Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Google is developing a Chrome security control that by default will stop extensions installed via enterprise policy from altering the browser's new tab page or default search engine. This will limit unwanted redirects in managed environments; MSPs and system administrators should review centrally deployed extensions and policy configurations for compatibility.
On July 30 an attacker emptied 1,196 Bitcoin addresses in 41 minutes, stealing 1,082.65 BTC (~$70.2M). Galaxy Research linked the sweep to a firmware integration mistake in Coldcard (Coinkite) that, after a March 2021 change, caused seed generation to rely on a predictable software PRNG. Firmware integrity and key-generation trust in custody devices are now a critical concern for admins and MSPs.
A JavaScript ad file served by Adform was altered to run in visitors' browsers and change cryptocurrency wallet addresses. Adform discovered the incident on July 27, removed the injected code, informed affected customers and reported the case to authorities. MSPs and admins should audit third‑party ad tags and review traffic from that date.
A critical authorization flaw in Adobe Campaign Classic (CVE-2026-48449) has been reported with a CVSS score of 10.0. The bug can allow attackers to execute arbitrary code without user interaction, posing a serious threat to on-prem deployments and customer data. Admins and MSPs should apply Adobe's updates immediately and review access and monitoring controls.
Microsoft says attackers abused compromised hotel wireless to serve a bogus browser update that installed CornFlake, a RAT able to access webcams, microphones and log keystrokes. Researchers track the campaign as CaptiveCrunch and link it to Storm‑2945, tied to Midnight Blizzard. MSPs should harden guest Wi‑Fi, monitor captive portals and strengthen endpoint defenses.
A flaw in Active Storage lets unauthenticated actors read files from a Rails app and can, in certain scenarios, escalate to remote code execution. Admins and MSPs should deploy the Rails patch quickly, tighten file access controls, and limit how uploaded content is processed to reduce risk.
A Chinese-speaking threat actor has conducted attacks since January 2025 against government and public organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The intrusions are linked to OctLurk and SilkLurk toolsets; MSPs and sysadmins should review detection, network segmentation and incident response preparedness.
Blackpoint Cyber researchers uncovered a campaign using the Go-based HollowFrame loader and Rust-based Matryoshka malware against a law firm. The attack starts from a link to an encrypted archive that contains a Windows LNK; executing it launches a multi-stage infection chain. Admins should tighten email filtering, restrict LNK execution and reinforce EDR and monitoring.
A sub-cluster of Russian actor Midnight Blizzard, Storm-2945, has been compromising hospitality sign-in portals since May 2026 to push malware to travelers and harvest credentials. MSPs and sysadmins should verify portal integrity, enforce MFA and WAF protections, and increase logging and endpoint defenses.
Since May 2026, Storm-2945, a Midnight Blizzard sub-cluster, has been compromising hotel and hospitality login portals to infect guest devices with malware and harvest credentials. MSPs and sysadmins should audit captive portal security, enforce MFA, segment networks, strengthen endpoint defenses and monitor access logs while tracking related threat intelligence.
Bitsight says some low-cost Android TV boxes include apps that alter device identity to impersonate Samsung, Huawei, Xiaomi or Vivo phones and click ads on sites run by the same operators; researchers named the campaign Fuyao and tied it to Zhejiang Fengwo IoT Technology Co., Ltd. The same apps also turn boxes into outbound proxy exits using owners' broadband, creating bandwidth, IP reputation and abuse risks for MSPs and admins.
Threat actor ShinyHunters accessed the SaaS environment of a prominent physical security vendor. MSPs and sysadmins should assume integrations, API keys and credentials may be exposed; review access controls, rotate credentials and enable monitoring for suspicious activity.
Google patched 1,072 security issues across Chrome 149 and 150, a total that exceeds the fixes in the prior 23 releases combined. The subsequent Chrome 151 update fixed another 370 bugs, 349 of which were reported by Google itself. MSPs and sysadmins should prioritize testing and deploying these updates promptly.
Amgen reported that attackers accessed corporate and patient data across multiple cloud environments managed by external providers. For MSPs and sysadmins, such supplier-side breaches underline the need to review vendor security, encryption, access governance, logging and incident response for customer-hosted data.
A US bank relied on a ransomware group that claimed it would delete stolen data; trusting such promises is risky. For sysadmins and MSPs this highlights the need for robust backups, protections against data exfiltration, forensic preservation and timely regulatory or law enforcement engagement.
Arch Linux has paused allowing others to adopt AUR packages following a rise in incidents where attackers took over package maintainership. MSPs and sysadmins should treat AUR as a higher supply-chain risk and verify maintainers, signatures and update provenance before deploying AUR-sourced software.
Researchers at Nanyang Technological University in Singapore found 84 vulnerabilities in 4G/5G core infrastructure. Several issues could cause denial-of-service or allow attackers to hijack user sessions, creating direct risks for operators and MSPs responsible for customer connectivity and core systems.
A malicious script injected into Adform's ad code modified wallet addresses copied to users' clipboards, substituting attacker-controlled addresses. Sites running Adform could expose users' crypto to theft; managed service providers and sysadmins should treat third-party ad scripts as a supply-chain risk.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.