Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

PaperCut fixes two actively exploited flaws with maintenance releases

PaperCut published maintenance releases that replace earlier emergency fixes; PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are available for download. Administrators of print infrastructure should update quickly to remediate the two actively exploited vulnerabilities and replace temporary patches with the full fixes.

11 Sep 2026 thehackernews.com
Security The Hacker News

Cisco FMC vulnerabilities exploited to steal credentials and deploy Qilin ransomware

Cisco says three distinct threat clusters abused two recently patched Secure Firewall Management Center (FMC) vulnerabilities to exfiltrate credentials and deliver Qilin ransomware. The attacks leveraged critical flaws including CVE-2026-20079 (CVSS 10.0). MSPs and sysadmins should apply FMC updates, audit access and rotate credentials.

11 Sep 2026 thehackernews.com
Security BleepingComputer

Attackers Turning AI Platforms into an Attack Surface

Threat actors are abusing popular AI services to host malicious content, manipulate search results and trick users into installing malware. Campaigns target Claude Artifacts, shared AI conversations, sponsored search listings and ClickFix-style lures; MSPs and sysadmins should strengthen output validation, access controls and download protections in customer environments.

11 Sep 2026 bleepingcomputer.com
Security BleepingComputer

GitLab urges emergency patch for CVE-2026-85706 critical path traversal

GitLab is advising administrators to immediately apply fixes for CVE-2026-85706, a maximum-severity path traversal flaw. Path traversal bugs can allow attackers to reach files outside intended locations and risk system compromise; operators should install the update and review access controls.

11 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Trezor: 347,000 emails targeted after Brevo breach

Trezor reported a phishing campaign after the Brevo breach that targeted 347,000 email addresses and saw 2,500 users click a malicious link. MSPs and sysadmins should audit client accounts, enforce 2FA, tighten email filtering and notify affected customers.

11 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Associate of Conti ransomware given a 4-year prison sentence

A Ukrainian national was sentenced to four years for involvement in Conti ransomware incidents during 2021–2022. For MSPs and sysadmins this underlines that law enforcement can disrupt criminal infrastructure but threats persist; keep backups, tighten access controls and validate incident response plans.

11 Sep 2026 bleepingcomputer.com
Security The Register

Anthropic leak alleges drone swarms and bioweapons research misuse

Reports say Anthropic models fell into unauthorized hands and were used by various actors to generate guidance for drone swarms and biotech research. MSPs and admins should tighten API key management, access controls and monitoring to reduce risk of LLM-assisted attacks or data leakage.

11 Sep 2026 theregister.com
Security The Hacker News

ThreatsDay: 200 Android flaws, browser-based phishing, 119K scam stores

This roundup covers 200 Android flaws, browser-driven phishing techniques, 119,000 scam e-commerce sites and 23 other security incidents. Common factors are excessive permissions, abuse of trusted services and exposed systems. MSPs and admins should audit extension permissions, integrations, patching and package sources.

10 Sep 2026 thehackernews.com
Security The Register

Apple Watch can capture conversation snippets without the other party's consent

Reports indicate Apple Watch may record portions of conversations involving people who haven't consented. For MSPs and admins this raises privacy and compliance risks (GDPR/KVKK); review MDM profiles, microphone permissions and client disclosures to reduce exposure.

10 Sep 2026 theregister.com
Security The Hacker News

Google Play Early Access used to distribute thousands of deceptive Android apps

Threat actors are abusing Google Play's Early Access program to publish thousands of deceptive apps that promise money, rewards, casino wins and premium content. For MSPs and sysadmins these apps raise risks of fraud, data theft or malware on managed devices, so tighten app-install policies, restrict store channels and monitor device telemetry.

10 Sep 2026 thehackernews.com
Security BleepingComputer

Mantax Otax: new Android malware that encrypts files and steals data

Mantax Otax Android malware can encrypt files, exfiltrate sensitive data and spam/harass victims. For MSPs and admins this increases risk of data loss and privacy breaches on managed Android endpoints — review MDM policies, backups and mobile threat protections.

10 Sep 2026 bleepingcomputer.com
Security Microsoft

AI-assisted executive impersonation and fake invoices used in ACH payment fraud

Microsoft analyzed a BEC campaign that leveraged AI to craft executive impersonations and fraudulent invoices targeting finance teams. The attacks aimed to redirect ACH payments; email authentication, payment verification procedures and staff training are essential mitigations.

10 Sep 2026 microsoft.com
Security The Hacker News

Check Point patches two 9.8-rated VPN certificate RCE flaws

Check Point fixed two critical vulnerabilities in VPN certificate handling; both are rated CVSS 9.8 and can enable unauthenticated remote code execution under certain conditions. Security Gateways and management components are impacted — update internet-exposed appliances and review VPN services promptly.

10 Sep 2026 thehackernews.com
Security The Hacker News

PaperCut attacker used hundreds of AI agents to compromise 440+ instances

A suspected Russian-speaking actor used numerous AI agents to craft exploits against two recently disclosed PaperCut NG/MF flaws and compromised over 440 instances. Blackpoint Cyber and GreyNoise link the activity to IP 45.142.193.132; MSPs should apply patches and review access logs immediately.

10 Sep 2026 thehackernews.com
Security The Hacker News

Gigabud hides banking apps by creating Android work profiles

Group-IB says the Gigabud banking trojan installs a second app on infected Android devices that creates a work profile and places a modified banking app inside. Because the work profile is isolated from the personal space, the malware can bypass some detection and monitoring, increasing the risk of unnoticed fraud on customer devices.

10 Sep 2026 thehackernews.com
Security BleepingComputer

September 2026 Windows Server update breaks Remote Desktop Services (RDS)

After September 2026 security updates, administrators report Remote Desktop Services failures on Windows Server 2019, 2022 and 2025. The issue can block remote logins and in some cases require a hard reboot to recover. Test updates before deploying to production and prepare rollback options.

10 Sep 2026 bleepingcomputer.com
Security The Hacker News

CISA adds Cisco/Citrix/Fortinet flaws to KEV — Sept 12, 2026 patch deadline

CISA added three vulnerabilities affecting Cisco, Citrix and Fortinet to its KEV catalog, requiring FCEB agencies to apply patches by Sept 12, 2026. CVE-2026-20079 (CVSS 10.0) is included; MSPs and sysadmins should quickly inventory affected devices and deploy patches or mitigations.

10 Sep 2026 thehackernews.com
Security Microsoft

Microsoft Defender: Detect and disrupt AI-themed attacks

Microsoft Defender details capabilities to identify and disrupt AI-themed phishing, malware and multi-stage attacks across the attack chain. For MSPs and sysadmins these enhancements broaden detection coverage and enable automated responses to reduce impact on servers and customer environments.

10 Sep 2026 microsoft.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.