Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
ReliaQuest reported that following the ShinyHunters incident an employee was targeted by attackers impersonating security staff in a social-engineering attempt to steal data. The attack did not succeed; MSPs and sysadmins should review identity verification, access controls and anti-phishing training.
CISA has directed U.S. agencies to rapidly address an actively exploited issue in Zimbra Collaboration Suite (ZCS) with a tight remediation window. Server admins and MSPs should immediately apply vendor updates, review logs for signs of compromise, isolate affected hosts and confirm backups.
ToxicPanda has expanded its capabilities, targeting 349 apps and supporting 167 remote commands. It abuses device VPN permission to block access to Google Play, which can obstruct updates, removals and incident response on managed devices.
Under an agreement with the U.S. Department of Justice, ByteDance-owned TikTok will pay $400 million to resolve 2024 claims over children’s privacy; $300 million is payable immediately and $100 million is conditional on a legal step. MSPs and sysadmins should note the compliance and data-handling precedents such settlements can create.
Autonomous AI agents are being used by attackers to probe networks, identities and automation pipelines. MSPs and sysadmins should use similar tools to test defenses, increase agent monitoring, restrict privileges and harden automation controls.
A supply-chain attack used a legitimate-looking device update app to install malware on Android-based car head units. Compromised units are being added to a proxy botnet and can be abused for traffic routing or ad fraud; monitor network connections and validate update sources.
Windows Named Pipes are a common IPC mechanism, but weak access controls can allow privileged services to be reached by untrusted processes. ThreatLocker highlights endpoint verification, command authorization, strict input validation and narrowly scoped privileges as measures to harden named-pipe communication.
AWS has opted to quarantine leaked credentials, but security experts warn this alone won't prevent abuse. For MSPs and sysadmins the lesson is to maintain key rotation, comprehensive monitoring and strict access controls.
Trend Micro researchers found trojanized npm packages posing as calendar and streak utilities that install an AI-assisted Linux backdoor, RedC2 4.0. When loaded, the module makes the bundled binary executable and launches it in the background, enabling a stealthy C2 channel. Audit dependencies and restrict executable permissions.
Check Point Research demonstrated that Microsoft Defender's signed boot-time driver BTR.sys can be abused to perform kernel-level file and registry operations. The technique does not rely on a software flaw or external drivers and can affect systems from Windows 7 to Windows 11 25H2, so admins should review boot security and driver access controls.
Kaspersky discovered in June 2026 a new malware family targeting DoFun-based Android head unit firmware. It abuses built-in updaters to deploy staged payloads for ad fraud and assembling a proxy botnet; fleet managers and MSPs should validate update channels, isolate telematics networks and enforce firmware integrity checks.
Homeland Security officials recommended immediate patching of vulnerabilities in TrueConf. Reports say Ukrainian hacktivists are exploiting the flaws, and because TrueConf is used beyond Russia, administrators should promptly check and apply updates.
Toronto's SickKids hospital discovered an intruder on its careers site and restricted access while applying fixes. The organization says the issue stemmed from a third‑party software flaw affecting multiple entities; MSPs should audit vendor components, credentials and logs.
Malicious updates were pushed to popular Rust crates so normal build and install workflows delivered an information‑stealing payload. Developer credentials and CI environment secrets may be exposed; sysadmins and MSPs should audit dependency management and secret handling immediately.
Integrating Wazuh with AI and machine learning aims to improve alert prioritization, cut false positives, and speed up automated response processes. For MSPs and sysadmins, better alert correlation and automation can shorten incident response times and reduce operational burden.
Cisco released fixes for Crosswork platforms and Secure Workload following an internal security review. Nine vulnerabilities were addressed, five rated CVSS 10.0. Four issues affect Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning irrespective of configuration — admins should apply updates and audit impacted systems immediately.
New SynkLoader malware is being delivered through Microsoft Teams phishing messages and uses a fake lock screen to capture user credentials. This poses a risk for MSPs and sysadmins, as stolen credentials can enable lateral movement and account takeover; review MFA and Teams security settings.
A code-injection flaw in GitLab tracked as CVE-2026-19478 (CVSS 9.4) is being actively exploited soon after disclosure. Because it can let unauthenticated actors alter, delete or overwrite public projects, apply vendor patches immediately, restrict public access, and audit repository activity.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.