Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Cloudflare for Government obtained FedRAMP High (Class D) approval and is preparing to pursue DoD IL4 authorization. That signals Cloudflare services now meet stricter federal controls, a key consideration for MSPs and sysadmins managing customers with U.S. government compliance requirements.
A developer used a hastily made, intended-as-temporary script that surfaced on LinkedIn before the project ended, triggering personal and corporate complications. For MSPs and sysadmins: quick fixes, poor secrets or access handling and lack of code hygiene can expose infrastructure and damage client trust.
LexisNexis took Diligence, Metabase API and Newsdesk offline after suspicious activity was detected on servers managed by an unnamed third-party vendor. The vendor has not been identified; outages can impact client data access and integrations. MSPs and sysadmins should review credentials, check logs and reassess third-party risk controls.
Valve has informed European Steam hardware customers that some customer data was stolen after a breach at shipping partner CEVA Logistics. For MSPs and sysadmins this underlines supply-chain exposure risks—review customer notifications, tighten access controls and monitoring, and be alert for phishing or account abuse.
CISA warned that attackers are actively exploiting a critical command-injection vulnerability in Progress Kemp LoadMaster. For MSPs and server admins this can enable remote code execution and appliance compromise; apply vendor patches immediately, isolate affected units, and review logs and credentials.
Ransomware groups are increasingly going after mid‑level IT managers in their 40s rather than CEOs, since those staff often hold critical access and can authorize payments. For MSPs and sysadmins this raises the need for strict privilege control, network segmentation, user training and an incident plan (disconnect affected hosts and notify law enforcement).
Atlassian's Rovo assistant can be induced to transmit Jira or Confluence content accessible to a signed-in user to a server controlled by attackers. Two security firms independently found different exploitation paths, and only one of those routes is confirmed closed. Administrators should review Rovo permissions, apply patches, and monitor outbound connections and logs.
Research finds that email content can escape message boundaries and interfere with webmail UIs across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail. The techniques can lead to credential and token theft, account takeover and manipulation of trusted UI elements and AI mail readers; operators should review isolation and mitigation settings.
Metabase has warned a critical zero-day in its BI and data-visualization software is being actively exploited. The flaw (CVSS 10.0) permits unauthenticated SQL injection into the application's database and can lead to administrator-level access; no CVE has been assigned yet. Administrators should isolate Metabase instances, limit access, monitor logs and apply patches as they are released.
N-able released Hotfix 2 for N-central to address active exploitation of a disclosed flaw. The company reports attackers have accessed managed environments and established persistence; MSPs and admins should apply the patch, follow mitigations and audit logs for indicators of compromise.
CISA added CVE-2026-8037, a critical CVSS 9.6 command injection flaw in Progress Kemp LoadMaster, to its KEV catalog after 792 reported exploit attempts. MSPs operating LoadMaster appliances should urgently apply vendor updates, restrict management-plane access, enforce network controls and monitor logs to limit exposure.
The Head Mare hacktivist group exploited unpatched TrueConf video conferencing servers to modify installer packages and implant backdoors. MSPs and sysadmins should patch servers, verify installer integrity, and scan endpoints to detect and remove unauthorized backdoor components.
OpenSourceMalware researcher Paul uncovered about 800 malicious npm packages that use AI‑generated or typo‑squatted names to deliver RATs and info‑stealers targeting Windows, macOS and Linux. The campaign increases supply‑chain risk for servers and customer environments; dependency scanning, lockfiles/allowlists and network/EDR monitoring should be prioritized.
Attackers are using ClickFix-style methods to deploy a Go-written macOS stealer that can drain crypto wallets and exfiltrate browser passwords, Apple iCloud Keychain entries and cached credentials. The infection runs a shell script to fingerprint the host and fetch a payload matched to the CPU architecture; MSPs and admins should monitor for unusual scripts, remote fetches and Keychain/browser access.
Extortion group UNC6671 is using vishing against employees in finance, private equity and professional services, calling personal phones to gain access to SaaS accounts. They impersonate IT support and urge supposed urgent security migrations to harvest credentials or bypass MFA; MSPs and admins should alert staff, require verification via official channels, and enforce strong MFA and monitoring.
A former NSA official warned — after attacks attributed to Iran — that water infrastructure controllers must not be directly exposed to the internet. For MSPs and sysadmins this underlines the need to review network segmentation, access controls and secure remote access for OT environments.
With attention concentrated on AI developments, ransomware incidents have risen. MSPs and sysadmins should prioritize patching, backups, monitoring, phishing defenses and tighten remote-access controls and incident response procedures.
A reflected pre-auth XSS in the WordPress login screen affecting all versions has been fixed (CVE-2026-64638, CVSS 8.9). pwn.ai demonstrated the issue can be chained with a logged-in admin action to achieve PHP code execution on the server. Apply the security update immediately to protect servers and client environments.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.