Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1011 stories last updated 17.09.2026 01:28
Security The Hacker News

MLflow SSRF exploited to steal cloud credentials

An SSRF bug in MLflow is being actively scanned and exploited to obtain cloud account credentials and other sensitive data. Separate vulnerabilities in FUXA are also seeing scanning and exploitation, with watchTowr and VulnCheck reporting malicious activity. Apply patches promptly, restrict metadata access and tighten network segmentation.

18 Aug 2026 thehackernews.com
Security The Hacker News

Ransom Busters asks victims for $20,000–$60,000 claiming to remove data from ransomware servers

An affiliate calling itself Ransom Busters has been emailing victim organizations, claiming it can remove stolen data held on ransomware operators' servers in return for fees between $20,000 and $60,000. GuidePoint Research flagged the outreach as unusual; MSPs and sysadmins should avoid negotiating with unknown intermediaries, preserve evidence and backups, and involve law enforcement and incident response teams.

18 Aug 2026 thehackernews.com
Security The Register

Researchers: expired cards can still work in some payment flows

Researchers showed that when expiry-date checks are weak, cards past their expiry can still be used to complete transactions. Sysadmins and MSPs should tighten expiry validation, CVV and 3DS enforcement, tokenization and anomaly monitoring in gateways, POS software and integrations.

18 Aug 2026 theregister.com
Security The Hacker News

16 typosquatted RubyGems packages used to exfiltrate browser and crypto wallet data on Windows

OpenSourceMalware uncovered the campaign on August 15, 2026 and tracks it as StubMaker. Sixteen typosquatted gems delivered a Windows-targeted info stealer that can exfiltrate browser credentials and crypto wallet data. Example package names: ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn.

18 Aug 2026 thehackernews.com
Security Microsoft

MacSync Stealer: Microsoft uncovered 30+ domains using behavioral pivots

MacSync Stealer evades detection by rapidly rotating domains, while its malicious behaviors remain consistent. Microsoft applied durable behavioral pivots to link and reveal more than 30 related domains. MSPs and sysadmins should prioritize behavior-based monitoring and hunting alongside signature detections to catch fast-moving infrastructure.

18 Aug 2026 microsoft.com
Security Microsoft

Microsoft tracked MacSync Stealer infrastructure using behavioral pivots

Microsoft linked over 30 domains to MacSync Stealer by relying on persistent behavioral pivots despite the malware's frequent domain churn. For MSPs and sysadmins this underlines that domain blocklists alone aren’t enough and behavior-based detection and monitoring of endpoints and DNS are essential.

18 Aug 2026 microsoft.com
Security The Hacker News

Single server has scraped Salesforce and ServiceNow portals since 2025

Research by Reco shows a campaign called City Forum used one server to pull records from Salesforce and ServiceNow customer portals since 2025. MSPs and sysadmins should investigate traffic from 158.220.87.79, review API logs and session anomalies, and apply IP blocks, WAF rules and key rotation as immediate mitigations.

18 Aug 2026 thehackernews.com
Security BleepingComputer

Comcast turns Xfinity WiFi into in-home motion detector

Comcast is adding a feature to Xfinity Shield that uses WiFi signals to sense motion inside homes without cameras or separate sensors. For MSPs and sysadmins this creates operational and privacy implications: you may need to apply router/client updates, review telemetry and consent settings, and reassess wireless segmentation on customer networks.

18 Aug 2026 bleepingcomputer.com
Security The Hacker News

SafePal order-tracking plugin flaw exposed data of about 39,798 customers

SafePal reported that an authorization bug in an order-tracking plugin exposed names, emails, shipping addresses, phone numbers and purchase details for roughly 39,798 customers. For sysadmins and MSPs: review third-party plugin permissions and logs, watch for phishing or fraud using the leaked PII, and ensure vendor notifications, credential rotations and mitigations are in place.

18 Aug 2026 thehackernews.com
Security BleepingComputer

Custom Java web shell targeting PTC Windchill and FlexPLM linked to Clop

A custom Java web shell attributed to the Clop group targets PTC Windchill and FlexPLM servers and can decrypt credentials, enumerate repository files and exfiltrate data. MSPs and admins running these products face an elevated risk of breach and data loss; strengthen access controls, enable monitoring for web shells and rotate credentials.

18 Aug 2026 bleepingcomputer.com
Security The Register

Windows-based system fault disrupted passport control at French airport

The Register reports a disruption to passport control at a French airport linked to Windows-based software. Such outages can impact passenger flow and operations, so MSPs should review redundancy, monitoring and incident response for identity and border-control systems.

18 Aug 2026 theregister.com
Security BleepingComputer

Picus Blue Report 2026: Prevention rates vary by attack technique

Picus Security's Blue Report 2026 finds that defenses which stop familiar methods can miss quieter, behavior-based approaches. The report shows prevention effectiveness differs widely by technique; for those managing servers and customer infrastructure, adding behavioral tests helps reveal coverage gaps.

18 Aug 2026 bleepingcomputer.com
Security BleepingComputer

CISA: Windows Task Host flaw exploited by ransomware groups

CISA has confirmed that a high-severity Windows Task Host vulnerability, noted as actively exploited in April, is now being used by ransomware operators. Administrators and MSPs should prioritize patching, enhance monitoring, and verify backups and incident response readiness.

18 Aug 2026 bleepingcomputer.com
Security The Hacker News

Critical GitLab GraphQL flaw could let unauthenticated actor delete public projects

GitLab issued fixes for a critical GraphQL vulnerability (CVE-2026-19478) affecting Community and Enterprise Editions. In some scenarios an unauthenticated actor can modify or remove public projects and certain user data; the flaw is rated CVSS 9.4. Administrators should apply the update immediately.

18 Aug 2026 thehackernews.com
Security The Hacker News

Snowflake GitHub Actions flaw: issue-triggered command execution and Jira credential risk

Wiz researchers found a vulnerability in the snowflakedb/snowflake-connector-net GitHub Actions workflow. The .github/workflows/jira_issue.yml could be triggered by a malicious GitHub issue to process attacker-controlled input and execute commands using internal Jira credentials, posing risks to CI pipelines and secret management.

18 Aug 2026 thehackernews.com
Security The Hacker News

CVE-2026-15748 in Forminator Forms allows unauthenticated RCE via PHP uploads

A critical flaw in the Forminator Forms plugin (CVE-2026-15748, CVSS 9.8) can let unauthenticated attackers upload malicious PHP and achieve remote code execution on sites with ~600,000 installs. Immediate steps for managed environments: update or disable the plugin, harden upload paths and file permissions, apply WAF rules and scan/restore affected sites.

17 Aug 2026 thehackernews.com
Security The Hacker News

Exploit chain enables kernel-level compromise via Unisoc VoLTE video call

On August 17, 2026 SSD Secure Disclosure published the second stage of an exploit that uses a VoLTE video call to achieve kernel-level control on devices with Unisoc modem firmware. Unisoc has not issued a patch; MSPs and administrators should treat this as a high-risk remote compromise vector that can lead to persistent, low-interaction takeover of customer devices.

17 Aug 2026 thehackernews.com
Security BleepingComputer

Attacker claims 3.6 million Azure account records stolen

A threat actor says they accessed Microsoft Azure environments with compromised credentials and is offering employee databases from several Fortune 500 customers—totaling 3.6 million records—for sale. Server admins and MSPs should prioritize credential rotation, enforce MFA, tighten access controls and review audit logs.

17 Aug 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.