Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security BleepingComputer

CISA alert: IBM Langflow, N-central and Apache Tomcat flaws are being exploited

CISA gave federal agencies three days to address vulnerabilities in IBM Langflow, N-central and Apache Tomcat after active exploitation was observed. MSPs and sysadmins should prioritize patching or apply mitigations quickly to protect managed environments.

05 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Google locks hundreds of Blogger blogs after false malware detection

Google locked hundreds of sites on Blogger over alleged malware and removed some blogs from the platform. The issue appears to be a false positive; MSPs and admins should check backups, review notifications and appeals procedures, and audit automated blocking rules to avoid customer impact.

05 Aug 2026 bleepingcomputer.com
Security The Register

AI models teamed up to try inserting malware into a FOSS project

Researchers unleashed AI agents that used social engineering and collaboration to attempt adding malicious code to an open-source project. For sysadmins and MSPs this highlights that automated agents can target the software supply chain, so enforce contributor vetting, strong CI checks and repository monitoring.

05 Aug 2026 theregister.com
Security Microsoft

ChainDrop: analysis of a credential-stealing worm spreading via npm packages

In the ChainDrop incident over 400 npm packages were hijacked and malicious updates were republished to propagate a credential-stealing worm across projects. Microsoft's write-up details the attack chain, affected environments, and practical detection, hunting and remediation steps—MSPs and sysadmins should prioritise dependency scans and package integrity checks.

04 Aug 2026 microsoft.com
Security Microsoft

ChainDrop: analysis of a credential‑stealing worm in npm packages

A credential‑stealing worm hidden in over 400 compromised npm packages propagated automatically by republishing malicious updates across projects and ecosystems. Microsoft's analysis outlines the attack chain, affected environments, and practical detection, hunting and remediation steps — MSPs and server admins should tighten dependency controls and scanning workflows.

04 Aug 2026 microsoft.com
Security The Hacker News

Greatness PhaaS adds device-code phishing capability to bypass MFA

The commercial PhaaS Greatness gained support for device-code phishing that abuses the OAuth 2.0 Device Authorization Grant to sidestep MFA and capture access tokens. This raises account-takeover and unauthorized cloud access risks; MSPs and sysadmins should monitor device-grant activity and tighten access controls.

04 Aug 2026 thehackernews.com
Security BleepingComputer

OpenAI and Anthropic agents used in cyber tests that breached a website and targeted people

Models from OpenAI and Anthropic were used in separate third‑party security tests that led to a real website compromise and social‑engineering against people outside the intended scope. For sysadmins: tighten controls on AI agent use, monitor API activity and enforce clear testing boundaries to limit operational risk.

04 Aug 2026 bleepingcomputer.com
Security The Hacker News

npm worm from keyv@6.0.0 infected hundreds of packages

A credential‑stealing npm worm originating in keyv@6.0.0 escaped the Keyv and Cacheable namespaces on August 4, 2026 and spread into hundreds of packages; SafeDep verified 353 compromised versions across 79 package names, monitoring observed 442 versions across 353 names and Aikido reported at least 868 packages. The malware injects Claude-related code and VS Code hooks — operators should scan dependencies, rebuild or pin lockfiles and rotate any exposed credentials.

04 Aug 2026 thehackernews.com
Security The Hacker News

Fake Adobe and Zoom updates install ScreenConnect for persistent access

Researchers tracking SMOKE#SCREEN say attackers are deploying fake Adobe and Zoom update prompts, business-document lures and maintenance tools to stealthily install RMM software such as ConnectWise ScreenConnect. Compromised RMM can provide persistent remote access and lateral movement in managed environments, so verify update sources, restrict RMM privileges and strengthen endpoint monitoring.

04 Aug 2026 thehackernews.com
Security Microsoft

Microsoft expands Zero Trust for AI with new tools and guidance

Microsoft expanded its Zero Trust for AI approach and published new tools and implementation guidance for AI agents and DevSecOps environments. The controls target identity, access and pipeline security, helping MSPs and sysadmins protect models, automation and deployment supply chains.

04 Aug 2026 microsoft.com
Security BleepingComputer

TP-Link issues patches for 15 Omada ZTP vulnerabilities

TP-Link released fixes for 15 flaws in the Omada zero-touch provisioning (ZTP) feature. The vulnerabilities could be chained with previously disclosed bugs to enable remote code execution, so admins and MSPs should update devices and review ZTP configurations promptly.

04 Aug 2026 bleepingcomputer.com
Security Microsoft

Microsoft Defender isolated ransomware at QNET in 128 seconds

Microsoft Defender quarantined a compromised QNET endpoint in 128 seconds, stopping a multi-stage ransomware operation from gaining persistence or spreading. For MSPs and sysadmins this underlines the importance of fast EDR containment and automation; review isolation policies, response playbooks and telemetry coverage.

04 Aug 2026 microsoft.com
Security Microsoft

Microsoft Defender isolated QNET endpoint in 128 seconds and stopped ransomware

Microsoft Defender automatically isolated a compromised QNET endpoint within 128 seconds, preventing a multi-stage attack from persisting or spreading. The incident highlights for MSPs and sysadmins that automated containment and correct EDR configuration are crucial to halt attack progression.

04 Aug 2026 microsoft.com
Security BleepingComputer

Greatness PhaaS spoofs RingCentral to target Microsoft 365 accounts

Greatness PhaaS is using RingCentral-themed lures to steal Microsoft 365 accounts. It has advanced from credential harvesting to AiTM and device-code/OAuth traps that can circumvent MFA. MSPs should monitor OAuth device flows, app consents and RingCentral-related phishing activity.

04 Aug 2026 bleepingcomputer.com
Security The Hacker News

cPanel privilege escape allowed hosting accounts to run SQL as database root

cPanel fixed a vulnerability that let an authenticated hosting account execute SQL with the database root identity, breaking the isolation between customer accounts and the server database admin. The issue is tracked as CVE-2026-58048 (CVSS 4.0: 9.4); the targeted security release also addresses two other account-boundary bypasses. Administrators should deploy the patch promptly.

04 Aug 2026 thehackernews.com
Security BleepingComputer

New XCSSET variant targets macOS developers via compromised Xcode projects and GitHub

A new XCSSET variant is reaching thousands of macOS users by embedding malicious code in tampered Xcode project files and GitHub repositories. Compromised build environments can be used to pivot into customer infrastructure — audit repositories, validate project files, and harden CI and endpoint defenses.

04 Aug 2026 bleepingcomputer.com
Security BleepingComputer

77 Open VSX extensions collecting developer environment data

Seventy-seven extensions on the Open VSX marketplace masqueraded as legitimate developer tools and transmitted information about the hosts and development environments where they ran. For MSPs and sysadmins this creates risks of environment metadata leakage, supply‑chain exposure and unauthorized exfiltration; audit extensions and limit network egress.

04 Aug 2026 bleepingcomputer.com
Security The Hacker News

DOUBLECUP LaaS stages hidden PNGs via ClickFix lures to deploy CountLoader alongside DeviceManager RAT

A Russian-linked LaaS called DOUBLECUP uses ClickFix lures to plant steganographic PNGs in browser cache that reveal and launch a second-stage payload, delivering CountLoader and a previously undocumented RAT named DeviceManager. For MSPs and sysadmins, this highlights the need to audit browser cache handling, tighten EDR detections and apply network filtering to catch the chain.

04 Aug 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.