Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A contractor data analyst at Brightly Software was sentenced to two years in prison after using stolen data to extort $2.5 million from the employer. The case underlines insider threat risks; MSPs and sysadmins should enforce least-privilege, monitor access logs and deploy DLP to reduce damage from malicious or compromised insiders.
Apple is sending new 'Threat Notification' alerts informing users their iPhone may have been targeted by mercenary spyware. MSPs and sysadmins should monitor managed devices for these alerts, enforce updates, and prepare incident response steps for affected endpoints.
Ukrainian authorities shut down 94 call operations used for investment scams and attempts to access bank accounts, seizing millions in cash and evidence. For MSPs and sysadmins this underlines abuse of VoIP/telecom infrastructure and rising social-engineering threats — monitor call patterns, coordinate with telcos and brief customers.
Trump proposes letting private cyber contractors monitor and disrupt foreign criminal networks under strict rules, with firms required to post $1M collateral. For MSPs and sysadmins this raises legal exposure, escalation risk and changes to incident-response and contract considerations.
Microsoft does not automatically provide full backups for M365 and Azure, so customers and MSPs must take responsibility. To mitigate ransomware risk, use third‑party, immutable and tested backups, set retention rules and practice recovery procedures.
An actor tied to the Akira ransomware group rebooted a compromised host into network-enabled Safe Mode to neutralize endpoint protection and stole data, but did not perform file encryption. For MSPs and admins: review protections against Safe Mode bypasses, enforce EDR tamper and boot protections, limit local admin rights and monitor reboot/boot events.
The Jewelbug actor gained access to government webmail accounts while simultaneously running cryptocurrency fraud schemes. For MSPs and sysadmins this highlights risks around email credentials, detecting unauthorized access, and protecting client communications.
Microsoft released fixes for a Windows zero-day called LegacyHive following July 2026 updates. Administrators and MSPs should prioritize testing and deploying the patches, monitor for unusual activity, and follow Microsoft's advisories.
The CRM vendor confirmed a customer database was copied and likely retrieved in a readable format. An AWS key embedded in client-side JavaScript may have enabled the access; rotate exposed keys, tighten IAM privileges and remove secrets from frontend code to reduce risk.
Cloudflare has made Certificate Transparency Monitoring generally available. They no longer send email alerts for certificates Cloudflare issued for your domains, so inbox alerts should be less noisy and more meaningful. MSPs and sysadmins should review monitoring and notification rules accordingly.
Twitch leaves an option enabled by default that allows broadcasters' streams to be used to train Amazon's AI systems; streamers need to opt out. For MSPs and sysadmins this poses a risk that customer streams become training data for third‑party models and raises compliance and contract concerns, so review platform settings and agreements.
Attackers started abusing a critical SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1) after a public PoC appeared. Microsoft issued a fix in its July 2026 updates; operators should apply patches, limit exposure and monitor for suspicious access immediately.
WhatsApp has started rolling out an optional 'Scam Alert' that uses an on-device machine learning model to warn users about potential scam attempts. For MSPs and sysadmins this matters for corporate device policies, user awareness and mobile security procedures.
Near-autonomous AI agents carried out attacks against Taiwan's nuclear safety agency. Agent-based campaigns against critical infrastructure highlight the need for continuous monitoring, network segmentation, and automated privilege controls for MSPs and system administrators.
Check Point Research links the North Korea–linked Lazarus Group to exploitation of a newly patched Microsoft Windows zero-day to install a previously unseen backdoor and obtain SYSTEM-level access against defense and aerospace firms in France, Germany, Brazil and India. Researchers say this continues the Operation Dream Job campaign. Admins and MSPs should apply Microsoft's patches immediately, hunt for indicators and verify there are no unauthorized privilege escalations.
A set of 737 free VPN/proxy Chrome extensions was discovered mainly targeting Russian-speaking users and forwarding browser traffic through a proxy infrastructure. They appeared under at least 40 developer accounts on the Chrome Web Store and accumulated 75,486 installs; 274 mimicked other extensions. Audit client browsers and block suspicious add-ons.
The City-Forum data-theft campaign employs custom tools to harvest information exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals. MSPs and sysadmins should review anonymous-access and data-visibility settings on customer portals and tighten monitoring and access controls.
The NFC relay malware WindRelay, used alongside the SpyNote RAT, can capture live card details and forward them to attackers in real time while enabling fraudulent loan or credit requests on victims' behalf. This threat requires MSPs and sysadmins to monitor for RAT activity, harden mobile payment paths and prepare incident response plans.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.