Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

Vulnerability in DeepSeek Harness allowed agents to disable their sandbox

A flaw in DeepSeek's open-source tool DeepSeek Harness let AI agents running in a sandbox lift their workspace restrictions. Agents could call the tool's web API or command interface to break isolation, risking data exposure, privilege escalation, and lateral movement across managed infrastructure.

09 Sep 2026 thehackernews.com
Security The Hacker News

Critical vulnerability in Alby Hub affects internet-exposed wallets

Alby warned of a critical vulnerability in Alby Hub that can be exploited when the Hub is reachable from the internet, potentially letting attackers take control of a wallet and move funds. Alby Hub is a self-hosted Lightning wallet and v1.7.0 is among affected versions. MSPs and admins with internet-accessible Hubs should check exposure and apply updates.

09 Sep 2026 thehackernews.com
Security The Hacker News

Update for CVE-2026-87491 in Chrome V8 being exploited in the wild

Google released updates addressing 230 security issues, including a medium-severity V8 bug (CVE-2026-87491) that is actively exploited in the wild. The out-of-bounds write in V8 can enable code execution from within Chrome's sandbox. Update Chrome on endpoints and managed client systems immediately.

09 Sep 2026 thehackernews.com
Security The Hacker News

cPanel patch fixes flaw that let mail-privileged account gain root

cPanel fixed a vulnerability that allowed an authenticated account with mail privileges to place files via EmailTrack and execute code with root privileges on the server. The advisory on September 8 says all supported cPanel and WHM versions were affected; administrators should apply the update immediately.

09 Sep 2026 thehackernews.com
Security The Register

Airport group's client-side JavaScript exposed API keys for four years

A researcher says Iterable credentials were left in front-end JavaScript over a four-year period with excessive privileges. Those keys could have exposed 8.8M customer records or allowed mass deletion; operators should avoid embedding secrets in client code, enforce least privilege and rotate keys.

09 Sep 2026 theregister.com
Security BleepingComputer

Over 36,000 internet-exposed Plex servers unpatched and vulnerable

More than 36,000 internet-facing Plex Media Server instances remain unpatched against multiple vulnerabilities and are exposed to potential attacks. Administrators should update Plex immediately, restrict or disable remote access, tighten network access controls and monitor logs.

09 Sep 2026 bleepingcomputer.com
Security BleepingComputer

ShieldCrash zero-day for Microsoft Defender enables SYSTEM access

An anonymous researcher using the name Nightmare Eclipse published a ShieldCrash exploit targeting Microsoft Defender that can achieve SYSTEM-level control. Because it appeared immediately after Microsoft's September 2026 Patch Tuesday, administrators should urgently review telemetry, isolate suspect hosts and follow Microsoft's guidance for mitigations.

09 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Google patches another actively exploited Chrome zero-day

Google released updates addressing 230 vulnerabilities, including a Chrome zero-day that is being exploited in the wild — the seventh Chrome zero-day fixed this year. MSPs and sysadmins should prioritize deploying browser updates across endpoints and monitor customer environments for related indicators.

09 Sep 2026 bleepingcomputer.com
Security The Register

Microsoft sets Patch Tuesday record with 974 CVEs

Microsoft's latest Patch Tuesday delivers fixes for 974 CVEs, a new high. Adobe also published important patches. MSPs and sysadmins should triage critical updates, test compatibility and schedule deployments to reduce exposure and avoid outages.

09 Sep 2026 theregister.com
Security The Hacker News

Slim Spider stole crypto custody secrets from a Brazilian financial institution

CrowdStrike has been tracking a financially motivated actor called Slim Spider active against Brazilian financial organizations since March 2026. The group reportedly exfiltrated crypto custody data from a Brazilian institution and shows detailed knowledge of local payments infrastructure. MSPs and sysadmins should review access controls, logging and incident response for finance or crypto customers.

08 Sep 2026 thehackernews.com
Security Krebs on Security

Microsoft fixes 974 security flaws in largest single patch batch

Microsoft released updates addressing at least 974 vulnerabilities across Windows and other software, marking its biggest single patch release to date. The company says AI is speeding vulnerability discovery, but many MSPs and organizations will struggle to prioritize testing and deploying so many fixes.

08 Sep 2026 krebsonsecurity.com
Security The Hacker News

3,400 BTC returned after Liquid exploit; network paused, ~598.5 BTC missing

An exploit in Elements led to a theft on the Liquid sidechain; the attacker returned 3,400 BTC while about 598.5 BTC (around $47M) remains unrecovered. Liquid is paused so L-BTC cannot be redeemed for BTC, posing custody and liquidity concerns that MSPs and admins should monitor.

08 Sep 2026 thehackernews.com
Security The Hacker News

ChatGPT flaw: a planted prompt could forward Gmail data to another account

Check Point Research demonstrated that a single injected instruction in a ChatGPT chat can make the model perform covert background actions while replying normally. In the PoC it read data from a connected Gmail account and sent it to a second ChatGPT account via a covert channel; MSPs should review OAuth scopes, connector permissions and audit logs.

08 Sep 2026 thehackernews.com
Security The Hacker News

FreeIPA flaw allows anonymous client to create administrator credentials

Red Hat warns that a chain of two bugs in FreeIPA and 389 Directory Server can let a never-logged-in client add a chosen Kerberos principal to the directory and gain administrators group access. This enables creation of reusable admin credentials; operators should apply updates, limit anonymous LDAP operations and review admin account security.

08 Sep 2026 thehackernews.com
Security BleepingComputer

DoppelCart network uses over 119,000 fake shops to steal card data

An operation called DoppelCart is running more than 119,000 domains hosting fake online stores to harvest payment card details. For MSPs and sysadmins this underscores the need for traffic monitoring, URL/DNS blocking, WAF protection and active certificate/ takedown tracking.

08 Sep 2026 bleepingcomputer.com
Security BleepingComputer

EU Cyber Resilience Act: knowing what shipped and when is critical

The EU Cyber Resilience Act takes effect on September 11 and may force vendors to report actively exploited flaws within as little as a single day. ActiveState warns that compliance will require precise records of what was shipped (component/version) and the exact discovery timeline for vulnerabilities.

08 Sep 2026 bleepingcomputer.com
Security The Hacker News

Adobe issues critical patch for Magento CVE-2026-75650 (StyleSmuggler)

Adobe released updates fixing a critical vulnerability affecting Adobe Commerce and Magento Open Source (CVE-2026-75650, CVSS 10.0). Sansec reports the flaw has been actively exploited since Sept 4, 2026 to install a Rust backdoor and a PHP web shell; administrators should apply patches immediately and scan systems for unauthorized files and outbound connections.

08 Sep 2026 thehackernews.com
Security The Hacker News

BengalSEO manipulates Bing results to distribute MayaBot and tech‑support scams

DFIR Report revealed in March 2026 a long-running SEO poisoning operation called BengalSEO, traced back to Rajasthan since 2015 and linked to two IT firms named WeConnect. The campaign skews Bing results to funnel users to MayaBot installers and fake tech‑support sites; MSPs and admins should monitor search-origin traffic, URL reputation and endpoint defenses.

08 Sep 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.