Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Google says extortion actors are moving to target AI training data, models and prompt repositories as high-value assets. Theft can expose customer IP and trigger ransom demands, so MSPs and sysadmins should harden access controls, encryption, network segmentation, exfiltration detection and incident response.
Grindr agreed to pay £26M to resolve a UK class action while denying liability. Because allegations involved health data — including HIV status — and sharing with third parties, MSPs and admins should review data flows, vendor contracts and compliance controls.
Threat actors are moving beyond AI coding assistants to multi-agent AI setups that automate every phase of intrusions to harvest credentials at scale. MSPs and sysadmins should expect faster, higher-volume credential theft and prioritize MFA, least-privilege controls, endpoint monitoring and detection of automation-driven behaviors.
A Vietnam-linked Advance Passenger Information System (APIS) database exposed 220 million passenger and crew records from 2017–2026, including sensitive fields such as names, passport numbers, birth dates, nationalities and flight details. Researchers reached the cloud-hosted system using default credentials; MSPs and admins should audit cloud access, enforce credential hygiene and tighten data storage controls.
Researchers disclosed PEEP, a Chromium-based post-exploitation toolkit that injects an extension into browser profiles to establish persistent backdoors on Chrome and Edge. It needs prior admin or code-execution access; attackers forge Chromium's Secure Preferences to bypass Web Store checks and user prompts, enabling host command execution.
Threat actors impersonate IT support and target executives to steal data from Microsoft 365 and other SaaS accounts for extortion. The campaign uses vishing, AitM token theft and logins via residential proxies to evade protections. MSPs and admins should tighten help-desk procedures, enforce phishing-resistant MFA and monitor anomalous sessions.
This week included a Chrome zero‑day, router hijacking campaigns, and credential‑stealing code distributed via a trusted developer supply chain. Attackers also used text‑based QR codes in emails to bypass image blocking. MSPs and admins should prioritize patching, auditing third‑party components and tightening network device access.
A US regulator has opened an inquiry into Tesla's self-certification practices for the Cybercab model. The investigation may prompt tighter oversight that affects OTA updates, telematics access and compliance obligations—MSPs and sysadmins should review update pipelines, access control and logging for managed vehicle systems.
N-able released Hotfix 4 for on-premises N-central builds older than 2026.3.1.14; systems patched to Hotfix 3 still require this update. The fix closes an unauthenticated RCE vulnerability, and N-able's incident notice says it has been exploited while the release notes call that unconfirmed. MSPs and admins should apply Hotfix 4 immediately.
Check Point Research reports JSCeal is a compiled V8 JSC malware that harvests credentials and intercepts traffic. Obfuscated with javascript-obfuscator and techniques like RC4 string protection, it can use stolen session cookies to bypass Google authentication, raising session-hijack and detection challenges for managed environments.
Natural Resources Wales accidentally published a spreadsheet five years ago that revealed diversity information for around 2,000 employees. NRW says its review found no evidence the data were misused; the incident is a reminder for admins and MSPs to tighten file handling, access controls and Freedom of Information processes.
A zero-day called StyleSmuggler is being exploited across all Magento and Adobe Commerce versions to install a Linux backdoor. For operators and MSPs this is critical: audit webstore hosts now, review logs and file changes, isolate suspicious instances, and monitor Adobe for security updates.
The phishing-as-a-service tool BigBear 2.0 bypassed MFA at 258 organizations and exfiltrated over 5,000 Microsoft 365 credentials. For MSPs and admins this underlines the need to harden identity controls, enforce conditional access and watch for suspicious session activity.
Online maths platform Mathspace disclosed that attackers accessed its Metabase internal reporting system and stole records for more than one million students, staff and parents. MSPs and sysadmins should review access controls, authentication and incident response for internal analytics tools to limit exposure.
Trezor reports that a breach at logistics partner ShipMonk in August exposed data for an additional 67,000 U.S. customers, bringing the affected total to 81,000. For MSPs and sysadmins this increases the risk of phishing, targeted social engineering and misuse of customer contact data; review notifications, MFA and monitoring controls.
A chain of two recently disclosed vulnerabilities is being used to gain unauthorized access to MikroTik RouterOS devices that have SSH reachable from the internet. MSPs and sysadmins should apply RouterOS patches promptly, restrict remote SSH exposure and monitor for suspicious sessions and configuration changes.
CERT Polska warned on September 5 that MikroTik routers with SSH reachable from the internet are being abused to obtain administrative access without authentication, with incidents traced back to at least September 2. MSPs and sysadmins should audit internet-facing SSH, restrict or firewall access, and apply mitigations promptly.
Elastic Security Labs found four modules tied to REVSTEALER that persist after the stealer removes itself, including ProManager, WinUpdate and SoftManager. One module disables Windows Update and Microsoft Defender before launching a cryptocurrency miner, creating persistence, resource drain and security exposure for managed systems.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.