Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
From late April to mid‑June 2026 Microsoft Defender Experts noted increased ACR Stealer activity; campaigns use ClickFix lures to exfiltrate browser credentials, access tokens and sensitive documents from enterprise environments. For MSPs and sysadmins token theft enables lateral movement and customer risk — review logs, rotate credentials/tokens and reinforce user awareness.
Microsoft highlights the need to limit privileges for autonomous AI agents using strong identity, access controls, tool binding and audit logging. For MSPs and sysadmins, scoping agent permissions and keeping audit trails lowers the risk of unauthorized access or harmful actions on customer infrastructure.
Microsoft warns that as AI agents become more autonomous, identity, access and auditing controls must be tightened. The post gives practical guidance for limiting agent access—using role-scoped permissions, tool binding, credential management and detailed logging—which matters for MSPs and sysadmins responsible for customer infrastructure.
Attackers gained control of AsyncAPI npm packages and abused trusted CI/CD pipelines to push malware via npm. The import-time execution of the payload and the attack chain underline the need for dependency audits, CI secret restrictions, and package integrity and build monitoring to protect infrastructure.
Signals from endpoints, identities, cloud workloads and third-party tools create noise that makes prioritization hard. Microsoft's Defender Experts analyzes those inputs and provides actionable recommendations and managed response to lower operational burden. This helps MSPs and sysadmins convert alerts into reliable, fast actions and reduce false positives.
Microsoft issued updates that fix at least 570 vulnerabilities in Windows and other products, nearly three times the number patched last month. The company attributes part of the increase to AI-assisted discovery; MSPs and sysadmins should test and deploy these updates promptly and watch for compatibility or regressions.
A failed DNSSEC key rollover caused an outage for the .al TLD. Cloudflare used a Negative Trust Anchor to restore resolution, and 1.1.1.1 now returns EDE 33 in DNS responses to indicate when DNSSEC validation was bypassed — useful for MSPs and sysadmins to detect and report validation skips.
A contractor left internal CISA credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months before the problem was reported. CISA’s postmortem points to shortcomings in the agency’s response and third-party oversight; MSPs should reinforce secret management, repository scanning and continuous monitoring to prevent similar incidents.
Cloudflare launched Precursor, a new engine that continuously validates behavior to improve bot management. It turns client-side session activity into detection signals to identify sophisticated automation more precisely while lowering friction for legitimate users.
Krebs on Security reports a startup offering millions for zero-day flaws in popular software is operated by people with criminal records who previously ran fake intelligence firms and a defunct AI lobbying project under aliases. For MSPs and server admins this raises the risk from vulnerabilities traded via opaque buyers and underscores the need to review supplier trust, patching and monitoring practices.
The FBI, working with industry partners, took control of hundreds of domains tied to NetNut. NetNut is a residential proxy service run by Alarum Technologies [NASDAQ: ALAR]; the move followed reporting that linked NetNut to the Popa botnet, which involves at least two million compromised devices. MSPs and server admins should monitor outbound proxies, tighten filtering and scan endpoints for compromise.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.