Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
PaperCut published maintenance releases that replace earlier emergency fixes; PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are available for download. Administrators of print infrastructure should update quickly to remediate the two actively exploited vulnerabilities and replace temporary patches with the full fixes.
Cisco says three distinct threat clusters abused two recently patched Secure Firewall Management Center (FMC) vulnerabilities to exfiltrate credentials and deliver Qilin ransomware. The attacks leveraged critical flaws including CVE-2026-20079 (CVSS 10.0). MSPs and sysadmins should apply FMC updates, audit access and rotate credentials.
Threat actors are abusing popular AI services to host malicious content, manipulate search results and trick users into installing malware. Campaigns target Claude Artifacts, shared AI conversations, sponsored search listings and ClickFix-style lures; MSPs and sysadmins should strengthen output validation, access controls and download protections in customer environments.
GitLab is advising administrators to immediately apply fixes for CVE-2026-85706, a maximum-severity path traversal flaw. Path traversal bugs can allow attackers to reach files outside intended locations and risk system compromise; operators should install the update and review access controls.
Trezor reported a phishing campaign after the Brevo breach that targeted 347,000 email addresses and saw 2,500 users click a malicious link. MSPs and sysadmins should audit client accounts, enforce 2FA, tighten email filtering and notify affected customers.
A Ukrainian national was sentenced to four years for involvement in Conti ransomware incidents during 2021–2022. For MSPs and sysadmins this underlines that law enforcement can disrupt criminal infrastructure but threats persist; keep backups, tighten access controls and validate incident response plans.
Reports say Anthropic models fell into unauthorized hands and were used by various actors to generate guidance for drone swarms and biotech research. MSPs and admins should tighten API key management, access controls and monitoring to reduce risk of LLM-assisted attacks or data leakage.
This roundup covers 200 Android flaws, browser-driven phishing techniques, 119,000 scam e-commerce sites and 23 other security incidents. Common factors are excessive permissions, abuse of trusted services and exposed systems. MSPs and admins should audit extension permissions, integrations, patching and package sources.
Reports indicate Apple Watch may record portions of conversations involving people who haven't consented. For MSPs and admins this raises privacy and compliance risks (GDPR/KVKK); review MDM profiles, microphone permissions and client disclosures to reduce exposure.
Threat actors are abusing Google Play's Early Access program to publish thousands of deceptive apps that promise money, rewards, casino wins and premium content. For MSPs and sysadmins these apps raise risks of fraud, data theft or malware on managed devices, so tighten app-install policies, restrict store channels and monitor device telemetry.
Mantax Otax Android malware can encrypt files, exfiltrate sensitive data and spam/harass victims. For MSPs and admins this increases risk of data loss and privacy breaches on managed Android endpoints — review MDM policies, backups and mobile threat protections.
Microsoft analyzed a BEC campaign that leveraged AI to craft executive impersonations and fraudulent invoices targeting finance teams. The attacks aimed to redirect ACH payments; email authentication, payment verification procedures and staff training are essential mitigations.
Check Point fixed two critical vulnerabilities in VPN certificate handling; both are rated CVSS 9.8 and can enable unauthenticated remote code execution under certain conditions. Security Gateways and management components are impacted — update internet-exposed appliances and review VPN services promptly.
A suspected Russian-speaking actor used numerous AI agents to craft exploits against two recently disclosed PaperCut NG/MF flaws and compromised over 440 instances. Blackpoint Cyber and GreyNoise link the activity to IP 45.142.193.132; MSPs should apply patches and review access logs immediately.
Group-IB says the Gigabud banking trojan installs a second app on infected Android devices that creates a work profile and places a modified banking app inside. Because the work profile is isolated from the personal space, the malware can bypass some detection and monitoring, increasing the risk of unnoticed fraud on customer devices.
After September 2026 security updates, administrators report Remote Desktop Services failures on Windows Server 2019, 2022 and 2025. The issue can block remote logins and in some cases require a hard reboot to recover. Test updates before deploying to production and prepare rollback options.
CISA added three vulnerabilities affecting Cisco, Citrix and Fortinet to its KEV catalog, requiring FCEB agencies to apply patches by Sept 12, 2026. CVE-2026-20079 (CVSS 10.0) is included; MSPs and sysadmins should quickly inventory affected devices and deploy patches or mitigations.
Microsoft Defender details capabilities to identify and disrupt AI-themed phishing, malware and multi-stage attacks across the attack chain. For MSPs and sysadmins these enhancements broaden detection coverage and enable automated responses to reduce impact on servers and customer environments.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.