Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1011 stories last updated 17.09.2026 01:28
Security BleepingComputer

Pokémon Center: CEVA Logistics breach affected customer data

Pokémon Center told customers in the UK and Germany that a breach at CEVA Logistics exposed personal and order information and caused some orders to be cancelled. MSPs and sysadmins should reassess vendor access, data‑sharing arrangements and incident response procedures.

17 Aug 2026 bleepingcomputer.com
Security The Hacker News

Evooo1Bot: Linux botnet derived from Mirai turns devices into SOCKS5 proxies

Researchers discovered a new Linux botnet family called Evooo1Bot that builds on Mirai’s leaked DDoS engine and can turn internet-exposed edge devices into SOCKS5 proxies. For MSPs and admins this means risk of anonymized malicious traffic and infrastructure abuse — prioritize changing default credentials, disabling unused services and monitoring outbound connections.

17 Aug 2026 thehackernews.com
Security BleepingComputer

Philips and GE investigate claims of data theft by Clop

Philips and General Electric are probing reports that the Clop ransomware group exfiltrated data. Such vendor or partner intrusions can affect customer data and service continuity; review access logs, third‑party links and credentials promptly.

17 Aug 2026 bleepingcomputer.com
Security BleepingComputer

French tax authority (DGFiP) breach: data of 678,000 individuals stolen

The French Ministry of the Economy and Finance reported an intrusion into DGFiP systems that resulted in data for 678,000 individuals being exfiltrated. For MSPs and admins the concern is increased phishing and identity-fraud risk—review access controls, audit logs and customer notification plans.

17 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Microsoft preparing patch for Defender ShieldBreak (CVE-2026-69414)

Microsoft is working on a patch for the 'ShieldBreak' zero-day in Defender, tracked as CVE-2026-69414. MSPs and system administrators should be ready to test and deploy the update quickly when released, since exploited endpoints or management hosts could be at risk.

17 Aug 2026 bleepingcomputer.com
Security BleepingComputer

SafePal data breach affects 39,798 customers; order records stolen

Hardware wallet provider SafePal reports roughly 39,798 customers had order records exfiltrated following an exploited flaw. Adversaries claim to be offering the stolen dataset for sale; infrastructure teams should audit access logs, rotate credentials, verify database permissions, notify affected customers and prepare for increased phishing and fraud attempts.

16 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Large-scale DDoS attacks disrupted Threema service

Threema was hit by large DDoS attacks this week, causing significant message delivery interruptions. MSPs and sysadmins should review monitoring, capacity planning, and traffic-scrubbing/mitigation arrangements and coordinate with upstream providers to protect customer environments.

16 Aug 2026 bleepingcomputer.com
Security The Register

ChainDrop (Shai-Hulud) poisons 444 npm packages in supply chain

A Shai-Hulud variant of ChainDrop altered 444 npm packages and spreads via tarballs and developer-tool hooks. It can evade common defenses, creating a cascading threat to build systems, CI/CD pipelines and client infrastructure if contaminated packages are installed.

15 Aug 2026 theregister.com
Security BleepingComputer

Evooo1Bot Linux botnet converts routers into SOCKS5 relay nodes

The Mirai-based modular Linux botnet Evooo1Bot is targeting internet-facing gateway devices and converting them into SOCKS5 proxy nodes. For MSPs and admins this increases the risk of customer devices being abused for anonymized malicious traffic, complicates attribution and highlights the need for strong credentials, firmware updates and network segmentation.

15 Aug 2026 bleepingcomputer.com
Security The Register

1.6M RingCentral accounts exposed after ShinyHunters extortion claim

ShinyHunters has posted what it says are 1.6M RingCentral account records following an extortion claim. MSPs and sysadmins should assume credentials or contact data may be included and take steps such as scanning for reused passwords, forcing rotations where needed, reviewing logs, and enhancing monitoring for account takeover and phishing.

14 Aug 2026 theregister.com
Security The Register

Russian missile reportedly used Nvidia AI chip for targeting; Kyiv seeks tighter controls

Reports indicate a Russian guided missile employed an Nvidia AI processor to enhance targeting. Kyiv is urging tighter export and procurement controls to prevent foreign chips being repurposed for weapons, a move that could impact hardware supply chains and compliance for service providers.

14 Aug 2026 theregister.com
Security The Register

French tax authority confirms data breach; 2 million-record claim under review

After an attacker claimed roughly 2 million tax records, the French tax office acknowledged a data breach while disputing claims of ongoing access. Investigators are quantifying the impact; MSPs and admins should audit credentials, verify backups and review logs for potential customer data exposure.

14 Aug 2026 theregister.com
Security The Register

Autonomous AI agents pose physical risks to critical infrastructure

Experts warn that autonomous AI agents can automate cyber intrusions and escalate them into physical damage affecting energy, transport and industrial control systems. MSPs and administrators should strengthen defenses by segmenting OT, tightening access controls, increasing monitoring and exercising incident response for AI-driven threats.

14 Aug 2026 theregister.com
Security BleepingComputer

Hackers tied to €30M bank fraud arrested after exploiting service provider flaw

Authorities arrested four suspects in Brazil and charged three in Europe over an exploitation of a service provider vulnerability that allowed withdrawals from Commerzbank customer accounts, with losses around €30 million. The case highlights the need for MSPs and admins to prioritize third-party security, access controls and transaction monitoring.

14 Aug 2026 bleepingcomputer.com
Security Cloudflare

Cloudflare Gateway detects MCP traffic with protocol-level heuristics

Cloudflare Gateway uses protocol-level signals to identify MCP requests. Security teams can leverage this to find shadow MCP connections, enforce Portal-only access for approved servers, and block direct connections on managed network paths—helping protect control-plane communications.

14 Aug 2026 blog.cloudflare.com
Security Cloudflare

Cloudflare Access for Workers: attach Access policy to Workers

Cloudflare's Access for Workers lets you assign an Access policy to a Worker and have that policy enforced across all places the Worker runs — routes, custom domains, workers.dev and preview environments. For MSPs and sysadmins this means centralized authorization, consistent protection including previews, and fewer configuration steps.

14 Aug 2026 blog.cloudflare.com
Security The Register

Trezor confirms 13,000 customers' data exposed in logistics breach

Trezor has confirmed that about 13,000 customers' personal data were exposed after a breach at a logistics supplier. The incident illustrates that secure hardware cannot mitigate risks originating from fulfillment and supply-chain partners. MSPs and sysadmins should review third‑party security, data minimization and breach notification processes.

14 Aug 2026 theregister.com
Security The Register

BOFH diary: Covid ransomware protocol and Y2K blockchain's impact on uptime

In a tongue-in-cheek BOFH piece the author recounts how internal 'Covid ransomware protocol' steps and a Y2K-style blockchain experiment reduced service availability. For MSPs and sysadmins the takeaway is clear: overcomplicated, untested security processes and flashy tech choices can raise operational risk.

14 Aug 2026 theregister.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.