Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
The Register partner content reviews eSIM providers for travel in 2026, focusing on cost versus the services offered. This matters for MSPs and sysadmins because roaming connectivity, device compatibility, remote provisioning and expense controls influence how corporate devices are managed abroad.
An anonymous researcher using the 'Nightmare Eclipse' handle released a zero-day called 'FalconFlank' targeting CrowdStrike Falcon. The exploit can elevate to SYSTEM on up-to-date Windows hosts; MSPs and administrators should verify detections, review telemetry and follow vendor guidance.
Microsoft is addressing an Exchange Online outage that is causing delays and 'Server busy' errors for mail exchanged with outside domains. MSPs and admins should inform customers, monitor Service Health, and have fallback routing or communication plans ready.
Google released a Chrome update that fixes a high-severity zero-day in the V8 engine being actively exploited, along with 11 other vulnerabilities. Administrators and MSPs should prioritize deploying the update to managed endpoints and review the release notes for mitigations and indicators.
A search engine that promises tree planting has released a Linux browser intended to offer Europe an alternative to big tech. The increase of Linux desktop share in the EU to 5.7% between 2024 and 2025 means more client systems may run Linux, affecting browser compatibility, support and deployment choices.
Cisco issued a consolidated update for IOS XR that fixes multiple vulnerabilities, including three rated critical. One issue affects Nexus 9000 Series Switches and can allow privilege escalation; only mitigations exist until the release is applied. MSPs and sysadmins should test and deploy the update promptly and enable interim mitigations.
Through the Daybreak program OpenAI is providing $1B in AI credits along with discounted models, training and support to frontline cyber teams. Managed service providers and sysadmins can use this to boost detection, automation and incident response, but should assess integration, data privacy and vendor-dependence risks.
The ThreatsDay roundup highlights CEO phishing kits, roughly 5,000 compromised Dropbox accounts and attacks abusing OAuth consent. Adversaries exploit ordinary channels—calls, shared files and seemingly trusted apps—so a single mistaken consent or click can be enough. MSPs and sysadmins should audit OAuth apps, enforce MFA and scan incoming shares and links.
Cisco released patches addressing CVE-2026-20212, which affects 10 Silicon One-based Nexus 9000 switches and can allow an unauthenticated remote attacker to gain root-level code execution. Cisco also issued an IOS XR hardening bundle covering seven umbrella CVEs, two rated 9.8, with no workaround for IOS XR versions. Apply updates immediately.
Cloudflare Managed Defense combines OpenAI Daybreak models with WAF data and production traffic signals to rank vulnerabilities by risk. The capability can stage edge mitigations and propose code patches to address top threats first. This helps operators reduce exposure faster and streamline patch workflows.
Researchers reported that BraZetsu, a Python-based Windows malware framework, converts compromised systems into inventory for underground markets. Its modular features let Initial Access Brokers package access and sustain persistence and lateral movement; MSPs and sysadmins should prioritize patching, access controls and behavior-based detection.
Thomson Reuters says an unauthorized actor obtained files from its West Publishing C-Track court case platform in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands and Ontario. The company detected the activity on June 30, 2026 and warns a portion of records may include names and other sensitive or sealed data.
France's data protection authority CNIL penalized Hôpital privé de la Loire €500,000 after an incident that exposed about 727,000 patient and relative records. For MSPs and sysadmins this highlights regulator enforcement risk and the importance of access controls, encryption, logging and compliance practices.
A campaign using Canada Revenue Agency (CRA) forms as bait has expanded to 46 countries, with roughly 45% of observed activity focused on the United States. ANY.RUN linked 601 incidents to the operation. Targeting remote management tools, these attacks pose direct access and supply-chain risks for MSPs and server admins.
A Symantec Threat Hunter Team report says that since February 2026 threat actors have used node.exe to deliver malicious payloads in targeted campaigns against government departments, tech firms and hotels. For admins this shows trusted runtimes can be abused to evade defenses; tighten application integrity, binary signing and process/network monitoring.
GitGuardian found a Shai-Hulud variant that expanded its search surface from 189 to 469 locations across developer setups, CI/CD tooling, cloud configs and AI tool settings. For MSPs and sysadmins this widens the secret-exposure risk; implement secret scanning, rotate keys, tighten CI/CD tokens and monitor for abnormal activity.
Attackers gained access to Coder's Cloudflare and provisioned rogue registry hosts that served Terraform modules with credential-stealing code. Systems that automatically pull or apply modules and customer environments are at risk; verify module origins, rotate affected credentials, and scan fetched packages.
Invisible Unicode characters once used to hide instructions from AI models are now being applied to break up words inside emails so phishing and spam filters miss them. MSPs and admins should normalize and strip Unicode, add detection beyond simple signatures, and improve monitoring and user awareness to reduce successful evasions.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.