Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
U.S. and Australian authorities urged critical infrastructure operators to be ready to isolate vital operational technology (OT) systems during cyberattacks or major disruptions. The guidance highlights identifying critical assets, having safe disconnect procedures, testing them and coordinating with stakeholders. These steps help limit attack spread and protect service continuity.
A critical flaw in vBulletin allows unauthenticated attackers to run PHP via template processing and a patch has been released. A public exploit is available, so administrators managing forums should apply the update immediately.
A single compromised SSO login can give attackers access to multiple enterprise applications. Specops Software recommends stronger passwords, phishing-resistant MFA and identity hardening to reduce risk; MSPs and admins should prioritize user controls and configuration checks to protect customer environments.
A two-decade-old vulnerability in BMC interfaces has exposed authentication hashes on more than 24,000 internet-reachable servers. Providers and admins should inventory and isolate exposed BMCs, apply firmware updates or patches, rotate credentials, and restrict network access to block attacker access.
Medical Computer Business Services (MCBS) disclosed a 2025 network breach that affected sensitive information for more than 1.26 million people. The incident underlines the need for providers and admins to prioritise third‑party risk management, encryption, access controls and incident detection/response.
A zero-day flaw in the FastJson Java library is being abused to execute code remotely without authentication or user interaction, with attackers focusing on US firms. Infrastructure teams should urgently apply updates, tighten WAF/IPS protections and restrict incoming traffic to mitigate risk.
Arista issued a patch for a command-injection zero-day affecting on-prem VeloCloud Orchestrator that has been exploited in the wild. MSPs and sysadmins should apply the update immediately, isolate management interfaces, rotate credentials, audit logs for suspicious activity, and tighten network access controls.
The Dysphoria botnet has taken control of about 200,000 devices worldwide to conduct DDoS attacks and relay traffic. MSPs and sysadmins should watch for unusual outbound traffic and abuse, ensure vulnerable devices are patched or isolated, and apply edge filtering or rate limits to reduce impact.
Microsoft introduced Project Perception as a new cyber security stack tailored for the AI era. As AI workloads and threats evolve, telemetry, detection and control models need updating; managed service providers and sysadmins should plan for greater visibility and automation.
Cloudflare published pvcli as an open-source command-line tool that offers a curl-like interface to simplify testing of privacy protocols such as OHTTP. For server admins and MSPs it helps validate implementations, simulate requests, troubleshoot privacy proxies and integrate tests into automation.
Microsoft's action against Tycoon2FA coincided with declines in several common phishing methods. Attackers moved into Teams-based social engineering and increasingly used automated, multi-stage attack chains; MSPs and sysadmins should monitor Teams traffic, automation indicators and multi-stage attack signs rather than rely solely on email filters.
In Q2 2026 Microsoft's action against the Tycoon2FA phishing platform helped reduce several major phishing methods, while attackers moved into Teams-based social engineering and more automated, multi-step attack chains. MSPs and sysadmins should monitor collaboration channels and update email defenses and detections for automated multi-stage campaigns.
Microsoft is partnering with AXA XL to provide cyber insurance policyholders access to Microsoft Incident Response services. The alliance is designed to help organizations coordinate technical response, business actions and insurance workflows to strengthen resilience against incidents.
Microsoft and AXA XL's agreement gives AXA XL cyber insurance customers access to Microsoft Incident Response. The collaboration aims to align technical remediation, business continuity and insurance handling to speed response and limit impact. MSPs should notify customers that coordinated incident support and claims assistance are available.
LG Electronics USA plans to suspend smart TV apps that turn televisions into always-on residential proxy nodes. Researchers found about 42% of apps in the webOS store allowed third parties to route users' traffic, creating bandwidth, security and abuse risks that MSPs should watch for.
Cloudflare implemented two new WAF rules after the WordPress security team reported two high-severity flaws. The rules filter traffic for customers running affected WordPress versions, but administrators should still deploy the vendor patch immediately for their servers and clients.
Microsoft Security will be at Black Hat USA 2026 with supply chain research, hands‑on security sessions, expert discussions and a reception. The event gives MSPs and sysadmins practical insight into AI-driven risks and supply‑chain attacks, plus training and networking opportunities.
From late April to mid-June 2026 Microsoft Defender Experts recorded a rise in ACR Stealer activity. Campaigns use ClickFix-themed lures to harvest browser credentials, authentication tokens and sensitive documents; MSPs and sysadmins should prioritize credential/token protection and monitoring for related indicators.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.