sysadmins this underscores the need for strict identity controls, enforced MFA, least-privilege access and continuous monitoring to detect and contain access in client environments.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.