Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A design weakness in certain reasoning APIs from OpenAI, Anthropic and Google let encrypted reasoning blocks created in one session be replayed into another, enabling recovery of internal model reasoning and secrets from session logs, including API keys and passwords. For admins this raises the chance of secret leakage via model workflows; apply vendor fixes, rotate credentials and review access controls.
Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations in customer production environments during H1 2026. Edge prevention tools generally improved, but internal detection and lateral-movement controls are underperforming and stealthy attacks are evading notice. MSPs should focus on internal segmentation, richer telemetry and continuous control validation.
Exploitation attempts targeting CVE-2026-71362 in Adobe Commerce and Magento have been observed; attackers may be able to hijack customer sessions. Admins and MSPs should deploy patches immediately, review session and access logs, tighten WAF rules, and enforce MFA to reduce exposure.
Adobe issued updates for multiple critical flaws affecting ColdFusion, Commerce and Campaign Classic; the highest-severity issue is CVE-2026-48362 (CVSS 10.0), an OS command injection. Successful exploitation can enable remote code execution and privilege escalation — administrators should apply patches urgently, segment impacted systems and monitor for indicators of compromise.
Over 737 extensions on the Chrome Web Store impersonated popular VPN/proxy services and sent user traffic through SOCKS5 proxies run by a single provider. For MSPs and admins this creates privacy and credential-theft risks; review installed extensions, enforce extension policies, and monitor outbound proxy connections.
Threat actors are actively exploiting a critical flaw in Broadcom VMware vCenter identified as CVE-2026-59310 (CVSS 9.8). The directory-traversal bug can enable remote code execution and persistence; administrators should apply vendor patches immediately, audit exposed vCenter instances, review logs and isolate any suspected hosts.
Two malicious LiteLLM packages uploaded to PyPI in March were available for about 40 minutes and contained code that harvested secrets—cloud credentials, SSH keys, Kubernetes tokens and database passwords—on systems that installed them. CloudSEK's dataset of roughly 434,000 files suggests over 2,100 organizations could be affected; admins should validate package sources, run dependency scans and rotate any exposed keys.
Rail police have deployed live facial recognition at Victoria station as privacy groups raise concerns about wider normalization. For MSPs and sysadmins this raises operational and security issues around data handling, retention, false-positive risk and GDPR compliance when integrating such surveillance into customer infrastructure.
SAP released fixes for CVE-2026-58231 affecting Commerce Cloud (Data Hub Adapter); the issue carries a CVSS score of 10.0. Due to inadequate authorization and input checks, unauthenticated actors could execute code remotely; managed service providers should apply patches immediately, restrict access and review logs.
Researcher Chaotic Eclipse released a PoC called ShieldBreak that reportedly bypasses fixes for CVE-2026-50656 (RoguePlanet) in Microsoft Defender and allows SYSTEM-level escalation. MSPs and sysadmins should immediately verify Defender updates, review configurations and detection rules, and monitor for exploitation attempts.
The "Plug and Pwn" attacks exploit Windows Plug and Play to cause automatic installation of vendor software when a device is connected, enabling attackers to escalate to SYSTEM. For admins this turns physical USB devices into a high-risk vector; restrict USB usage, enforce driver install policies, and deploy vendor fixes or blocking rules.
A vulnerability in Cisco Secure Firewall ASA and FTD, tracked as CVE-2026-20349 (CVSS 8.6), is being exploited in the wild; improper handling of HTTP requests can allow an unauthenticated remote attacker to trigger a denial-of-service. Administrators should apply Cisco patches immediately, restrict HTTP access to management interfaces and block risky traffic via network filters.
After Rapid7 published a PoC, attackers began using it to exploit a critical Microsoft SharePoint flaw. Server admins and MSPs should promptly apply patches or mitigations if available, monitor for suspicious activity and audit exposed SharePoint instances.
Signal introduced Automatic Key Verification to automate verification of encryption keys and help detect man-in-the-middle interception. For admins and MSPs this raises the importance of keeping clients updated and encouraging secure communication practices to ensure message integrity.
Threat actor Nightmare Eclipse released a new zero-day exploit called 'ShieldBreak' targeting Microsoft Defender that enables escalation to the Windows SYSTEM account. The disclosure followed Microsoft's August 2026 Patch Tuesday; MSPs and sysadmins should verify updates, monitor for exploitation and apply mitigations promptly.
Microsoft's monthly update fixes 398 vulnerabilities, including a kernel-level network driver flaw under active exploitation (CVE-2026-68820, CVSS 7.0). The bug can be used to escalate to SYSTEM when an attacker already has code execution on a host; MSPs and admins should prioritize this patch and tighten monitoring.
Discovered in February 2026 by Palo Alto Networks Unit 42, Kimwolf v7 is an updated Android/IoT botnet. It abuses HTTP/2 to make attack traffic resemble legitimate browser connections, complicating detection and mitigation of DDoS activity. MSPs and admins should pay closer attention to anomalous HTTP/2 flows and insecure IoT endpoints.
A vulnerability in Zoom's annotation feature used during screen sharing could allow a participant to take control of another attendee's machine, and vice versa between viewers and presenter. Because the issue worked without user interaction, MSPs and sysadmins should urgently apply Zoom patches, restrict annotations and tighten meeting access and endpoint controls.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.