Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Citrix warned customers of two security flaws affecting NetScaler Gateway and NetScaler ADC and urged immediate remediation. Because these issues impact remote-access and networking appliances, MSPs and admins should prioritize applying patches or temporary mitigations to protect client access and service continuity.
CISA has informed federal agencies that a severe security flaw in MLflow is being actively abused. Administrators running MLflow should apply patches, restrict access, and strengthen logging and network segmentation to protect models and data.
Manic is a newly observed Android threat active in multiple European countries that can, as a fallback, relay stolen data through nearby compromised devices. This enables lateral data leakage and makes detection and containment harder; MSPs should reassess Bluetooth/Wi‑Fi controls and device isolation measures.
US federal agencies warn attackers are employing AI-assisted tools to create and deploy exploit code against PLCs and other industrial control devices. For MSPs and sysadmins this raises the risk of faster weaponization of vulnerabilities and calls for stronger network segmentation, firmware/patch management, and detection and response measures.
On Cloudflare Workers, researchers demonstrated a remote Spectre side-channel that extracted a JSON Web Token (JWT) from a neighboring Worker instance with measured exfiltration up to 12 bits per second. The end-to-end test ran at about 360× the bandwidth of a 2021 proof‑of‑concept, highlighting co-tenancy and token exposure risks for hosted workloads.
Researchers found the SilkParasite espionage group targeting government bodies in Central Asia using seven RAT families, five of which are new: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT and NodeEdgeRAT. For admins and MSPs this raises the urgency to review logging, network segmentation and endpoint detection to limit stealthy access and data exfiltration.
In Frost Radar 2026, Microsoft is positioned as a visionary leader in the Cloud Workload Protection Platforms category. The recognition reflects Microsoft Defender for Cloud's unified runtime protection for servers and containers, which is relevant for MSPs and sysadmins assessing cloud workload security solutions.
In the 2026 Frost Radar for Cloud Workload Protection Platforms, Microsoft was ranked as a leader, with Microsoft Defender for Cloud noted for its unified runtime security. MSPs and sysadmins should take this as a signal to reassess workload protection and runtime security options for customer environments.
A suspected ransomware affiliate is contacting victims before breaches become public using the Ransom Busters name, offering decryption and deletion of stolen data for a fee. For MSPs and sysadmins this increases the chance clients pay fraudsters and complicates incident response. Review notification procedures, communication channels, and no-payment policies.
The StopAndProtect campaign uses roughly 2,000 compromised WordPress sites worldwide to deliver malware, seize infected hosts and store exfiltrated files, screenshots and operational logs. Because the group employs a toolkit of multiple malicious components, MSPs and sysadmins should monitor site integrity, unusual outbound connections and keep WordPress core and plugins patched.
Japanese cloud and data-center provider Sakura Internet reported unauthorized access to its sales management system, exposing customer contract and membership information for up to 1.36 million accounts. For MSPs and sysadmins this raises risks of phishing, account abuse and regulatory notifications; review access controls, rotate credentials and audit logs.
CISA added four critical vulnerabilities that are being exploited in the wild to its KEV list, affecting macOS, SharePoint, vCenter and Microsoft IKE. Include CVE-2026-65400 in your emergency response: prioritize patches, verify asset inventory and apply network/access mitigations immediately.
Cloudflare re-examined remote Spectre exploitation against its Workers platform in 2024–2025 and identified new building blocks such as Spectre gadgets, remote timers, and techniques for achieving co-location. Additional mitigations were deployed to harden Workers; hosting providers and admins should reassess isolation and defenses against timing attacks for tenant workloads.
Microsoft Defender Experts linked over 30 rotating domains to MacSync Stealer, an information stealer targeting macOS. The analysis correlated recurring endpoint and network signals across shifting infrastructure to map activity from delivery to data collection and exfiltration; MSPs should monitor mac endpoints, DNS logs and suspicious domains.
Microsoft corrected a bug that caused Windows Defender to crash on some systems with 0xc0000005 access violation after a recent security update. Administrators should install the fix and verify endpoint protection remains operational on servers and client devices.
CISA reports active exploitation of a critical remote code execution flaw in the Windows IKE Service Extensions component. Prioritize patching systems that handle VPN/IKE, follow vendor guidance and monitor for unusual connections or command activity on managed infrastructure.
Microsoft says update support for Windows 11 24H2 Home and Pro will cease in two months. Because affected devices will stop receiving security fixes, MSPs and sysadmins should plan upgrades, run compatibility tests and schedule deployments to avoid exposure.
Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, dubbed CoSnitch. A crafted link can let an attacker, with one click, quietly pull data from apps and other data available to the user's Copilot session by abusing an undocumented URL parameter. MSPs should review app connectors, revoke tokens and apply vendor fixes when available.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.