Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security BleepingComputer

CISA issues guidance to isolate critical OT systems during cyberattacks

U.S. and Australian authorities urged critical infrastructure operators to be ready to isolate vital operational technology (OT) systems during cyberattacks or major disruptions. The guidance highlights identifying critical assets, having safe disconnect procedures, testing them and coordinating with stakeholders. These steps help limit attack spread and protect service continuity.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

vBulletin fixes critical pre-auth RCE flaw; public exploit released

A critical flaw in vBulletin allows unauthenticated attackers to run PHP via template processing and a patch has been released. A public exploit is available, so administrators managing forums should apply the update immediately.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Is your SSO resilient to modern credential attacks?

A single compromised SSO login can give attackers access to multiple enterprise applications. Specops Software recommends stronger passwords, phishing-resistant MFA and identity hardening to reduce risk; MSPs and admins should prioritize user controls and configuration checks to protect customer environments.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

20-year-old BMC flaw leaks password hashes on over 24,000 servers

A two-decade-old vulnerability in BMC interfaces has exposed authentication hashes on more than 24,000 internet-reachable servers. Providers and admins should inventory and isolate exposed BMCs, apply firmware updates or patches, rotate credentials, and restrict network access to block attacker access.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

MCBS breach exposes data of 1.26 million people

Medical Computer Business Services (MCBS) disclosed a 2025 network breach that affected sensitive information for more than 1.26 million people. The incident underlines the need for providers and admins to prioritise third‑party risk management, encryption, access controls and incident detection/response.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

FastJson zero-day RCE exploited against US companies

A zero-day flaw in the FastJson Java library is being abused to execute code remotely without authentication or user interaction, with attackers focusing on US firms. Infrastructure teams should urgently apply updates, tighten WAF/IPS protections and restrict incoming traffic to mitigate risk.

27 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Arista patches zero-day in VeloCloud Orchestrator exploited in active attacks

Arista issued a patch for a command-injection zero-day affecting on-prem VeloCloud Orchestrator that has been exploited in the wild. MSPs and sysadmins should apply the update immediately, isolate management interfaces, rotate credentials, audit logs for suspicious activity, and tighten network access controls.

27 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Dysphoria botnet spreads to 200,000 devices, used for DDoS and traffic relay

The Dysphoria botnet has taken control of about 200,000 devices worldwide to conduct DDoS attacks and relay traffic. MSPs and sysadmins should watch for unusual outbound traffic and abuse, ensure vulnerable devices are patched or isolated, and apply edge filtering or rate limits to reduce impact.

27 Jul 2026 bleepingcomputer.com
Security Microsoft

Microsoft unveils Project Perception, a security stack for the AI era

Microsoft introduced Project Perception as a new cyber security stack tailored for the AI era. As AI workloads and threats evolve, telemetry, detection and control models need updating; managed service providers and sysadmins should plan for greater visibility and automation.

27 Jul 2026 blogs.microsoft.com
Security Cloudflare

Cloudflare open-sources pvcli CLI for testing OHTTP and privacy protocols

Cloudflare published pvcli as an open-source command-line tool that offers a curl-like interface to simplify testing of privacy protocols such as OHTTP. For server admins and MSPs it helps validate implementations, simulate requests, troubleshoot privacy proxies and integrate tests into automation.

27 Jul 2026 blog.cloudflare.com
Security Microsoft

Q2 2026 email threats: trends after Tycoon2FA disruption

Microsoft's action against Tycoon2FA coincided with declines in several common phishing methods. Attackers moved into Teams-based social engineering and increasingly used automated, multi-stage attack chains; MSPs and sysadmins should monitor Teams traffic, automation indicators and multi-stage attack signs rather than rely solely on email filters.

23 Jul 2026 microsoft.com
Security Microsoft

Q2 2026 email threats: Tycoon2FA disruption and Teams-focused tactics

In Q2 2026 Microsoft's action against the Tycoon2FA phishing platform helped reduce several major phishing methods, while attackers moved into Teams-based social engineering and more automated, multi-step attack chains. MSPs and sysadmins should monitor collaboration channels and update email defenses and detections for automated multi-stage campaigns.

23 Jul 2026 microsoft.com
Security Microsoft

Microsoft and AXA XL launch collaboration on incident response

Microsoft is partnering with AXA XL to provide cyber insurance policyholders access to Microsoft Incident Response services. The alliance is designed to help organizations coordinate technical response, business actions and insurance workflows to strengthen resilience against incidents.

22 Jul 2026 microsoft.com
Security Microsoft

Microsoft and AXA XL expand incident response access for policyholders

Microsoft and AXA XL's agreement gives AXA XL cyber insurance customers access to Microsoft Incident Response. The collaboration aims to align technical remediation, business continuity and insurance handling to speed response and limit impact. MSPs should notify customers that coordinated incident support and claims assistance are available.

22 Jul 2026 microsoft.com
Security Krebs on Security

LG to ban residential proxy use in smart TV apps

LG Electronics USA plans to suspend smart TV apps that turn televisions into always-on residential proxy nodes. Researchers found about 42% of apps in the webOS store allowed third parties to route users' traffic, creating bandwidth, security and abuse risks that MSPs should watch for.

22 Jul 2026 krebsonsecurity.com
Security Cloudflare

Cloudflare WAF blocks two high-severity WordPress vulnerabilities

Cloudflare implemented two new WAF rules after the WordPress security team reported two high-severity flaws. The rules filter traffic for customers running affected WordPress versions, but administrators should still deploy the vendor patch immediately for their servers and clients.

17 Jul 2026 blog.cloudflare.com
Security Microsoft

Microsoft at Black Hat USA 2026: Focus on AI-era and supply chain threats

Microsoft Security will be at Black Hat USA 2026 with supply chain research, hands‑on security sessions, expert discussions and a reception. The event gives MSPs and sysadmins practical insight into AI-driven risks and supply‑chain attacks, plus training and networking opportunities.

17 Jul 2026 microsoft.com
Security Microsoft

Increase in ACR Stealer campaigns using ClickFix lures to steal credentials and documents

From late April to mid-June 2026 Microsoft Defender Experts recorded a rise in ACR Stealer activity. Campaigns use ClickFix-themed lures to harvest browser credentials, authentication tokens and sensitive documents; MSPs and sysadmins should prioritize credential/token protection and monitoring for related indicators.

16 Jul 2026 microsoft.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.