Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Five suspects tied to Black Axe were sent to the United States to face prosecution over alleged global cyber-enabled financial crimes and related laundering offenses. The case highlights that organized groups can run cross-border financial attacks; MSPs and sysadmins should strengthen monitoring, fraud controls and client authentication.
Microsoft confirmed the September 2026 KB5002914 security update can cause copy-and-paste to silently fail for some Excel users. For MSPs and sysadmins this may disrupt workflows and raise support volume; test the update and prepare rollback or mitigation steps before wide deployment.
Attackers took over HBO Max's official Reddit account to channel the ClickFix malvertising campaign. The incident was part of a short, high-intensity ad-driven infection wave aimed at macOS and Windows endpoints; MSPs and admins should review ad networks, account credentials and endpoint defenses.
DDRop is a new hardware attack that blocks memory write operations so CPUs can keep reading stale encrypted data, undermining TDX and SEV‑SNP confidentiality. It requires an attacker who already controls server software and briefly gains physical access to attach a small circuit. Providers should harden physical access and follow vendor security updates.
An attacker gained persistent root-level remote control inside 3BB by exploiting a backdoor in the MeshCentral management tool, a breach uncovered by Hunt.io. An internet-exposed server left by the attacker stored their tools and lists of subscriber credentials; operators should audit remote-management access and credential protection.
ExPatch reported a Telegram Desktop weakness that allowed a bot to embed hidden JavaScript into chats; the script executes when an exported HTML file is opened in a browser and can collect and transmit the messages contained in the file. For MSPs and admins this means exported chat archives can leak sensitive customer data; avoid opening HTML exports in browsers, inspect or sanitize files, and apply vendor fixes when available.
AI-driven tools have increased the speed and scale of vulnerability discovery; 35,853 CVEs were published in H1 2026, roughly a 49% rise versus the prior period. MSPs and sysadmins must update validation and triage workflows to avoid alert fatigue and concentrate on genuine risks.
Japan's Digital Agency reported that a VPN vulnerability may have exposed around 246,000 records belonging to government employees. For MSPs and sysadmins this underlines the need to review VPN configurations, audit access logs and authentication controls, and enforce patching and credential rotation to limit impact.
Homebrew 7.0.0 is released with a native BrewUI graphical interface and an integrated vulnerability scanner. This helps admins tighten install policies, audit package security and reduce risks in deployments.
Some customers' passport and selfie photos and transaction histories were reportedly passed to third parties after Revolut complied with fraudulent government-style requests. Attackers demanded 10,000 Bitcoin; MSPs and sysadmins should review identity verification, legal checks and data-sharing controls immediately.
A cross-store Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' leaked OAuth tokens for roughly 31,000 users to proxy servers linked to a Russian commercial bot service. Admins and MSPs should treat the leak as account compromise—revoke exposed tokens, remove the extension from endpoints, block related network destinations and review extension policies to limit further abuse.
Attackers combine social-engineering with rogue OAuth apps to reach Google Workspace without stolen credentials. The webinar examines two attack cases, explains the attack flow and outlines mitigations such as app whitelisting, permission reviews and token revocation.
Microsoft acknowledged that its September 2026 security patches are causing Remote Desktop Services (RDS) to fail on some Windows Server installations. This can disrupt remote administration and customer access, so MSPs and admins should test updates and have rollback plans before deployment.
Revolut reported that an attacker posing as a government body gained access to data for some customers. Reported exfiltrated items include financial records and passport copies, raising risks of identity theft and account fraud. MSPs and admins should review identity-verification and customer checks.
Microsoft disclosed two campaigns in which attackers abused third-party email delivery services to send over one million scam messages between August 3–5, 2026, and used passkey-focused social engineering to take over cloud accounts and exfiltrate data. For MSPs and admins this means reviewing email-provider trust, monitoring passkey approval flows and session activity, and ensuring fast revocation and conditional access controls.
AI tools accelerate discovery of code, configurations and hidden assets, making obscurity-based defenses unreliable. For MSPs and sysadmins, secrets management, strong authentication and explicit security controls must be prioritized.
A China-linked espionage group is exploiting CVE-2026-51990 in Sogou Input Method for Windows to install the GrayRabbit backdoor. Sysadmins and MSPs should apply patches immediately, hunt for suspicious processes and C2 traffic in telemetry, and check customer systems for persistence indicators.
The U.S. CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its KEV catalog after reports of active exploitation. MSPs and sysadmins should urgently deploy fixes for CVE-2026-42016 (CVSS 8.1) and related issues, restrict exposure where possible, and audit logs for signs of compromise.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.