Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
An SSRF bug in MLflow is being actively scanned and exploited to obtain cloud account credentials and other sensitive data. Separate vulnerabilities in FUXA are also seeing scanning and exploitation, with watchTowr and VulnCheck reporting malicious activity. Apply patches promptly, restrict metadata access and tighten network segmentation.
An affiliate calling itself Ransom Busters has been emailing victim organizations, claiming it can remove stolen data held on ransomware operators' servers in return for fees between $20,000 and $60,000. GuidePoint Research flagged the outreach as unusual; MSPs and sysadmins should avoid negotiating with unknown intermediaries, preserve evidence and backups, and involve law enforcement and incident response teams.
Researchers showed that when expiry-date checks are weak, cards past their expiry can still be used to complete transactions. Sysadmins and MSPs should tighten expiry validation, CVV and 3DS enforcement, tokenization and anomaly monitoring in gateways, POS software and integrations.
OpenSourceMalware uncovered the campaign on August 15, 2026 and tracks it as StubMaker. Sixteen typosquatted gems delivered a Windows-targeted info stealer that can exfiltrate browser credentials and crypto wallet data. Example package names: ubnuler, ubnlder, ri18nr, reaker, rakier, orakw, joxn.
MacSync Stealer evades detection by rapidly rotating domains, while its malicious behaviors remain consistent. Microsoft applied durable behavioral pivots to link and reveal more than 30 related domains. MSPs and sysadmins should prioritize behavior-based monitoring and hunting alongside signature detections to catch fast-moving infrastructure.
Microsoft linked over 30 domains to MacSync Stealer by relying on persistent behavioral pivots despite the malware's frequent domain churn. For MSPs and sysadmins this underlines that domain blocklists alone aren’t enough and behavior-based detection and monitoring of endpoints and DNS are essential.
Research by Reco shows a campaign called City Forum used one server to pull records from Salesforce and ServiceNow customer portals since 2025. MSPs and sysadmins should investigate traffic from 158.220.87.79, review API logs and session anomalies, and apply IP blocks, WAF rules and key rotation as immediate mitigations.
Comcast is adding a feature to Xfinity Shield that uses WiFi signals to sense motion inside homes without cameras or separate sensors. For MSPs and sysadmins this creates operational and privacy implications: you may need to apply router/client updates, review telemetry and consent settings, and reassess wireless segmentation on customer networks.
SafePal reported that an authorization bug in an order-tracking plugin exposed names, emails, shipping addresses, phone numbers and purchase details for roughly 39,798 customers. For sysadmins and MSPs: review third-party plugin permissions and logs, watch for phishing or fraud using the leaked PII, and ensure vendor notifications, credential rotations and mitigations are in place.
A custom Java web shell attributed to the Clop group targets PTC Windchill and FlexPLM servers and can decrypt credentials, enumerate repository files and exfiltrate data. MSPs and admins running these products face an elevated risk of breach and data loss; strengthen access controls, enable monitoring for web shells and rotate credentials.
The Register reports a disruption to passport control at a French airport linked to Windows-based software. Such outages can impact passenger flow and operations, so MSPs should review redundancy, monitoring and incident response for identity and border-control systems.
Picus Security's Blue Report 2026 finds that defenses which stop familiar methods can miss quieter, behavior-based approaches. The report shows prevention effectiveness differs widely by technique; for those managing servers and customer infrastructure, adding behavioral tests helps reveal coverage gaps.
CISA has confirmed that a high-severity Windows Task Host vulnerability, noted as actively exploited in April, is now being used by ransomware operators. Administrators and MSPs should prioritize patching, enhance monitoring, and verify backups and incident response readiness.
GitLab issued fixes for a critical GraphQL vulnerability (CVE-2026-19478) affecting Community and Enterprise Editions. In some scenarios an unauthenticated actor can modify or remove public projects and certain user data; the flaw is rated CVSS 9.4. Administrators should apply the update immediately.
Wiz researchers found a vulnerability in the snowflakedb/snowflake-connector-net GitHub Actions workflow. The .github/workflows/jira_issue.yml could be triggered by a malicious GitHub issue to process attacker-controlled input and execute commands using internal Jira credentials, posing risks to CI pipelines and secret management.
A critical flaw in the Forminator Forms plugin (CVE-2026-15748, CVSS 9.8) can let unauthenticated attackers upload malicious PHP and achieve remote code execution on sites with ~600,000 installs. Immediate steps for managed environments: update or disable the plugin, harden upload paths and file permissions, apply WAF rules and scan/restore affected sites.
On August 17, 2026 SSD Secure Disclosure published the second stage of an exploit that uses a VoLTE video call to achieve kernel-level control on devices with Unisoc modem firmware. Unisoc has not issued a patch; MSPs and administrators should treat this as a high-risk remote compromise vector that can lead to persistent, low-interaction takeover of customer devices.
A threat actor says they accessed Microsoft Azure environments with compromised credentials and is offering employee databases from several Fortune 500 customers—totaling 3.6 million records—for sale. Server admins and MSPs should prioritize credential rotation, enforce MFA, tighten access controls and review audit logs.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.