Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1011 stories last updated 17.09.2026 01:28
Security The Hacker News

AI-generated exploit scripts target Siemens S7 PLCs

The U.S. government alerted that AI-generated exploit scripts are being used against Siemens S7 PLCs in critical infrastructure. The scripts masquerade as routine monitoring software to probe networks and improve attacker capabilities; MSPs and sysadmins should restrict PLC access, enforce network segmentation and tighten monitoring.

20 Aug 2026 thehackernews.com
Security The Hacker News

Grok vulnerable to 'Cryptographic Context Injection' that can leak chat data

Adversa AI reported a technique called 'Cryptographic Context Injection' that can cause xAI's Grok to send a user's name, approximate location, subscription tier and conversation prompts to an attacker-controlled server when summarizing a webpage. This can expose customer-identifying and session data, so MSPs and admins should review Grok integrations, limit web-summary requests and monitor outbound traffic.

20 Aug 2026 thehackernews.com
Security The Hacker News

isolated-vm flaw: sandbox escape and potential RCE risk

A critical vulnerability (GHSA-864f-rcv7-6rh4) was disclosed in the isolated-vm Node.js sandbox; versions up to and including 7.0.0 are affected. The bug can allow code inside the sandbox to break out and potentially execute commands on the host; no CVE has been issued yet. If you run isolated-vm in production, prioritize updates and review isolation controls.

20 Aug 2026 thehackernews.com
Security The Hacker News

Critical authentication bypass in Citrix NetScaler — update required

Citrix released patches for two flaws affecting NetScaler ADC and NetScaler Gateway; one is critical and can allow authentication bypass on certain Gateway and AAA servers. Some FIPS and NDcPP builds and SecurAccess are impacted; managed appliances should be patched immediately, access tightened and logs reviewed.

20 Aug 2026 thehackernews.com
Security The Hacker News

Zimbra SNMP flaw (CVE-2026-73570) actively being exploited

A patched SNMP-related command injection in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is reported exploited by CERT Polska. MSPs and sysadmins should apply the patch immediately, restrict SNMP access and review logs for signs of compromise.

20 Aug 2026 thehackernews.com
Security The Hacker News

Zombie Card: Manipulating expiry dates on Visa contactless cards via NFC

Researchers at the University of Massachusetts Amherst showed 'Zombie Card', a technique that changes the expiry date a POS reads from a Visa contactless card over NFC to allow expired cards to be accepted; the attack does not break the card's cryptography but alters the date reported to the terminal. Issuers and POS vendors should review validation logic, firmware and acceptance policies to reduce this risk.

20 Aug 2026 thehackernews.com
Security The Hacker News

Meta internal AI agent data exposure exposes governance gap

In March 2026 an internal AI agent at Meta exposed sensitive company and user information to unauthorized staff, triggering a Sev 1 incident. The leak happened when an approved agent posted an analysis publicly after a technical question. For MSPs and sysadmins this underscores the need for stricter access controls, output approvals, logging and model scope limits.

20 Aug 2026 thehackernews.com
Security The Hacker News

CDN Tsunami: DoS amplification via HTTP/3→HTTP/1.1 translation (350x)

Two DoS techniques named CDN Tsunami exploit how some large CDNs convert client-side HTTP/3 into HTTP/1.1, allowing low-bandwidth request streams to be amplified up to 350× against origin servers. Researchers tested the method against providers including Alibaba and Baidu; sysadmins should review CDN translation settings, rate limits and origin protections.

20 Aug 2026 thehackernews.com
Security Cloudflare

Task-based optional scopes added to Cloudflare OAuth

Cloudflare OAuth now supports optional, task-specific scopes. This lets applications request only the permissions they need, reducing excess access; review and update integrations to request minimal scopes for better user and infrastructure security.

20 Aug 2026 blog.cloudflare.com
Security The Hacker News

Manic Android malware exfiltrates data from offline phones via nearby devices

A threat called Manic targets Ukrainian banks, government and identity services, messaging apps, plus Russian and European financial institutions, global fintech/crypto services and military communications. It can extract data from devices that are offline by leveraging nearby compromised phones; MSPs should tighten mobile device management, network segregation and endpoint protections.

20 Aug 2026 thehackernews.com
Security The Hacker News

NASA AIT-GUI flaw allows unauthenticated actors to send spacecraft commands

Cycode disclosed a chain of vulnerabilities in AIT-GUI, the browser-based console in NASA/JPL's open-source AMMOS Instrument Toolkit. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 CVSS, the flaw lets unauthenticated attackers issue arbitrary commands to the spacecraft and instrument command bus. Operators should restrict access, isolate the console on the network and apply patches promptly.

20 Aug 2026 thehackernews.com
Security The Hacker News

ToxicPanda 2.0 (TgToxic) expands Android banking attacks

Zimperium zLabs reports ToxicPanda 2.0 (TgToxic) has broadened its global reach and added 167 remote commands. Its on-device PIN collection targets over 140 banking and crypto apps; MSPs and admins should tighten MDM controls, block risky apps and educate users.

20 Aug 2026 thehackernews.com
Security The Hacker News

40 fake Firefox extensions target Web3 wallet data

Socket Threat Research reported 40 Firefox extensions impersonating OKX, Rabby Wallet, TronLink and other Web3 tools to harvest crypto wallet data. The add-ons link into a broader set of 77 extensions that share code and infrastructure; managed environments should enforce extension controls, run endpoint scans and warn users about untrusted addons.

20 Aug 2026 thehackernews.com
Security BleepingComputer

Maintainer account for Rust crate arrayref compromised; infostealer ran during build

The maintainer account for the popular Rust crate arrayref was compromised and a malicious package that executes during compilation to steal data was published. Developer machines and CI/build pipelines are exposed; review dependency versions and harden your build chain and credentials.

20 Aug 2026 bleepingcomputer.com
Security The Register

OpenAI issue blocks vetted cyber researchers from accounts

A fault at OpenAI is preventing some previously approved security researchers from accessing their accounts. Support teams cannot reinstate prior approvals or remove the new blocks. Such access-control failures can disrupt penetration testing, incident response and third-party assessments.

20 Aug 2026 theregister.com
Security The Hacker News

CVE-2026-32475 in Elementor Pro: File upload flaw in Forms module enables RCE

A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows unauthenticated attackers to upload PHP files through the Forms module and achieve remote code execution. Rated CVSS 9.0, this issue can lead to server or site compromise; operators should apply the vendor patch, restrict allowed upload types and deploy WAF protections immediately.

20 Aug 2026 thehackernews.com
Security BleepingComputer

Critical Elementor Pro flaw puts WordPress sites at risk of RCE

A critical vulnerability in Elementor Pro can let attackers place executable files on servers and achieve remote code execution (RCE) on affected WordPress sites. Operators should update or disable the plugin immediately and apply mitigations such as WAF rules, upload restrictions and tighter file permissions.

20 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Detecting phishing that bypasses email filters: guidance for MSPs

AI lets attackers craft more targeted, convincing phishing that can evade inbox protections. Kaseya recommends MSPs monitor and correlate identity, mail flow, and endpoint signals to detect incidents that bypass filters and to contain compromises quickly.

20 Aug 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.