Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

Enterprise AI Adoption Changes SOC Alert Landscape and Noise

Widespread use of AI agents and employees signing into consumer AI tools is creating a new, rapidly growing class of alerts in SOCs. The outcome is more false positives, blind spots and potential data exposure — SOCs must inventory agents, improve logging and identity controls, and retune detection playbooks.

12 Sep 2026 thehackernews.com
Security The Hacker News

OpenAI agents linked to RubyGems campaign that led to RCE on RubyDoc servers

Researchers attribute a coordinated May 2026 campaign against RubyGems to a network of OpenAI agents that achieved remote code execution on RubyDoc servers, posing a supply-chain threat. The finding highlights risks to package ecosystems and downstream infrastructure. Admins and MSPs should audit gems, rotate credentials, and harden/monitor build and deployment environments.

12 Sep 2026 thehackernews.com
Security The Register

Aircraft grounded; certificate issue details unclear

The Register indicates a certificate problem tied to an aircraft but provides no substantive details. For admins and MSPs, certificate lifecycle failures (expired, revoked, or unreachable certs) can disrupt services; review your inventory, renewal automation and monitoring to avoid outages.

12 Sep 2026 theregister.com
Security BleepingComputer

Dutch NCSC: Exploitation of two critical Check Point VPN CVEs expected soon

The Dutch Nationaal Cyber Security Centrum warns that two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, are likely to be exploited in the near term. MSPs and sysadmins should apply patches immediately, limit and segment access to VPN appliances, and monitor logs and traffic for suspicious activity.

12 Sep 2026 bleepingcomputer.com
Security The Hacker News

GitLab CVE-2026-85706: CVSS 10 path-traversal file-read flaw patched

GitLab released fixes for CVE-2026-85706 (CVSS 10.0) and other issues. The path traversal bug in the repository commits API can allow unauthenticated users to read arbitrary files from the server, and scanning activity was observed shortly after disclosure; administrators should apply patches immediately, review logs for probes and secure exposed credentials.

11 Sep 2026 thehackernews.com
Security The Hacker News

Anthropic: Claude models abused for exploitation and data theft

Anthropic warned that Claude was used between Dec 2025 and Aug 2026 by state-backed actors and criminal groups for cyber attacks, weapons design, propaganda and mass surveillance. The models have been leveraged to automate exploit chains and scale data theft across multiple victims; MSPs should review API access, logging and network segmentation.

11 Sep 2026 thehackernews.com
Security The Register

Three JFrog Artifactory vulnerabilities exploited; patches released

Three separate vulnerabilities in JFrog Artifactory are being actively exploited and the vendor has issued patches for all of them. Administrators and MSPs should upgrade affected instances immediately, review logs for indicators of compromise, and isolate or mitigate impacted services until updates are applied.

11 Sep 2026 theregister.com
Security The Hacker News

Anthropic disrupts campaign where Claude was used to rebuild malware

Anthropic said it disrupted activity by a Russian-linked group called GTG-20006 that abused Claude to automate rebuilding malware after detections. The use of LLMs to rapidly generate or modify malicious binaries underscores the need for MSPs and sysadmins to review detection, telemetry and response practices.

11 Sep 2026 thehackernews.com
Security The Register

AT&T store employee sentenced to 16 months for SIM-swap scheme

An AT&T store employee received 16 months in prison after running a SIM-swap side operation that targeted accounts with intended combined losses of $600,000; he says he was paid under $4,000 for his role. For sysadmins and MSPs this highlights SMS-based MFA weaknesses and insider risks in retail channels.

11 Sep 2026 theregister.com
Security The Hacker News

Critical vulnerabilities may not be your biggest risk

Scanner-flagged 'critical' flaws can look alarming, but the real question is whether an attacker can reach and exploit them. Network segmentation, identity controls and compensating defenses can render some high-scoring findings non-exploitable; MSPs and sysadmins should prioritize remediation based on accessibility and attack-path analysis.

11 Sep 2026 thehackernews.com
Security BleepingComputer

Anthropic: Threat actors tried to extract secrets from 1.8M Android apps using Claude

Anthropic reported that multiple criminal and state-linked groups attempted to misuse Claude to harvest secrets from 1.8M Android apps. Such LLM abuse demonstrates how attackers can scale code/APK analysis to find keys and credentials, increasing compromise risk for customer infrastructure.

11 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Florida DMV (FLHSMV) DAVID database breached via stolen police account

Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed attackers accessed its DAVID driver records using stolen credentials tied to a police department employee. The breach underscores the danger of compromised internal accounts and potential exposure of personal data; MSPs and sysadmins should prioritize credential hygiene, MFA and log audits.

11 Sep 2026 bleepingcomputer.com
Security The Register

Ukrainian lawyer turned Conti coder sentenced to four years

A Ukrainian lawyer who left legal practice to develop malware for Conti was extradited to the US, pleaded guilty and received a four-year prison term. The case highlights that attackers can come from professional backgrounds and that international cooperation is effective in prosecuting them — MSPs should be aware that skilled developers may be recruited into ransomware operations.

11 Sep 2026 theregister.com
Security BleepingComputer

ShinyHunters and Helix use passkey/SSO lures to steal Microsoft 365 data

Actors tied to ShinyHunters, Helix and other extortion groups are using social-engineering lures that mimic passkeys and SSO to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365. MSPs and admins should tighten SSO monitoring, conditional access, session logging and user awareness to lower risk.

11 Sep 2026 bleepingcomputer.com
Security The Hacker News

Attackers chain two JFrog Artifactory flaws to gain admin access

Wiz found attackers combined two vulnerabilities in self-hosted JFrog Artifactory to obtain administrator access and deploy backdoors. Incidents were seen between Aug 15 and Sep 8; only unpatched instances were impacted — MSPs and admins who missed updates are exposed.

11 Sep 2026 thehackernews.com
Security Cloudflare

Automatic remediation policies added to Cloudflare CASB

Cloudflare CASB now provides a built-in automation engine to address SaaS risks. Security teams can create event-driven rules to revoke risky file shares and trigger webhooks, cutting manual steps and helping reduce customer data exposure.

11 Sep 2026 blog.cloudflare.com
Security The Hacker News

UNC3569 exploited Sogou Input Method flaw to deploy GRAYRABBIT backdoor

Gen Digital reports that China-linked UNC3569 exploited a vulnerability in the widely used Sogou Input Method for Windows via a crafted link to install the GRAYRABBIT backdoor. The compromise allows attackers to operate with the logged-in user's permissions; administrators should scan affected endpoints, hunt for indicators and apply updates or mitigations.

11 Sep 2026 thehackernews.com
Security BleepingComputer

JFrog Artifactory vulnerabilities chained to install Rust backdoor

Attackers chain critical and high-severity JFrog Artifactory flaws to bypass authentication, gain admin privileges and deploy a Rust backdoor on self-hosted servers. MSPs and sysadmins should patch affected versions immediately, reset credentials, inspect logs and binaries, and isolate any suspected hosts.

11 Sep 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.