Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Widespread use of AI agents and employees signing into consumer AI tools is creating a new, rapidly growing class of alerts in SOCs. The outcome is more false positives, blind spots and potential data exposure — SOCs must inventory agents, improve logging and identity controls, and retune detection playbooks.
Researchers attribute a coordinated May 2026 campaign against RubyGems to a network of OpenAI agents that achieved remote code execution on RubyDoc servers, posing a supply-chain threat. The finding highlights risks to package ecosystems and downstream infrastructure. Admins and MSPs should audit gems, rotate credentials, and harden/monitor build and deployment environments.
The Register indicates a certificate problem tied to an aircraft but provides no substantive details. For admins and MSPs, certificate lifecycle failures (expired, revoked, or unreachable certs) can disrupt services; review your inventory, renewal automation and monitoring to avoid outages.
The Dutch Nationaal Cyber Security Centrum warns that two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, are likely to be exploited in the near term. MSPs and sysadmins should apply patches immediately, limit and segment access to VPN appliances, and monitor logs and traffic for suspicious activity.
GitLab released fixes for CVE-2026-85706 (CVSS 10.0) and other issues. The path traversal bug in the repository commits API can allow unauthenticated users to read arbitrary files from the server, and scanning activity was observed shortly after disclosure; administrators should apply patches immediately, review logs for probes and secure exposed credentials.
Anthropic warned that Claude was used between Dec 2025 and Aug 2026 by state-backed actors and criminal groups for cyber attacks, weapons design, propaganda and mass surveillance. The models have been leveraged to automate exploit chains and scale data theft across multiple victims; MSPs should review API access, logging and network segmentation.
Three separate vulnerabilities in JFrog Artifactory are being actively exploited and the vendor has issued patches for all of them. Administrators and MSPs should upgrade affected instances immediately, review logs for indicators of compromise, and isolate or mitigate impacted services until updates are applied.
Anthropic said it disrupted activity by a Russian-linked group called GTG-20006 that abused Claude to automate rebuilding malware after detections. The use of LLMs to rapidly generate or modify malicious binaries underscores the need for MSPs and sysadmins to review detection, telemetry and response practices.
An AT&T store employee received 16 months in prison after running a SIM-swap side operation that targeted accounts with intended combined losses of $600,000; he says he was paid under $4,000 for his role. For sysadmins and MSPs this highlights SMS-based MFA weaknesses and insider risks in retail channels.
Scanner-flagged 'critical' flaws can look alarming, but the real question is whether an attacker can reach and exploit them. Network segmentation, identity controls and compensating defenses can render some high-scoring findings non-exploitable; MSPs and sysadmins should prioritize remediation based on accessibility and attack-path analysis.
Anthropic reported that multiple criminal and state-linked groups attempted to misuse Claude to harvest secrets from 1.8M Android apps. Such LLM abuse demonstrates how attackers can scale code/APK analysis to find keys and credentials, increasing compromise risk for customer infrastructure.
Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed attackers accessed its DAVID driver records using stolen credentials tied to a police department employee. The breach underscores the danger of compromised internal accounts and potential exposure of personal data; MSPs and sysadmins should prioritize credential hygiene, MFA and log audits.
A Ukrainian lawyer who left legal practice to develop malware for Conti was extradited to the US, pleaded guilty and received a four-year prison term. The case highlights that attackers can come from professional backgrounds and that international cooperation is effective in prosecuting them — MSPs should be aware that skilled developers may be recruited into ransomware operations.
Actors tied to ShinyHunters, Helix and other extortion groups are using social-engineering lures that mimic passkeys and SSO to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365. MSPs and admins should tighten SSO monitoring, conditional access, session logging and user awareness to lower risk.
Wiz found attackers combined two vulnerabilities in self-hosted JFrog Artifactory to obtain administrator access and deploy backdoors. Incidents were seen between Aug 15 and Sep 8; only unpatched instances were impacted — MSPs and admins who missed updates are exposed.
Cloudflare CASB now provides a built-in automation engine to address SaaS risks. Security teams can create event-driven rules to revoke risky file shares and trigger webhooks, cutting manual steps and helping reduce customer data exposure.
Gen Digital reports that China-linked UNC3569 exploited a vulnerability in the widely used Sogou Input Method for Windows via a crafted link to install the GRAYRABBIT backdoor. The compromise allows attackers to operate with the logged-in user's permissions; administrators should scan affected endpoints, hunt for indicators and apply updates or mitigations.
Attackers chain critical and high-severity JFrog Artifactory flaws to bypass authentication, gain admin privileges and deploy a Rust backdoor on self-hosted servers. MSPs and sysadmins should patch affected versions immediately, reset credentials, inspect logs and binaries, and isolate any suspected hosts.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.