Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security BleepingComputer

Chrome may block policy-installed extensions from changing new tab and search

Google is developing a Chrome security control that by default will stop extensions installed via enterprise policy from altering the browser's new tab page or default search engine. This will limit unwanted redirects in managed environments; MSPs and system administrators should review centrally deployed extensions and policy configurations for compatibility.

02 Aug 2026 bleepingcomputer.com
Security The Hacker News

Coldcard firmware flaw led to theft of 1,082.65 BTC (~$70M)

On July 30 an attacker emptied 1,196 Bitcoin addresses in 41 minutes, stealing 1,082.65 BTC (~$70.2M). Galaxy Research linked the sweep to a firmware integration mistake in Coldcard (Coinkite) that, after a March 2021 change, caused seed generation to rely on a predictable software PRNG. Firmware integrity and key-generation trust in custody devices are now a critical concern for admins and MSPs.

01 Aug 2026 thehackernews.com
Security The Hacker News

Adform ad script tampered with — crypto wallet addresses targeted

A JavaScript ad file served by Adform was altered to run in visitors' browsers and change cryptocurrency wallet addresses. Adform discovered the incident on July 27, removed the injected code, informed affected customers and reported the case to authorities. MSPs and admins should audit third‑party ad tags and review traffic from that date.

01 Aug 2026 thehackernews.com
Security The Hacker News

CVE-2026-48449 in Adobe Campaign Classic: CVSS 10.0 remote code risk

A critical authorization flaw in Adobe Campaign Classic (CVE-2026-48449) has been reported with a CVSS score of 10.0. The bug can allow attackers to execute arbitrary code without user interaction, posing a serious threat to on-prem deployments and customer data. Admins and MSPs should apply Adobe's updates immediately and review access and monitoring controls.

01 Aug 2026 thehackernews.com
Security The Hacker News

Hijacked hotel Wi‑Fi used to push fake update delivering CornFlake RAT

Microsoft says attackers abused compromised hotel wireless to serve a bogus browser update that installed CornFlake, a RAT able to access webcams, microphones and log keystrokes. Researchers track the campaign as CaptiveCrunch and link it to Storm‑2945, tied to Midnight Blizzard. MSPs should harden guest Wi‑Fi, monitor captive portals and strengthen endpoint defenses.

01 Aug 2026 thehackernews.com
Security BleepingComputer

Critical Active Storage flaw in Rails allows unauthenticated file read and potential RCE

A flaw in Active Storage lets unauthenticated actors read files from a Rails app and can, in certain scenarios, escalate to remote code execution. Admins and MSPs should deploy the Rails patch quickly, tighten file access controls, and limit how uploaded content is processed to reduce risk.

01 Aug 2026 bleepingcomputer.com
Security The Hacker News

Chinese-speaking actor targets Central Asian governments with OctLurk and SilkLurk

A Chinese-speaking threat actor has conducted attacks since January 2025 against government and public organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The intrusions are linked to OctLurk and SilkLurk toolsets; MSPs and sysadmins should review detection, network segmentation and incident response preparedness.

01 Aug 2026 thehackernews.com
Security The Hacker News

HollowFrame and Matryoshka used in spear-phishing attack on law firm

Blackpoint Cyber researchers uncovered a campaign using the Go-based HollowFrame loader and Rust-based Matryoshka malware against a law firm. The attack starts from a link to an encrypted archive that contains a Windows LNK; executing it launches a multi-stage infection chain. Admins should tighten email filtering, restrict LNK execution and reinforce EDR and monitoring.

31 Jul 2026 thehackernews.com
Security Microsoft

CaptiveCrunch: Midnight Blizzard (Storm-2945) targets hotel sign-in portals since May 2026

A sub-cluster of Russian actor Midnight Blizzard, Storm-2945, has been compromising hospitality sign-in portals since May 2026 to push malware to travelers and harvest credentials. MSPs and sysadmins should verify portal integrity, enforce MFA and WAF protections, and increase logging and endpoint defenses.

31 Jul 2026 microsoft.com
Security Microsoft

CaptiveCrunch: Midnight Blizzard targets hotel login portals

Since May 2026, Storm-2945, a Midnight Blizzard sub-cluster, has been compromising hotel and hospitality login portals to infect guest devices with malware and harvest credentials. MSPs and sysadmins should audit captive portal security, enforce MFA, segment networks, strengthen endpoint defenses and monitor access logs while tracking related threat intelligence.

31 Jul 2026 microsoft.com
Security The Hacker News

Cheap Android TV boxes fake phone identities and convert owners' broadband to proxy exits

Bitsight says some low-cost Android TV boxes include apps that alter device identity to impersonate Samsung, Huawei, Xiaomi or Vivo phones and click ads on sites run by the same operators; researchers named the campaign Fuyao and tied it to Zhejiang Fengwo IoT Technology Co., Ltd. The same apps also turn boxes into outbound proxy exits using owners' broadband, creating bandwidth, IP reputation and abuse risks for MSPs and admins.

31 Jul 2026 thehackernews.com
Security The Register

Well-known physical security brand breached by ShinyHunters

Threat actor ShinyHunters accessed the SaaS environment of a prominent physical security vendor. MSPs and sysadmins should assume integrations, API keys and credentials may be exposed; review access controls, rotate credentials and enable monitoring for suspicious activity.

31 Jul 2026 theregister.com
Security The Hacker News

Thousands of security flaws fixed in Chrome 149–151

Google patched 1,072 security issues across Chrome 149 and 150, a total that exceeds the fixes in the prior 23 releases combined. The subsequent Chrome 151 update fixed another 370 bugs, 349 of which were reported by Google itself. MSPs and sysadmins should prioritize testing and deploying these updates promptly.

31 Jul 2026 thehackernews.com
Security BleepingComputer

Amgen: breach in third‑party cloud providers exposed patient and corporate data

Amgen reported that attackers accessed corporate and patient data across multiple cloud environments managed by external providers. For MSPs and sysadmins, such supplier-side breaches underline the need to review vendor security, encryption, access governance, logging and incident response for customer-hosted data.

31 Jul 2026 bleepingcomputer.com
Security The Register

US bank trusted ransomware group that promised to delete its data

A US bank relied on a ransomware group that claimed it would delete stolen data; trusting such promises is risky. For sysadmins and MSPs this highlights the need for robust backups, protections against data exfiltration, forensic preservation and timely regulatory or law enforcement engagement.

31 Jul 2026 theregister.com
Security BleepingComputer

Arch Linux halts AUR package adoptions after rise in malicious takeovers

Arch Linux has paused allowing others to adopt AUR packages following a rise in incidents where attackers took over package maintainership. MSPs and sysadmins should treat AUR as a higher supply-chain risk and verify maintainers, signatures and update provenance before deploying AUR-sourced software.

31 Jul 2026 bleepingcomputer.com
Security The Hacker News

Researchers at Nanyang report 84 flaws in 4G/5G cores, session hijack risk

Researchers at Nanyang Technological University in Singapore found 84 vulnerabilities in 4G/5G core infrastructure. Several issues could cause denial-of-service or allow attackers to hijack user sessions, creating direct risks for operators and MSPs responsible for customer connectivity and core systems.

31 Jul 2026 thehackernews.com
Security BleepingComputer

Adform ad script compromised to replace copied crypto wallet addresses

A malicious script injected into Adform's ad code modified wallet addresses copied to users' clipboards, substituting attacker-controlled addresses. Sites running Adform could expose users' crypto to theft; managed service providers and sysadmins should treat third-party ad scripts as a supply-chain risk.

31 Jul 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.