Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
CERT-UA says UAC-0145, tied to Sandworm/APT44, has targeted Ukrainian IT staff with fabricated recruitment approaches to get them to install a malicious VPN. The VPN can execute remote commands, threatening servers and customer infrastructure; MSPs should verify recruitment contacts and tighten installation and VPN policies.
Signal introduced a verification feature to help confirm that the person you are messaging is the intended contact. The feature requires knowing the contact's phone number, so it can be limited if numbers change or are unknown; it's relevant for MSPs and admins aiming to reduce impersonation risk.
Researchers, aided by an AI agent, developed an exploit chain that allows attackers to take on any account, including administrators, and achieve unauthenticated remote code execution on SharePoint servers. The issue is CVE-2026-55040 (CVSS 9.1) affecting SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016; MSPs should prioritize patches and reduce public exposure.
The DeadLock group is running victim communications and leak operations on decentralized infrastructure, combining Session messaging with Polygon smart contracts to host extortion resources. This makes takedowns and evidence collection harder; MSPs and admins should monitor blockchain activity and review backups and incident communication procedures.
Microsoft released patches addressing at least 398 vulnerabilities in Windows and supported software. One flaw is already being actively exploited and two were publicly disclosed earlier; administrators should test and prioritize these updates, starting with the exploited and publicly detailed issues.
Google says Chrome’s abuse-detection systems blocked roughly 7 billion unwanted notifications per day on Android in Q1 2026. That reduces phishing/notification spam exposure and can lower support workload, but admins should still manage notification permissions, policies and keep Chrome updated.
OpenAI announced GPT‑5.6‑Cyber, a model tuned for vulnerability discovery, exploit-chain development and incident response. With loosened refusal constraints the risk of malicious use grows; MSPs and admins should tighten patching, network segmentation and monitoring to spot automated reconnaissance and exploit activity.
DeadLock is shifting its command, control and data-leak operations onto decentralized, blockchain-backed services to make takedown efforts harder. That lets attackers host C2 and leak sites in resilient, harder-to-block environments. MSPs and sysadmins should review backups, detection and incident response procedures.
A malicious SIM can instruct the cellular modem it sits in to execute attacker commands. Tests by University of Birmingham and security firm Fuzzware show that exploiting modems in devices such as EV chargers, industrial routers and vehicle telematics can enable device takeover. That raises the risk of remote compromise and lateral movement in customer networks.
Mozilla revoked the signing key used to validate Linux packages for Firefox and Thunderbird after an unencrypted copy was accidentally committed to an internal repository. The revocation can disrupt package signature checks and distro packaging; admins should pause automated installs, obtain the replacement key from Mozilla, and update verification and trust settings.
Russia-linked Sandworm has been using fake job postings to deliver a trojanized WireGuard VPN client to IT administrators. The malware can provide remote access and harvest credentials; MSPs and sysadmins should limit installs to official sources, verify signatures and strengthen endpoint detection.
Security researchers set up a mock crypto startup, posted developer openings and onboarded three hires believed to have ties to North Korea. The issued virtual machines logged activity, and the onboarding paperwork revealed details about candidate verification. MSPs and sysadmins should strengthen ID and bank-account checks.
Researchers demonstrated an abuse of Windows Plug and Play to retrieve signed vendor software for an emulated USB device, execute privileged installer components and escalate to SYSTEM on fully patched Windows 11. The same path can be activated over RDP when low-level USB or PnP redirection is allowed, so admins and MSPs should review remote USB and device installation policies.
A malicious tool server connected via MCP can make AI coding assistants leak SSH keys, environment secrets, source code and customer data by breaking instructions into benign-looking fragments. For MSPs and sysadmins this raises the need to vet third-party tool servers, isolate and rotate secrets, and monitor egress to detect stealthy exfiltration.
South Korean and U.S. cyber agencies warn that Gunra ransomware is exploiting vulnerabilities in Fortinet's FortiOS and FortiProxy to compromise organizations in healthcare, finance, government and service sectors. MSPs should prioritize patching, restrict remote access and review logs for signs of compromise.
Spanish police identified a suspect after a face-swap deepfake used in identity checks showed a brief glitch. For sysadmins and MSPs this highlights the risk deepfakes pose to remote ID and certificate issuance processes and underscores the need for stronger liveness checks and tighter certificate audit controls.
Mozilla discovered an unencrypted copy of a Firefox signing key on GitHub and revoked the affected key. Audit logs showed no unexpected access, but the event exposes weaknesses in release verification processes. MSPs and admins should review key rotation, signing workflows and verification controls.
Cloudflare recorded a 519% rise in hyper‑volumetric DDoS activity in H1 2026, with many incidents powered by reflections via DNS and CLDAP and some attacks approaching 1 Tbps. Geopolitical tensions altered attacker patterns; MSPs and sysadmins should reassess bandwidth planning, filtering and anti-reflection controls.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.