Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
N-able has confirmed that a 'god mode' privilege flaw in N-central was exploited and attackers accessed some customer networks. The vendor released a second hotfix and urges N-central users to apply it immediately. For MSPs this highlights the risk of a single management platform being used to pivot into client infrastructure.
ShinyHunters called a cancer diagnostics firm, tricked staff into giving access and leaked 10.9M email addresses along with personal and health data. MSPs and admins should urgently review social‑engineering defenses, access controls and incident response plans for customer data.
A use-after-free flaw in Linux's SCTP networking code dating back to 2008 can be exploited to break out of containers and obtain root on the host, researchers at Tencent report. Fixes published on Aug 3 are included in stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148; update any kernels that expose SCTP.
Researcher Malcolm Stagg revealed a new attack family called NatJack that tampers with NAT connection state to take over live TCP sessions, forge DNS replies, expose mapped ports and exhaust NAT tables. Demonstrated at Black Hat USA 2026 and observed across independent implementations including Windows; operators should patch devices, enable NAT logging and enforce connection limits.
MIT researchers demonstrated TONTOU, an attack that leverages timer interrupts to reopen opportunities for branch predictor poisoning, with a working proof-of-concept for Zen 2. This suggests some Spectre mitigations on Intel and AMD chips can be circumvented. System administrators should monitor vendor advisories and apply fixes.
A zero-day SQL injection in Metabase has been exploited to access and exfiltrate data from customer instances, with Framework and Tally reported affected. Admins and MSPs should urgently audit instances, rotate credentials, apply vendor fixes or mitigations, and review logs for indicators of compromise.
Researchers have identified an active phishing campaign that uses adversary-in-the-middle (AitM) tactics to hijack Microsoft 365 accounts and locate staff involved in payroll and finance to harvest related emails. Attackers employ residential proxies to mask malicious sign-ins as ordinary consumer traffic, increasing the risk of BEC and data exposure.
A Scottish NHS trust is investigating whether staff accessed the medical records of 9-year-old Minnie Merriman without authorization after she was publicly identified and a man was arrested on suspicion of murder. For MSPs and sysadmins: review access logs, enforce least-privilege and ensure alerting to protect patient data.
James Kettle's HTTP Terminator, an AI-assisted tool from PortSwigger, scanned tens of thousands of candidate desync vectors and produced validated new HTTP desynchronization methods. A separate human-led analysis chain revealed a zero-day in Apache Traffic Server; admins should review patching, traffic monitoring and WAF rules.
Healthcare software vendor Unlimited Technology Systems disclosed a data breach in October 2025 that affected more than 3.8 million people. MSPs and sysadmins should check whether client data was exposed, confirm regulatory notification obligations, and review access controls, backups, logging and incident response procedures.
Entra ID researcher Dirk-jan Mollema showed malware running in a signed-in Windows session can use a user's Windows Hello for Business key to authenticate to Microsoft Entra ID. An attacker could register a device, obtain a Primary Refresh Token (PRT) and add authentication methods, enabling longer-term cloud access and persistence—posing a notable risk for service providers and admins.
A GitHub issue created by an account without repo privileges could trigger code execution on CI runners for Anthropic's and Google's coding-agent repos and hijack the next agent run on OpenAI's repo. Novee Security tested default configurations and presented findings at Black Hat USA on August 5; administrators should review CI secrets and trigger settings.
An attacker used phishing to access a US defense supplier's Microsoft 365 account. The breach exposed engineering documents and possibly technical data subject to export controls. MSPs and sysadmins should focus on identity protections—MFA, conditional access and activity monitoring—to reduce impact and detect similar intrusions.
Cloudflare has moved bot mitigation from one-off risk checks to an ongoing trust assessment. Platforms like BotBase and Precursor continuously analyze behaviors to rate them as benign or malicious, and you can try Precursor Trace to see how cursor movements are classified. This provides more adaptive protection against bot activity for infrastructure serving customers.
An unauthorized access to Unlimited Technology Systems may have exposed names, Social Security numbers, medical diagnoses and insurance records for about 3.8 million individuals. The breach underscores the need for strict access controls, encryption and robust vendor risk and incident response practices for systems handling PHI/PII.
New analysis links TeamPCP to compromises of internet-facing infrastructure dating back to 2020, with the group later shifting focus to the software supply chain. Investigators identified technical overlaps such as shared domains and similar malware delivery and staging practices; MSPs and sysadmins should harden exposed services (notably Redis), audit supply-chain dependencies and strengthen telemetry and containment controls.
Levi Strauss & Co. reported attackers used social engineering on three employees to gain access to and steal corporate data from their machines. MSPs and system administrators should reassess endpoint defenses, MFA, phishing awareness training and incident response procedures.
A former Merseyside police officer was convicted under the Computer Misuse Act after using police IT systems to query records on acquaintances and was dismissed. The incident highlights insider risk and reinforces the need for tight access controls, comprehensive logging and staff-declaration processes for MSPs and sysadmins.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.