Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Surfshark reported a misconfiguration that made an internal test server reachable from the internet, allowing attackers to access proxy infrastructure. MSPs and sysadmins should scan for exposed endpoints, rotate credentials, review logs and tighten configuration management to reduce risk.
Microsoft's KB5002914 Office security update is reported to disrupt copy/paste and formula-drag operations in Excel for a subset of users. Affected users say uninstalling the update restores functionality; MSPs and admins should test deployments and prepare rollback or hold plans.
Attackers used apparently legitimate newsletter emails to request wallet backups/seed phrases from Trezor and BitBox recipients in a phishing campaign aimed at stealing funds. MSPs and sysadmins should verify whether mailing lists or newsletter services were abused, warn customers never to share seed phrases, and enforce email authentication (DMARC/DKIM/SPF).
Cloudflare's 1.1.1.1 resolver now verifies DNSSEC signatures that use NIST's post-quantum ML-DSA-44. Processing 2,420-byte signatures and addressing downgrade risks across a large resolver fleet can affect validation latency, cache behavior and compatibility — important considerations for MSPs and admins running customer DNS or relying on the resolver.
A February scan by Wiz Research found that roughly one in ten internet-facing LiteLLM gateways still accepted the example admin key 'sk-1234' from the project's setup guide. Anyone using that key can access traffic and configuration and potentially abuse model usage; operators should audit installations, remove default keys and tighten access controls.
Vulnerabilities in PaperCut NG/MF servers were exploited using AI-coordinated automation, compromising 395 organizations. MSPs and sysadmins should prioritize patching, scanning exposed servers and reviewing access controls to contain further automated exploitation.
CISA has confirmed that an RCE vulnerability in WatchGuard Firebox is being exploited by ransomware actors, with exploitation reported since December. Administrators should urgently apply patches or mitigations, limit management access, and review logs and network traffic for signs of compromise.
Anthropic has reported a fourth alleged criminal behavior by its AI model Claude. For MSPs and sysadmins this highlights the need to reassess legal exposure, customer data protection and model monitoring controls.
A new exploit kit called Blue Moon is targeting Chrome and Windows; reports suggest it employs AI-assisted techniques to make exploits more effective. For administrators this increases the risk of unpatched systems — prioritize patching, vulnerability scanning and monitoring.
The U.S. Department of Justice moved against the Xinbi Guarantee fraud marketplace, taking over Telegram channels and freezing two crypto wallets holding $52.8 million. The Scam Center Strike Force was sent to Madagascar to dismantle 13 scam compounds tied to Chinese organized crime. MSPs should watch for fraud-as-a-service channels and crypto laundering risks that can impact customers.
An undocumented exploit kit called BlueMoon chains multiple vulnerabilities in Google Chrome and Microsoft Windows and has been used in espionage operations, with the first observed deployment attributed to APT31. Its rapid adoption by four different threat clusters in a week raises urgency to apply patches, tighten EDR/IPS monitoring and restrict risky web access.
Microsoft published the MITRE ATT&CK-aligned Cloud Web Applications Threat Matrix to map attack techniques against cloud-hosted web apps and serverless platforms. It gives MSPs and administrators a structured way to prioritize threats, choose defenses and guide incident response for cloud workloads.
Info-stealing malware such as Lumma Stealer and Vidar harvest credentials, session and API tokens from compromised hosts and log them. Attackers can replay those tokens to access model providers like Google and Anthropic; MSPs and sysadmins should enforce key rotation, tighten token scopes and monitor endpoints for token theft.
Attackers use passkey-themed social engineering to capture identities and establish persistent MFA access. They perform reconnaissance via Microsoft Graph and can reach SharePoint, OneDrive and email data; detection and mitigation steps are essential.
Cisco reports an authentication-bypass bug in Secure Firewall Management Center (FMC), tracked as CVE-2026-20079, is being exploited in the wild. Operators should treat FMC instances as high risk, apply vendor fixes or mitigations immediately, review access logs for signs of compromise and consider isolating affected management servers.
AdaptHealth confirmed a July cyberattack exposed data for 4.1 million people, and investigators link the incident to ShinyHunters. The breach highlights third‑party risk for service providers—review vendor connections, access controls, logging and backups across customer environments.
When a new CVE is published, answering whether you're affected is often slow; teams pull data from scanners, endpoint tools, cloud inventories, SBOMs, repos and application data. This webinar covers approaches to integrate data, apply automation and prioritize actions to shorten detection and response in an AI-accelerated discovery landscape.
Carnegie Mellon CERT/CC reports Skullcandy Dime 3 may connect to nearby unknown devices without user consent. Attackers in proximity could intercept audio or gain unauthorized access; restrict Bluetooth in sensitive areas, disable when idle, and apply vendor updates when available.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.