Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Attackers accessed a private cellular network used by the local grid operator to reach remote devices and disabled a steam turbine and the process-water treatment system at a combined heat and power plant serving about 50,000 residents. Recovery began around 7:30 a.m. while intruders were still active, and customers did not lose heat. The incident highlights the need to harden OT access, segment cellular links and monitor remote connectivity.
Researchers uncovered a supply-chain compromise affecting BdThemes, prompting the WordPress plugins team to pause downloads temporarily. Attackers manipulated distribution metadata (JSON) rather than altering repository source files to inject rogue administrator accounts. MSPs and sysadmins should audit affected plugins, look for unknown admin users, verify package integrity and rotate credentials.
CISA has confirmed that a high-severity Microsoft SharePoint remote code execution flaw has been actively used by ransomware actors since early July. Providers and sysadmins should urgently apply patches or mitigations, tighten access to SharePoint hosts, segment them on the network, and monitor logs and unusual processes to limit exposure.
Cisco reported two high-severity flaws in Secure Endpoint Connector that affect ClamAV; public exploits can be used to crash the scanner and cause denial-of-service. Server admins and MSPs should verify patches and apply mitigations on affected endpoints promptly.
US federal agencies and South Korea's National Police Agency have issued global alerts about Gunra ransomware focusing on government and critical infrastructure. For IT teams: apply patches, verify and isolate backups, enforce network segmentation, strengthen endpoint and log monitoring, and implement the detection indicators and guidance from the agencies.
The Franklin project born from DEF CON is bringing additional security vendors on board and applying digital modeling together with artificial intelligence to reinforce water utility defenses. For MSPs and sysadmins this raises the need to adapt OT risk assessments, monitoring and incident response to new simulation and detection tools.
AI tools can lead to 10–50× more code output, increasing pressure on teams that must find vulnerabilities, handle dependencies and prioritize fixes. The webinar discusses practical strategies to scale security practices so reviews don't become a release bottleneck and you keep control over what ships.
Microsoft has observed Storm-1175 using a previously unseen ransomware called StormEncryptor. The malware is implemented in C++, tags encrypted files with .encrypted and marks a shift from the group's prior use of Medusa; MSPs should prioritize N-central patches, endpoint monitoring and backup validation.
The Hacker News summarizes this week’s incidents: unexpected AI behavior, a Metabase 0-day, MCP supply-chain attacks, and router backdoors. Short exploitation paths and default configurations mean MSPs and sysadmins should prioritize audits, patching and tightening deployments.
Attackers accessed the OT network of a small Polish plant that supplies heat to about 50,000 people by abusing a private APN. The case underscores the need to secure remote access, review APN settings, enforce network segmentation and deploy monitoring—items MSPs and sysadmins should reassess.
South Korean security firm Genians reports that North Korea's Kimsuky is running local AI models on its own servers and linking document-search tools to captured files. The group is embedding AI components into malware to automate spear-phishing and payload creation, making detection and response more difficult.
An attacker compromised BdThemes' upstream infrastructure and altered a JSON endpoint that administrators' browsers request to insert rogue admin accounts. Sites using BdThemes components risk unauthorized admin access and data exposure; immediately audit user accounts, plugin updates and revoke sessions/keys for affected customers.
Microsoft was named a Leader in the 2026 IDC MarketScape for enterprise MDR/MXDR. The assessment highlights Microsoft Defender Experts MDR's mix of AI, threat intelligence and human analysts; this can influence MSPs' and sysadmins' procurement and operational decisions.
IDC MarketScape placed Microsoft as a leader for enterprise MDR/MXDR in 2026. The report highlights Microsoft Defender Experts MDR's use of AI, threat intelligence and human analysts for detection and response—information relevant when choosing an MDR provider for managed environments.
OpenAI unveiled GPT 5.6 Cyber, a model aimed at discovering and assessing security flaws, running penetration tests, and assisting incident handling and remediation. Access is limited to approved users, so MSPs and sysadmins should watch availability and plan controls to manage integration and prevent misuse.
Microsoft analyzed the DeadLock ransomware; the operation uses a Rust-based encryptor and employs decentralized infrastructure for victim communications, negotiations and data-leak operations. Its double-extortion method — encrypting data while threatening publication — makes incident response, negotiations and recovery planning harder for MSPs and administrators.
Microsoft Threat Intelligence examined DeadLock, a new financially motivated ransomware. The operation uses decentralized services to manage victim contact, negotiations and data leaks while performing double extortion; MSPs and sysadmins should prioritise detection of Rust-built binaries, network indicators, and reliable backups and incident response.
Researchers identified malicious VS Code extensions helper-beeps.solidity-pro and web3devtoolsx.solidity-pro that install a browser wallet and exfiltrate API keys and credentials. Admins and MSPs should scan developer workstations, remove these extensions, and rotate any potentially compromised keys or tokens.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.