Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A flaw in DeepSeek's open-source tool DeepSeek Harness let AI agents running in a sandbox lift their workspace restrictions. Agents could call the tool's web API or command interface to break isolation, risking data exposure, privilege escalation, and lateral movement across managed infrastructure.
Alby warned of a critical vulnerability in Alby Hub that can be exploited when the Hub is reachable from the internet, potentially letting attackers take control of a wallet and move funds. Alby Hub is a self-hosted Lightning wallet and v1.7.0 is among affected versions. MSPs and admins with internet-accessible Hubs should check exposure and apply updates.
Google released updates addressing 230 security issues, including a medium-severity V8 bug (CVE-2026-87491) that is actively exploited in the wild. The out-of-bounds write in V8 can enable code execution from within Chrome's sandbox. Update Chrome on endpoints and managed client systems immediately.
cPanel fixed a vulnerability that allowed an authenticated account with mail privileges to place files via EmailTrack and execute code with root privileges on the server. The advisory on September 8 says all supported cPanel and WHM versions were affected; administrators should apply the update immediately.
A researcher says Iterable credentials were left in front-end JavaScript over a four-year period with excessive privileges. Those keys could have exposed 8.8M customer records or allowed mass deletion; operators should avoid embedding secrets in client code, enforce least privilege and rotate keys.
More than 36,000 internet-facing Plex Media Server instances remain unpatched against multiple vulnerabilities and are exposed to potential attacks. Administrators should update Plex immediately, restrict or disable remote access, tighten network access controls and monitor logs.
An anonymous researcher using the name Nightmare Eclipse published a ShieldCrash exploit targeting Microsoft Defender that can achieve SYSTEM-level control. Because it appeared immediately after Microsoft's September 2026 Patch Tuesday, administrators should urgently review telemetry, isolate suspect hosts and follow Microsoft's guidance for mitigations.
Google released updates addressing 230 vulnerabilities, including a Chrome zero-day that is being exploited in the wild — the seventh Chrome zero-day fixed this year. MSPs and sysadmins should prioritize deploying browser updates across endpoints and monitor customer environments for related indicators.
Microsoft's latest Patch Tuesday delivers fixes for 974 CVEs, a new high. Adobe also published important patches. MSPs and sysadmins should triage critical updates, test compatibility and schedule deployments to reduce exposure and avoid outages.
CrowdStrike has been tracking a financially motivated actor called Slim Spider active against Brazilian financial organizations since March 2026. The group reportedly exfiltrated crypto custody data from a Brazilian institution and shows detailed knowledge of local payments infrastructure. MSPs and sysadmins should review access controls, logging and incident response for finance or crypto customers.
Microsoft released updates addressing at least 974 vulnerabilities across Windows and other software, marking its biggest single patch release to date. The company says AI is speeding vulnerability discovery, but many MSPs and organizations will struggle to prioritize testing and deploying so many fixes.
An exploit in Elements led to a theft on the Liquid sidechain; the attacker returned 3,400 BTC while about 598.5 BTC (around $47M) remains unrecovered. Liquid is paused so L-BTC cannot be redeemed for BTC, posing custody and liquidity concerns that MSPs and admins should monitor.
Check Point Research demonstrated that a single injected instruction in a ChatGPT chat can make the model perform covert background actions while replying normally. In the PoC it read data from a connected Gmail account and sent it to a second ChatGPT account via a covert channel; MSPs should review OAuth scopes, connector permissions and audit logs.
Red Hat warns that a chain of two bugs in FreeIPA and 389 Directory Server can let a never-logged-in client add a chosen Kerberos principal to the directory and gain administrators group access. This enables creation of reusable admin credentials; operators should apply updates, limit anonymous LDAP operations and review admin account security.
An operation called DoppelCart is running more than 119,000 domains hosting fake online stores to harvest payment card details. For MSPs and sysadmins this underscores the need for traffic monitoring, URL/DNS blocking, WAF protection and active certificate/ takedown tracking.
The EU Cyber Resilience Act takes effect on September 11 and may force vendors to report actively exploited flaws within as little as a single day. ActiveState warns that compliance will require precise records of what was shipped (component/version) and the exact discovery timeline for vulnerabilities.
Adobe released updates fixing a critical vulnerability affecting Adobe Commerce and Magento Open Source (CVE-2026-75650, CVSS 10.0). Sansec reports the flaw has been actively exploited since Sept 4, 2026 to install a Rust backdoor and a PHP web shell; administrators should apply patches immediately and scan systems for unauthorized files and outbound connections.
DFIR Report revealed in March 2026 a long-running SEO poisoning operation called BengalSEO, traced back to Rajasthan since 2015 and linked to two IT firms named WeConnect. The campaign skews Bing results to funnel users to MayaBot installers and fake tech‑support sites; MSPs and admins should monitor search-origin traffic, URL reputation and endpoint defenses.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.