Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security BleepingComputer

Five alleged Black Axe leaders extradited to the US

Five suspects tied to Black Axe were sent to the United States to face prosecution over alleged global cyber-enabled financial crimes and related laundering offenses. The case highlights that organized groups can run cross-border financial attacks; MSPs and sysadmins should strengthen monitoring, fraud controls and client authentication.

15 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Microsoft confirms KB5002914 causes copy‑paste failures in Excel

Microsoft confirmed the September 2026 KB5002914 security update can cause copy-and-paste to silently fail for some Excel users. For MSPs and sysadmins this may disrupt workflows and raise support volume; test the update and prepare rollback or mitigation steps before wide deployment.

15 Sep 2026 bleepingcomputer.com
Security The Register

HBO Max Reddit account hijacked to serve ClickFix malvertising

Attackers took over HBO Max's official Reddit account to channel the ClickFix malvertising campaign. The incident was part of a short, high-intensity ad-driven infection wave aimed at macOS and Windows endpoints; MSPs and admins should review ad networks, account credentials and endpoint defenses.

15 Sep 2026 theregister.com
Security The Hacker News

DDRop undermines Intel TDX and AMD SEV‑SNP confidential computing

DDRop is a new hardware attack that blocks memory write operations so CPUs can keep reading stale encrypted data, undermining TDX and SEV‑SNP confidentiality. It requires an attacker who already controls server software and briefly gains physical access to attach a small circuit. Providers should harden physical access and follow vendor security updates.

14 Sep 2026 thehackernews.com
Security The Hacker News

MeshCentral backdoor gave root access in 3BB network; subscriber credentials targeted

An attacker gained persistent root-level remote control inside 3BB by exploiting a backdoor in the MeshCentral management tool, a breach uncovered by Hunt.io. An internet-exposed server left by the attacker stored their tools and lists of subscriber credentials; operators should audit remote-management access and credential protection.

14 Sep 2026 thehackernews.com
Security The Hacker News

Telegram Desktop flaw: JavaScript in HTML exports can exfiltrate messages

ExPatch reported a Telegram Desktop weakness that allowed a bot to embed hidden JavaScript into chats; the script executes when an exported HTML file is opened in a browser and can collect and transmit the messages contained in the file. For MSPs and admins this means exported chat archives can leak sensitive customer data; avoid opening HTML exports in browsers, inspect or sanitize files, and apply vendor fixes when available.

14 Sep 2026 thehackernews.com
Security The Hacker News

AI accelerated vulnerability discovery; validation and prioritization must adapt

AI-driven tools have increased the speed and scale of vulnerability discovery; 35,853 CVEs were published in H1 2026, roughly a 49% rise versus the prior period. MSPs and sysadmins must update validation and triage workflows to avoid alert fatigue and concentrate on genuine risks.

14 Sep 2026 thehackernews.com
Security BleepingComputer

Japan's Digital Agency: VPN flaw may have exposed 246,000 government employee records

Japan's Digital Agency reported that a VPN vulnerability may have exposed around 246,000 records belonging to government employees. For MSPs and sysadmins this underlines the need to review VPN configurations, audit access logs and authentication controls, and enforce patching and credential rotation to limit impact.

14 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Homebrew 7.0.0: native BrewUI and integrated security scanner

Homebrew 7.0.0 is released with a native BrewUI graphical interface and an integrated vulnerability scanner. This helps admins tighten install policies, audit package security and reduce risks in deployments.

14 Sep 2026 bleepingcomputer.com
Security The Register

Revolut handed over customer data after accepting fake government requests

Some customers' passport and selfie photos and transaction histories were reportedly passed to third parties after Revolut complied with fraudulent government-style requests. Attackers demanded 10,000 Bitcoin; MSPs and sysadmins should review identity verification, legal checks and data-sharing controls immediately.

14 Sep 2026 theregister.com
Security The Hacker News

Malicious Twitch extension exposed OAuth tokens of about 31,000 users

A cross-store Twitch browser extension named 'Twitch Enhanced Viewer | JeetBot' leaked OAuth tokens for roughly 31,000 users to proxy servers linked to a Russian commercial bot service. Admins and MSPs should treat the leak as account compromise—revoke exposed tokens, remove the extension from endpoints, block related network destinations and review extension policies to limit further abuse.

14 Sep 2026 thehackernews.com
Security BleepingComputer

Webinar: Malicious OAuth apps can enable Google Workspace breaches

Attackers combine social-engineering with rogue OAuth apps to reach Google Workspace without stolen credentials. The webinar examines two attack cases, explains the attack flow and outlines mitigations such as app whitelisting, permission reviews and token revocation.

14 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Microsoft confirms September security updates break RDS on Windows Server

Microsoft acknowledged that its September 2026 security patches are causing Remote Desktop Services (RDS) to fail on some Windows Server installations. This can disrupt remote administration and customer access, so MSPs and admins should test updates and have rollback plans before deployment.

14 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Revolut discloses customer data breach exposing financial records and passports

Revolut reported that an attacker posing as a government body gained access to data for some customers. Reported exfiltrated items include financial records and passport copies, raising risks of identity theft and account fraud. MSPs and admins should review identity-verification and customer checks.

14 Sep 2026 bleepingcomputer.com
Security The Hacker News

Attackers use passkey phishing to hijack Microsoft cloud accounts and steal data

Microsoft disclosed two campaigns in which attackers abused third-party email delivery services to send over one million scam messages between August 3–5, 2026, and used passkey-focused social engineering to take over cloud accounts and exfiltrate data. For MSPs and admins this means reviewing email-provider trust, monitoring passkey approval flows and session activity, and ensuring fast revocation and conditional access controls.

13 Sep 2026 thehackernews.com
Security The Register

Security through obscurity is no longer viable as AI increases exposure

AI tools accelerate discovery of code, configurations and hidden assets, making obscurity-based defenses unreliable. For MSPs and sysadmins, secrets management, strong authentication and explicit security controls must be prioritized.

13 Sep 2026 theregister.com
Security BleepingComputer

CVE-2026-51990: GrayRabbit deployed via Sogou Input Method for Windows flaw

A China-linked espionage group is exploiting CVE-2026-51990 in Sogou Input Method for Windows to install the GrayRabbit backdoor. Sysadmins and MSPs should apply patches immediately, hunt for suspicious processes and C2 traffic in telemetry, and check customer systems for persistence indicators.

13 Sep 2026 bleepingcomputer.com
Security The Hacker News

CISA adds five actively exploited Artifactory, ScreenConnect and RouterOS flaws to KEV

The U.S. CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its KEV catalog after reports of active exploitation. MSPs and sysadmins should urgently deploy fixes for CVE-2026-42016 (CVSS 8.1) and related issues, restrict exposure where possible, and audit logs for signs of compromise.

12 Sep 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.