Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

OpenAI's GPT-6 Astra scores 100% on ExploitBench as PoC requests blocked

OpenAI unveiled GPT-6 Astra, which recorded 100% in ExploitBench and the company is restricting PoC exploit requests. For admins this raises alarms: powerful LLMs can accelerate vulnerability discovery and exploit automation — tighten model access, patching and monitoring for customer systems.

04 Sep 2026 thehackernews.com
Security BleepingComputer

CVE-2026-19490: Critical authentication bypass in Citrix NetScaler being exploited

Vulnerability intelligence firm Previdian reports active exploitation of CVE-2026-19490, a critical authentication bypass in Citrix NetScaler. Managed appliances could allow unauthorized access and lateral movement—patch devices, restrict management access and apply Citrix's guidance without delay.

04 Sep 2026 bleepingcomputer.com
Security The Register

UK military seeks £5M for laser systems to stop drone swarms

Under Project PANOPTES the UK defense establishment is funding vehicle-mounted autonomous laser systems with £5M to counter drone swarms. For data center and client-site operators this raises issues around physical protection options, potential EM/laser interactions and compliance or procurement implications.

04 Sep 2026 theregister.com
Security BleepingComputer

39 new methods put passkey authentication at risk

Researchers documented 39 techniques that can undermine passkey-based authentication; attackers can exploit consent prompts, synced credentials, enrollment and recovery flows and other trust boundaries while leaving FIDO2 cryptography intact. For admins and MSPs this means reviewing UI prompts, sync and recovery implementations and threat models to mitigate practical bypasses.

04 Sep 2026 bleepingcomputer.com
Security BleepingComputer

New FalconFlank zero-day grants SYSTEM privileges in CrowdStrike Falcon

An anonymous researcher using the 'Nightmare Eclipse' handle released a zero-day called 'FalconFlank' targeting CrowdStrike Falcon. The exploit can elevate to SYSTEM on up-to-date Windows hosts; MSPs and administrators should verify detections, review telemetry and follow vendor guidance.

04 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Google patches Chrome V8 zero-day exploited in the wild

Google released a Chrome update that fixes a high-severity zero-day in the V8 engine being actively exploited, along with 11 other vulnerabilities. Administrators and MSPs should prioritize deploying the update to managed endpoints and review the release notes for mitigations and indicators.

04 Sep 2026 bleepingcomputer.com
Security The Register

Cisco rolled many IOS XR fixes into a single update

Cisco issued a consolidated update for IOS XR that fixes multiple vulnerabilities, including three rated critical. One issue affects Nexus 9000 Series Switches and can allow privilege escalation; only mitigations exist until the release is applied. MSPs and sysadmins should test and deploy the update promptly and enable interim mitigations.

04 Sep 2026 theregister.com
Security The Register

OpenAI allocates $1B in AI credits to frontline cyber defenders

Through the Daybreak program OpenAI is providing $1B in AI credits along with discounted models, training and support to frontline cyber teams. Managed service providers and sysadmins can use this to boost detection, automation and incident response, but should assess integration, data privacy and vendor-dependence risks.

04 Sep 2026 theregister.com
Security The Hacker News

CEO phishing kits, 5K Dropbox account breaches and OAuth consent traps

The ThreatsDay roundup highlights CEO phishing kits, roughly 5,000 compromised Dropbox accounts and attacks abusing OAuth consent. Adversaries exploit ordinary channels—calls, shared files and seemingly trusted apps—so a single mistaken consent or click can be enough. MSPs and sysadmins should audit OAuth apps, enforce MFA and scan incoming shares and links.

03 Sep 2026 thehackernews.com
Security The Hacker News

CVE-2026-20212 in Cisco Nexus 9000: remote root-level code execution

Cisco released patches addressing CVE-2026-20212, which affects 10 Silicon One-based Nexus 9000 switches and can allow an unauthenticated remote attacker to gain root-level code execution. Cisco also issued an IOS XR hardening bundle covering seven umbrella CVEs, two rated 9.8, with no workaround for IOS XR versions. Apply updates immediately.

03 Sep 2026 thehackernews.com
Security Cloudflare

Context-aware vulnerability discovery and remediation with Cloudflare and OpenAI Daybreak

Cloudflare Managed Defense combines OpenAI Daybreak models with WAF data and production traffic signals to rank vulnerabilities by risk. The capability can stage edge mitigations and propose code patches to address top threats first. This helps operators reduce exposure faster and streamline patch workflows.

03 Sep 2026 blog.cloudflare.com
Security The Hacker News

BraZetsu malware turns Windows hosts into marketable access inventory

Researchers reported that BraZetsu, a Python-based Windows malware framework, converts compromised systems into inventory for underground markets. Its modular features let Initial Access Brokers package access and sustain persistence and lateral movement; MSPs and sysadmins should prioritize patching, access controls and behavior-based detection.

03 Sep 2026 thehackernews.com
Security The Hacker News

Thomson Reuters C-Track breach: files accessed in March 2026

Thomson Reuters says an unauthorized actor obtained files from its West Publishing C-Track court case platform in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands and Ontario. The company detected the activity on June 30, 2026 and warns a portion of records may include names and other sensitive or sealed data.

03 Sep 2026 thehackernews.com
Security BleepingComputer

CNIL fines Hôpital privé de la Loire €500,000 after 727,000 records exposed

France's data protection authority CNIL penalized Hôpital privé de la Loire €500,000 after an incident that exposed about 727,000 patient and relative records. For MSPs and sysadmins this highlights regulator enforcement risk and the importance of access controls, encryption, logging and compliance practices.

03 Sep 2026 bleepingcomputer.com
Security The Hacker News

RMM phishing campaign spans 46 countries; US most targeted

A campaign using Canada Revenue Agency (CRA) forms as bait has expanded to 46 countries, with roughly 45% of observed activity focused on the United States. ANY.RUN linked 601 incidents to the operation. Targeting remote management tools, these attacks pose direct access and supply-chain risks for MSPs and server admins.

03 Sep 2026 thehackernews.com
Security The Hacker News

Attackers abuse Node.js node.exe to deliver malware

A Symantec Threat Hunter Team report says that since February 2026 threat actors have used node.exe to deliver malicious payloads in targeted campaigns against government departments, tech firms and hotels. For admins this shows trusted runtimes can be abused to evade defenses; tighten application integrity, binary signing and process/network monitoring.

03 Sep 2026 thehackernews.com
Security The Hacker News

Shai-Hulud infostealer now targets 469 credential locations

GitGuardian found a Shai-Hulud variant that expanded its search surface from 189 to 469 locations across developer setups, CI/CD tooling, cloud configs and AI tool settings. For MSPs and sysadmins this widens the secret-exposure risk; implement secret scanning, rotate keys, tighten CI/CD tokens and monitor for abnormal activity.

03 Sep 2026 thehackernews.com
Security BleepingComputer

Coder registry infrastructure breached, malicious Terraform modules distributed

Attackers gained access to Coder's Cloudflare and provisioned rogue registry hosts that served Terraform modules with credential-stealing code. Systems that automatically pull or apply modules and customer environments are at risk; verify module origins, rotate affected credentials, and scan fetched packages.

03 Sep 2026 bleepingcomputer.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.