Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft will deprecate the Similarity Checker built into Word next month. Administrators supporting schools or clients that rely on document plagiarism checks should review workflows, plan migrations and evaluate alternative tools or policies.
Canonical is trimming older community channels: the Ubuntu Pastebin closed in June and IRC will be deprioritized. MSPs and sysadmins should update their support contacts and migrate shared snippets or scripts to maintained platforms.
Microsoft will start rejecting mail from legacy Exchange Server installations that don't meet the October 2025 compatibility baseline for delivery to cloud mailboxes. Exchange Server 2016 and 2019 must be brought into compliance or their outgoing messages may be bounced. MSPs and sysadmins should review Microsoft's update and configuration guidance and prepare affected servers.
PostgreSQL 19 introduces a standardized graph-query syntax developed via multi-vendor collaboration, making it easier to handle graph data with SQL. Indexing and performance tuning are not fully mature yet, so query speed and scalability on large datasets may require extra attention.
The pnpm installer has been rebuilt in Rust and is offered as a backwards-compatible binary for existing projects. Expect faster, lower-memory installs in monorepos and CI; verify platform coverage, installation paths and signing/distribution steps before rolling out.
Wordfence telemetry shows heavy exploitation attempts against two critical vulnerabilities in Super Forms and Elementor Pro, recording over 440,000 intrusion attempts. CVE-2026-14894 in Super Forms stems from missing file type validation allowing unauthenticated arbitrary uploads; attackers may obtain RCE and compromise hosted sites, so MSPs and admins should apply patches or mitigations immediately.
Cloud print-and-post platform Docmail has been unavailable for a third day with no recovery ETA. The service supports over 30,000 UK organizations, including NHS bodies and medical clinics, and the provider has not announced a restoration schedule. MSPs should prepare manual mailing fallbacks and notify affected clients.
Plex released updates addressing multiple undisclosed vulnerabilities in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company requested CVE numbers and did not publish technical details, so administrators should apply the patches promptly and monitor affected systems.
Several lawsuits have been filed against identity verification vendor IDScan after an alleged breach that reportedly put over 153 million driver licenses up for sale. For MSPs and sysadmins this highlights risks to customer PII, regulatory notification obligations and the need to review vendor integrations and incident-response controls.
Google released Chrome updates fixing 12 flaws, including an actively exploited V8 vulnerability tracked as CVE-2026-85046 (CVSS 8.8), a type confusion issue. Administrators should update managed endpoints to at least 152.0.7977.82, enforce browser update policies and review logs/telemetry for signs of compromise.
Wayve and Uber have begun offering paid autonomous trips in London using 15 Mustangs, with a follow-up plan that may use a Nissan LEAF without a safety driver. Such fleets create operational and security demands for MSPs and sysadmins, including low-latency networking, edge/cloud compute, secure OTA updates, telemetry handling and regulatory compliance.
OpenAI unveiled GPT-6 Astra, which recorded 100% in ExploitBench and the company is restricting PoC exploit requests. For admins this raises alarms: powerful LLMs can accelerate vulnerability discovery and exploit automation — tighten model access, patching and monitoring for customer systems.
The Register reported a Windows 10 update-themed event held at London's O2 that treated updates as a spectacle. For server admins and MSPs this is a reminder to validate updates, schedule maintenance windows and communicate proactively to reduce customer impact.
Vulnerability intelligence firm Previdian reports active exploitation of CVE-2026-19490, a critical authentication bypass in Citrix NetScaler. Managed appliances could allow unauthorized access and lateral movement—patch devices, restrict management access and apply Citrix's guidance without delay.
A US law firm representing a customer says a UK telecom AI supplier renewed the contract as the customer tried to exit and that the solution was unreliable. The vendor has separately sued over unpaid fees; admins should check auto-renew clauses, SLAs and evidence retention.
Microsoft is addressing an issue on Windows that delays or prevents some users from launching the Microsoft Teams desktop app. For MSPs and sysadmins this can disrupt user access and raise support load; temporary options include using the web or mobile clients, restarting the app, and checking service health.
Under Project PANOPTES the UK defense establishment is funding vehicle-mounted autonomous laser systems with £5M to counter drone swarms. For data center and client-site operators this raises issues around physical protection options, potential EM/laser interactions and compliance or procurement implications.
Researchers documented 39 techniques that can undermine passkey-based authentication; attackers can exploit consent prompts, synced credentials, enrollment and recovery flows and other trust boundaries while leaving FIDO2 cryptography intact. For admins and MSPs this means reviewing UI prompts, sync and recovery implementations and threat models to mitigate practical bypasses.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.