Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A Tennessee congressional candidate was arrested after allegedly shooting Flock license-plate cameras. The incident underscores the risk of physical attacks on LPR equipment for MSPs and sysadmins; review camera placement, tamper-detection, evidence logging and coordination with law enforcement.
CISA added CVE-2026-18577 (CVSS 8.2), a high-severity issue affecting N-able N-central, to its KEV list after reports of active exploitation and customer compromises. The flaw stems from incomplete remediation of CVE-2026-18556. MSPs running N-central should verify patch status and apply mitigations immediately.
ChainDrop, a self-propagating malware, has infected over 1,300 packages in the npm registry. The affected packages represent roughly 2 billion downloads per month, raising the risk that client projects will pull compromised dependencies; audit dependency trees, pin versions and monitor builds.
The UK is weighing rules that would require employers to get consent or provide notice before deploying worker surveillance tools like AI productivity scoring, keystroke logging and biometric tracking. For MSPs and sysadmins this may force changes to how monitoring agents are deployed, how data is handled and how client contracts document consent.
Researchers uncovered 18 npm packages that delivered a cross-platform remote access trojan (RAT) targeting users of Alibaba developer tools; the campaign appears to be a supply-chain operation aimed at Chinese-speaking environments. Attackers abused packages like 'lib-mtop' that clash with private Alibaba package names, underscoring the need for dependency audits, lockfile/registry controls and package scanning.
Malicious pull requests carrying prompt injection can be used against Google’s developer kit to make one automated agent influence or control another. For MSPs and sysadmins this raises supply-chain and CI/CD risks—harden repo review, agent permissions and automation safeguards.
Unit 42 described three attack paths against Chrome's Google Password Manager cloud authenticator. Malware running with normal user rights on Windows can authenticate to passkey-protected accounts without any prompt shown to the victim, and the strongest technique targets the master key.
Resecurity reports INC Ransomware has stepped up exploitation of vulnerabilities in SonicWall SMA 1000 VPN appliances since early August 2026 and has listed multiple victims on its leak site. MSPs and sysadmins should deploy vendor fixes, review SMA logs and access, and isolate any suspected compromised devices.
Microsoft links a global campaign against hotel and hospitality Wi‑Fi to the Russian group Midnight Blizzard (APT29). Attackers are using custom malware and techniques that intercept captive portals and network traffic to harvest Microsoft 365 credentials; enforcing MFA, conditional access and network segmentation is advised.
Researchers showed that malware on already-compromised Windows systems can abuse Google Password Manager synced passkeys to take over accounts, bypass user verification, and extract private keys. MSPs and admins should treat passkeys on compromised endpoints as at risk and strengthen endpoint security and access controls.
Censys observed a threat actor leveraging a leaked DarkSword toolkit and operating over 100 web properties, most of which are fake AWS sign-in pages hosted on the same domain as the toolkit. The campaign targets iOS devices; MSPs should review DNS/URL filtering, block malicious domains and enforce MDM and patch management.
The Russian DOUBLECUP loader-as-a-service uses a ClickFix technique to embed malicious code in PNG files stored in browser caches, enabling CountLoader on Windows and macOS and the DeviceManager RAT on Windows. This stealthy, browser-based infection route raises detection and containment challenges for MSPs and sysadmins; review cache handling and endpoint defenses.
Fake Xeno Executor installers are distributing malware that provides remote access and steals sensitive data from Roblox users. Compromised endpoints can be abused for credential theft, remote control and pivoting into customer environments, so MSPs should tighten endpoint defenses, patching and user awareness.
PNLD confirmed that names, organisations and work email addresses for police, government staff and some customers were exposed on the dark web; the incident was detected on July 26. Such data can enable targeted phishing and social engineering, so MSPs should review email defenses, MFA and customer contact handling.
An internal file with officials' contact details at a UK government investment arm was publicly accessible for about 40 hours. The exposure stemmed from a misconfiguration and staff error and could enable phishing, impersonation or other targeted social engineering attacks; check access controls, audits and configuration scans.
N-able reports that an authentication bypass vulnerability identified as CVE-2026-18577 is being actively exploited against both hosted and on-premises N-central servers. MSPs and sysadmins should promptly apply patches or temporary mitigations to reduce the risk of unauthorized access and takeover of managed systems.
ExfilSquad breached the Police National Legal Database (PNLD) and exposed contact details for more than 100,000 UK police officers and justice personnel. For providers this raises the risk of targeted phishing and social engineering; review access controls, notify affected parties and increase monitoring and incident response readiness.
A weakness in COLDCARD hardware wallet firmware produced predictable seeds that contributed to the theft of about $88.6 million in Bitcoin from thousands of wallets. For MSPs and sysadmins this underlines the need to validate hardware wallet entropy and firmware fixes, instruct customers to recreate seeds on secure devices, and monitor or block affected addresses.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.