Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Register

Tennessee congressional candidate arrested over alleged shooting of plate cameras

A Tennessee congressional candidate was arrested after allegedly shooting Flock license-plate cameras. The incident underscores the risk of physical attacks on LPR equipment for MSPs and sysadmins; review camera placement, tamper-detection, evidence logging and coordination with law enforcement.

04 Aug 2026 theregister.com
Security The Hacker News

CISA adds N-able N-central flaw CVE-2026-18577 to KEV

CISA added CVE-2026-18577 (CVSS 8.2), a high-severity issue affecting N-able N-central, to its KEV list after reports of active exploitation and customer compromises. The flaw stems from incomplete remediation of CVE-2026-18556. MSPs running N-central should verify patch status and apply mitigations immediately.

04 Aug 2026 thehackernews.com
Security BleepingComputer

ChainDrop supply-chain attack impacts 1,300+ npm packages

ChainDrop, a self-propagating malware, has infected over 1,300 packages in the npm registry. The affected packages represent roughly 2 billion downloads per month, raising the risk that client projects will pull compromised dependencies; audit dependency trees, pin versions and monitor builds.

04 Aug 2026 bleepingcomputer.com
Security The Register

UK considers requiring consent before installing bossware

The UK is weighing rules that would require employers to get consent or provide notice before deploying worker surveillance tools like AI productivity scoring, keystroke logging and biometric tracking. For MSPs and sysadmins this may force changes to how monitoring agents are deployed, how data is handled and how client contracts document consent.

04 Aug 2026 theregister.com
Security The Hacker News

18 malicious npm packages deliver cross-platform RAT to Alibaba tool users

Researchers uncovered 18 npm packages that delivered a cross-platform remote access trojan (RAT) targeting users of Alibaba developer tools; the campaign appears to be a supply-chain operation aimed at Chinese-speaking environments. Attackers abused packages like 'lib-mtop' that clash with private Alibaba package names, underscoring the need for dependency audits, lockfile/registry controls and package scanning.

04 Aug 2026 thehackernews.com
Security The Register

Google dev kit: risk of agents taking control of other agents

Malicious pull requests carrying prompt injection can be used against Google’s developer kit to make one automated agent influence or control another. For MSPs and sysadmins this raises supply-chain and CI/CD risks—harden repo review, agent permissions and automation safeguards.

03 Aug 2026 theregister.com
Security The Hacker News

Google Password Manager: malware on Windows can sign into passkey accounts

Unit 42 described three attack paths against Chrome's Google Password Manager cloud authenticator. Malware running with normal user rights on Windows can authenticate to passkey-protected accounts without any prompt shown to the victim, and the strongest technique targets the master key.

03 Aug 2026 thehackernews.com
Security The Hacker News

INC Ransomware exploits SonicWall SMA 1000 vulnerabilities at scale

Resecurity reports INC Ransomware has stepped up exploitation of vulnerabilities in SonicWall SMA 1000 VPN appliances since early August 2026 and has listed multiple victims on its leak site. MSPs and sysadmins should deploy vendor fixes, review SMA logs and access, and isolate any suspected compromised devices.

03 Aug 2026 thehackernews.com
Security BleepingComputer

Hotel Wi‑Fi attacks use custom malware to target Microsoft 365 accounts

Microsoft links a global campaign against hotel and hospitality Wi‑Fi to the Russian group Midnight Blizzard (APT29). Attackers are using custom malware and techniques that intercept captive portals and network traffic to harvest Microsoft 365 credentials; enforcing MFA, conditional access and network segmentation is advised.

03 Aug 2026 bleepingcomputer.com
Security BleepingComputer

New Pass-ta-key attacks can hijack Google-synced passkeys

Researchers showed that malware on already-compromised Windows systems can abuse Google Password Manager synced passkeys to take over accounts, bypass user verification, and extract private keys. MSPs and admins should treat passkeys on compromised endpoints as at risk and strengthen endpoint security and access controls.

03 Aug 2026 bleepingcomputer.com
Security The Hacker News

Chinese-linked actor uses DarkSword kit to deploy GHOSTBLADE on iOS

Censys observed a threat actor leveraging a leaked DarkSword toolkit and operating over 100 web properties, most of which are fake AWS sign-in pages hosted on the same domain as the toolkit. The campaign targets iOS devices; MSPs should review DNS/URL filtering, block malicious domains and enforce MDM and patch management.

03 Aug 2026 thehackernews.com
Security BleepingComputer

DOUBLECUP hides malware in browser-cached PNGs via ClickFix

The Russian DOUBLECUP loader-as-a-service uses a ClickFix technique to embed malicious code in PNG files stored in browser caches, enabling CountLoader on Windows and macOS and the DeviceManager RAT on Windows. This stealthy, browser-based infection route raises detection and containment challenges for MSPs and sysadmins; review cache handling and endpoint defenses.

03 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Fake Xeno Executor installers deliver infostealer and RAT to Roblox users

Fake Xeno Executor installers are distributing malware that provides remote access and steals sensitive data from Roblox users. Compromised endpoints can be abused for credential theft, remote control and pivoting into customer environments, so MSPs should tighten endpoint defenses, patching and user awareness.

03 Aug 2026 bleepingcomputer.com
Security The Hacker News

PNLD leak: U.K. police and government contacts found on dark web

PNLD confirmed that names, organisations and work email addresses for police, government staff and some customers were exposed on the dark web; the incident was detected on July 26. Such data can enable targeted phishing and social engineering, so MSPs should review email defenses, MFA and customer contact handling.

03 Aug 2026 thehackernews.com
Security The Register

UK government investment arm left officials' contact list accessible for 40 hours

An internal file with officials' contact details at a UK government investment arm was publicly accessible for about 40 hours. The exposure stemmed from a misconfiguration and staff error and could enable phishing, impersonation or other targeted social engineering attacks; check access controls, audits and configuration scans.

03 Aug 2026 theregister.com
Security BleepingComputer

N-able warns of CVE-2026-18577 auth bypass affecting N-central

N-able reports that an authentication bypass vulnerability identified as CVE-2026-18577 is being actively exploited against both hosted and on-premises N-central servers. MSPs and sysadmins should promptly apply patches or temporary mitigations to reduce the risk of unauthorized access and takeover of managed systems.

03 Aug 2026 bleepingcomputer.com
Security BleepingComputer

ExfilSquad leaks contact data of over 100,000 UK police and staff from PNLD

ExfilSquad breached the Police National Legal Database (PNLD) and exposed contact details for more than 100,000 UK police officers and justice personnel. For providers this raises the risk of targeted phishing and social engineering; review access controls, notify affected parties and increase monitoring and incident response readiness.

03 Aug 2026 bleepingcomputer.com
Security BleepingComputer

RNG flaw in COLDCARD wallet linked to $88.6 million Bitcoin theft

A weakness in COLDCARD hardware wallet firmware produced predictable seeds that contributed to the theft of about $88.6 million in Bitcoin from thousands of wallets. For MSPs and sysadmins this underlines the need to validate hardware wallet entropy and firmware fixes, instruct customers to recreate seeds on secure devices, and monitor or block affected addresses.

02 Aug 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.