Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security Microsoft

Microsoft Security — July 2026: AI environment and defense updates

In July 2026 Microsoft rolled out security updates aimed at protecting AI environments, applying AI to defence, and strengthening the infrastructure behind AI-powered operations. The improvements help IT teams and MSPs deploy AI workloads more securely and add automated detection and response capabilities to improve threat handling.

30 Jul 2026 microsoft.com
Security BleepingComputer

Amazon links Debug and Chalk npm supply-chain attacks to North Korean actors

Amazon found that supply-chain attacks involving the npm packages Debug and Chalk are linked to North Korean actors. For sysadmins and MSPs this highlights the need to audit dependencies, tighten CI/CD and registry controls, and use package scanning and signature checks to reduce compromise risk.

30 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Security updates for Broadcom/VMware: three critical flaws allow auth bypass and VM escape

Broadcom released patches for five vulnerabilities in VMware vCenter, ESX, Workstation and Fusion; three are critical and can enable authentication bypass, arbitrary code execution, or escape from a VM to the host. Administrators and MSPs should prioritize updating management servers and multi-tenant hosts promptly.

30 Jul 2026 bleepingcomputer.com
Security The Register

FTC: Hims & Hers shared patient data with Meta and Snap; cancel option hidden

The FTC alleges telehealth provider Hims & Hers passed sensitive patient details to Meta and Snap and made it hard for customers to cancel prescription subscriptions. This raises privacy concerns, potential data sharing to ad platforms and unexpected billing risks that infrastructure teams should review.

30 Jul 2026 theregister.com
Security The Hacker News

Russian actors exploit Microsoft OWA flaw to persist mailbox access

Starting July 22, 2026, Russian-linked operators exploited a Microsoft OWA vulnerability to maintain access to mailboxes across US and European government targets and multiple commercial sectors. Access persisted despite credential rotations; admins should apply updates, review active sessions, check mailbox rules and permissions, and revoke suspicious sessions or tokens.

30 Jul 2026 thehackernews.com
Security BleepingComputer

Google: 1,072 security bugs fixed in Chrome across two releases with AI

Google reports it fixed 1,072 security bugs in Chrome across two recent releases after expanding use of AI. AI-assisted scanning and triage sped up discovery and remediation, so admins and MSPs should prioritize installing these updates and review their patch deployment processes.

30 Jul 2026 bleepingcomputer.com
Security The Hacker News

FCC adds foreign-made mobile robots and networked inverters to Covered List

On July 28 the FCC added foreign-produced mobile robots and networked power inverters to its Covered List. The change makes it harder for new models to obtain the authorizations needed to enter the US market, while previously authorized and already-owned devices remain unaffected. MSPs and admins should review procurement and compliance for these device classes.

30 Jul 2026 thehackernews.com
Security BleepingComputer

ShinyHunters claims Brinks Home breach, threatens to publish data

Brinks Home says ShinyHunters allegedly accessed parts of its internal systems and is threatening to make purportedly stolen data public. Providers and MSPs should audit logs, rotate credentials and keys, and check for exposed customer information or lateral movement.

30 Jul 2026 bleepingcomputer.com
Security The Hacker News

Amazon links September 2025 hijack of debug and chalk npm packages to North Korea

Amazon attributes the September 2025 compromise of debug and chalk to North Korea’s Sapphire Sleet. The attackers phished a maintainer via a fake npm domain and injected malicious code into at least 18 packages that together see billions of weekly downloads. MSPs and admins should audit dependencies, monitor maintainer accounts and pin versions.

30 Jul 2026 thehackernews.com
Security The Hacker News

Cisco FMC zero-day (CVE-2026-20316) actively exploited

CISA added CVE-2026-20316, which affects Cisco Secure Firewall Management Center (FMC), to its KEV list after reports of active zero‑day exploitation. The CVSS 5.3 vulnerability may permit unauthenticated remote access and risk exposing static credentials on appliances; MSPs should apply vendor fixes and audit credentials immediately.

30 Jul 2026 thehackernews.com
Security The Hacker News

Critical Active Storage flaw in Rails allows server file reads via image uploads

Ruby on Rails released patches for an unauthenticated Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5). Crafted image uploads can enable attackers to read arbitrary files on application servers and expose secrets such as secret_key_base, the Rails master key, database passwords and cloud storage credentials. MSPs and sysadmins should apply updates and tighten upload handling immediately.

29 Jul 2026 thehackernews.com
Security The Hacker News

Ruflo CVE-2026-59726: unauthenticated RCE and AI memory poisoning

A critical flaw in Ruflo (agent meta-harness for Anthropic Claude Code and OpenAI Codex), tracked as CVE-2026-59726 (CVSS 10.0), affects all releases before 3.16.3. Unauthenticated actors can execute remote commands and corrupt AI agent memory; Noma Security calls it RufRoot — upgrade to 3.16.3 immediately.

29 Jul 2026 thehackernews.com
Security The Hacker News

Three critical VMware vulnerabilities: auth bypass, code execution and VM escape

Broadcom released patches for VMware ESX, vCenter, Workstation and Fusion; three are rated critical. CVE-2026-59309 (CVSS 9.8) can allow attackers to circumvent authentication on vCenter if they can reach it over the network; other critical flaws may enable remote code execution and VM escape. Prioritize patching vCenter and restrict its network access.

29 Jul 2026 thehackernews.com
Security BleepingComputer

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper for persistent mailbox access

Russia-backed Laundry Bear (Void Blizzard) is exploiting a zero-day in Exchange OWA to deliver a backdoor called OWAReaper via email campaigns. The implant can give long-term mailbox access; MSPs and sysadmins should apply patches, monitor OWA and mailbox activity, and hunt for related indicators.

29 Jul 2026 bleepingcomputer.com
Security The Hacker News

Coordinated cyberattack hit 30+ Minnesota water systems; one plant offline

Between July 26–27 a coordinated intrusion into operational technology disrupted operations at over 30 community water utilities in Minnesota. The Braham facility went offline while Plymouth, South St. Paul and Maple Plain reported communication and automated-control issues, prompting a statewide cybersecurity response. MSPs should reassess OT segmentation and incident readiness.

29 Jul 2026 thehackernews.com
Security The Hacker News

Mythos warns: AI is shortening exploit timelines

Mythos highlights that AI is compressing the time to develop exploits, forcing a reassessment of which part of your vulnerability management is failing. The piece doesn't offer fixes; MSPs and sysadmins should urgently review prioritization, asset visibility, compensating controls and detection/response processes.

29 Jul 2026 thehackernews.com
Security BleepingComputer

Cisco warns of CVE-2026-20316 static credential flaw in FMC

Cisco reports that a static credential flaw in Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, has been leveraged in zero-day campaigns to obtain unauthorized access to appliances. Administrators should quickly apply Cisco fixes, restrict management access, rotate credentials and review logs for signs of compromise.

29 Jul 2026 bleepingcomputer.com
Security The Hacker News

JIT bug (CVE-2026-10702) can compromise Tor Browser and Firefox via single webpage visit

Nebula Security reports a JIT flaw (CVE-2026-10702) in Firefox that can be exploited by visiting a malicious page and was used to compromise Tor Browser. Mozilla rated it High and fixed it in Firefox 151.0.3; admins should deploy the update immediately and consider browser isolation and URL filtering.

29 Jul 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.