Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
More than 9,300 AWS access keys publicly exposed between Aug 2022 and Aug 2026 are still valid and can grant full control of corporate accounts. MSPs and sysadmins should treat this as high risk: revoke and rotate keys, use IAM roles and least-privilege, and monitor CloudTrail/GuardDuty for suspicious activity.
Microsoft issued a patch for an Entra ID vulnerability rated CVSS 10.0 that could enable remote code execution. Early reports suggested exploitation, but Microsoft later stated there was no active exploitation; administrators should deploy the update promptly and review authentication and access logs.
Wi‑Fi 7 strengthens WPA3 security, but CableLabs is urging vendors to use a workaround so legacy clients remain connected. That workaround may reduce protections, so MSPs and sysadmins should review compatibility modes, network segmentation and vendor updates before enabling it.
Reusing email, phone and payment details makes it easier for brokers and attackers to correlate user activity. Anonyome Labs recommends creating separate digital personas to reduce linkage and limit the impact of breaches, spam and identity theft. For MSPs, this approach can lower customer risk and simplify incident response.
CISA directed U.S. federal agencies to prioritize fixes for two actively exploited vulnerabilities in TrueConf Server. Because these flaws affect a self-hosted communications platform and can enable unauthorized access or disruption, MSPs and sysadmins should apply updates and review network and authentication controls.
Microsoft released a patch for a high-severity vulnerability in the Entra ID identity and access management platform that was used in attacks. For service providers and admins, this risk can enable token theft, account takeover and lateral movement, so apply the update and review identity/access logs and service accounts.
Threat actors are embedding commands in FTP server banners to deliver two previously unreported Windows RATs, E4del and PINHOLE. The technique can bypass basic traffic controls; MSPs and administrators should monitor FTP banners and logs, update IDS/IPS detections, and strengthen endpoint detection and response.
Toronto's Hospital for Sick Children (SickKids) reported that a vulnerability in third-party software led to exposure of personal data for some current and former employees and job applicants. Clinical systems and patient records were not affected. The incident underscores the need for MSPs and sysadmins to review vendor integrations and access controls.
A compromised maintainer republished arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 on crates.io that added a typosquatted dependency whose build script retrieved and executed a remote payload during compilation. With 245 million downloads across the affected packages, build-time malware can taint CI systems and downstream artifacts; inspect build scripts, pin dependencies and enforce isolated/reproducible builds.
Three suspected Russian espionage clusters — UNC6293, UNC7005 and UNC5976 — have been observed abusing Google OAuth grants and WhatsApp account linking to hijack accounts at universities, aerospace/defense, government and think tanks in Europe and the U.S. Because these flows can circumvent protections and expose data, MSPs and sysadmins should audit OAuth consents, linked accounts and authentication logs.
The ThreatsDay roundup highlights RCE in Gogs 10.0, an n8n workflow-to-RCE path, GLM-5.3 exploit research and a $10M reward announcement. It warns that trusted components, signed drivers and legitimate apps are being misused and that exposed services and weak checks lower attacker effort — apply patches and audit exposed workflows and drivers.
The U.S. government alerted that AI-generated exploit scripts are being used against Siemens S7 PLCs in critical infrastructure. The scripts masquerade as routine monitoring software to probe networks and improve attacker capabilities; MSPs and sysadmins should restrict PLC access, enforce network segmentation and tighten monitoring.
Adversa AI reported a technique called 'Cryptographic Context Injection' that can cause xAI's Grok to send a user's name, approximate location, subscription tier and conversation prompts to an attacker-controlled server when summarizing a webpage. This can expose customer-identifying and session data, so MSPs and admins should review Grok integrations, limit web-summary requests and monitor outbound traffic.
A critical vulnerability (GHSA-864f-rcv7-6rh4) was disclosed in the isolated-vm Node.js sandbox; versions up to and including 7.0.0 are affected. The bug can allow code inside the sandbox to break out and potentially execute commands on the host; no CVE has been issued yet. If you run isolated-vm in production, prioritize updates and review isolation controls.
Citrix released patches for two flaws affecting NetScaler ADC and NetScaler Gateway; one is critical and can allow authentication bypass on certain Gateway and AAA servers. Some FIPS and NDcPP builds and SecurAccess are impacted; managed appliances should be patched immediately, access tightened and logs reviewed.
A patched SNMP-related command injection in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is reported exploited by CERT Polska. MSPs and sysadmins should apply the patch immediately, restrict SNMP access and review logs for signs of compromise.
Researchers at the University of Massachusetts Amherst showed 'Zombie Card', a technique that changes the expiry date a POS reads from a Visa contactless card over NFC to allow expired cards to be accepted; the attack does not break the card's cryptography but alters the date reported to the terminal. Issuers and POS vendors should review validation logic, firmware and acceptance policies to reduce this risk.
In March 2026 an internal AI agent at Meta exposed sensitive company and user information to unauthorized staff, triggering a Sev 1 incident. The leak happened when an approved agent posted an analysis publicly after a technical question. For MSPs and sysadmins this underscores the need for stricter access controls, output approvals, logging and model scope limits.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.