Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Industry The Register

Matt Clifford leaving ARIA amid concerns over Anthropic role conflict

Matt Clifford will step down from ARIA because of his role at Anthropic. MPs have welcomed the move but still demand explanations about how the conflict arose; this raises issues for those handling procurement, contracts and oversight in client infrastructures.

07 Sep 2026 theregister.com
Security The Register

US watchdog probes Tesla's Cybercab self-certification

A US regulator has opened an inquiry into Tesla's self-certification practices for the Cybercab model. The investigation may prompt tighter oversight that affects OTA updates, telematics access and compliance obligations—MSPs and sysadmins should review update pipelines, access control and logging for managed vehicle systems.

07 Sep 2026 theregister.com
Infrastructure / Cloud The Register

Nitter instances spared after legal review, XCancel restored

A public Nitter instance, XCancel, was taken down after receiving a legal notice from X Corp but has been brought back following legal advice, and maintainers say more instances will follow. For sysadmins this underlines the legal exposure of hosting public proxies for X content and the need to prepare logging, rate-limiting and takedown procedures before deploying.

07 Sep 2026 theregister.com
Security The Hacker News

Fourth urgent hotfix for N-able N-central in five weeks addressing unauthenticated RCE

N-able released Hotfix 4 for on-premises N-central builds older than 2026.3.1.14; systems patched to Hotfix 3 still require this update. The fix closes an unauthenticated RCE vulnerability, and N-able's incident notice says it has been exploited while the release notes call that unconfirmed. MSPs and admins should apply Hotfix 4 immediately.

07 Sep 2026 thehackernews.com
Industry The Register

Smartphone makers failing to meet EU repair transparency rules

Most new smartphones do not provide owners with the technical details or parts access needed for repairs, while vendors still present high repairability scores. For MSPs and admins this complicates asset lifecycle management, warranty handling and timely security updates for client devices.

07 Sep 2026 theregister.com
Security The Hacker News

JSCeal malware can bypass Google authentication using stolen session cookies

Check Point Research reports JSCeal is a compiled V8 JSC malware that harvests credentials and intercepts traffic. Obfuscated with javascript-obfuscator and techniques like RC4 string protection, it can use stolen session cookies to bypass Google authentication, raising session-hijack and detection challenges for managed environments.

07 Sep 2026 thehackernews.com
Security The Register

Welsh regulator NRW FoI error exposed diversity data of 2,000 staff

Natural Resources Wales accidentally published a spreadsheet five years ago that revealed diversity information for around 2,000 employees. NRW says its review found no evidence the data were misused; the incident is a reminder for admins and MSPs to tighten file handling, access controls and Freedom of Information processes.

07 Sep 2026 theregister.com
Security BleepingComputer

StyleSmuggler zero-day: Linux backdoor deployed against Magento/Adobe Commerce

A zero-day called StyleSmuggler is being exploited across all Magento and Adobe Commerce versions to install a Linux backdoor. For operators and MSPs this is critical: audit webstore hosts now, review logs and file changes, isolate suspicious instances, and monitor Adobe for security updates.

07 Sep 2026 bleepingcomputer.com
Security BleepingComputer

BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations

The phishing-as-a-service tool BigBear 2.0 bypassed MFA at 258 organizations and exfiltrated over 5,000 Microsoft 365 credentials. For MSPs and admins this underlines the need to harden identity controls, enforce conditional access and watch for suspicious session activity.

07 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Mathspace breach: Metabase compromise exposed data of over 1 million people

Online maths platform Mathspace disclosed that attackers accessed its Metabase internal reporting system and stole records for more than one million students, staff and parents. MSPs and sysadmins should review access controls, authentication and incident response for internal analytics tools to limit exposure.

07 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Trezor data breach hits 67,000 more U.S. customers, total now 81,000

Trezor reports that a breach at logistics partner ShipMonk in August exposed data for an additional 67,000 U.S. customers, bringing the affected total to 81,000. For MSPs and sysadmins this increases the risk of phishing, targeted social engineering and misuse of customer contact data; review notifications, MFA and monitoring controls.

07 Sep 2026 bleepingcomputer.com
Artificial Intelligence BleepingComputer

ChatGPT can now learn your writing style from connected apps

OpenAI is testing a 'Writing Style' feature for ChatGPT that analyzes examples from connected apps to model a user's writing. This matters for MSPs and admins because app integrations and permissions can expose data and enable impersonation, so review connections, access rights and audit logs.

07 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Two new MikroTik RouterOS flaws target routers with internet-facing SSH

A chain of two recently disclosed vulnerabilities is being used to gain unauthorized access to MikroTik RouterOS devices that have SSH reachable from the internet. MSPs and sysadmins should apply RouterOS patches promptly, restrict remote SSH exposure and monitor for suspicious sessions and configuration changes.

07 Sep 2026 bleepingcomputer.com
Artificial Intelligence BleepingComputer

OpenAI rolls out ChatGPT Astra to $20 Plus subscribers

OpenAI has started offering ChatGPT Astra to $20 Plus subscribers while free user availability remains unspecified. The stronger model may affect automation and support workflows for customer environments, so administrators should verify compatibility, benchmark performance, and assess any licensing or cost implications.

06 Sep 2026 bleepingcomputer.com
Security The Hacker News

MikroTik routers hijacked via internet-exposed SSH

CERT Polska warned on September 5 that MikroTik routers with SSH reachable from the internet are being abused to obtain administrative access without authentication, with incidents traced back to at least September 2. MSPs and sysadmins should audit internet-facing SSH, restrict or firewall access, and apply mitigations promptly.

06 Sep 2026 thehackernews.com
Security The Hacker News

REVSTEALER-linked modules disable Windows Update and Defender to run crypto miner

Elastic Security Labs found four modules tied to REVSTEALER that persist after the stealer removes itself, including ProManager, WinUpdate and SoftManager. One module disables Windows Update and Microsoft Defender before launching a cryptocurrency miner, creating persistence, resource drain and security exposure for managed systems.

06 Sep 2026 thehackernews.com
Security BleepingComputer

Attackers hide phishing lures with invisible Unicode characters

Threat actors are using ASCII smuggling to insert invisible Unicode characters into emails to obscure phishing URLs and evade email filters. MSPs and sysadmins should apply Unicode normalization, strip zero-width characters, tighten mail gateway rules, and monitor for obfuscated domains to detect and block these campaigns.

06 Sep 2026 bleepingcomputer.com
Infrastructure / Cloud The Register

Leap-second policy may change; UTC could shift by up to an hour

A timekeeping body is considering stopping leap-second insertions to avoid an unprecedented negative adjustment and instead allowing UTC to diverge from Earth rotation by up to one hour. For sysadmins and MSPs this can affect time sync, log correlation, authentication and other time-dependent systems — review NTP/chrony configuration, vendor guidance and any leap-smear options.

06 Sep 2026 theregister.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.