Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft reports that the ASCII smuggling method—known from AI prompt injection—has been repurposed to evade email defenses using invisible Unicode chars. Attackers insert hidden characters inside words to disrupt content scanning and signature detection, so mail flow rules, spam/antiphishing controls and detection/incident procedures should be reviewed.
HPE released a patch for a critical vulnerability in the ArubaOS-CX network OS that could enable remote code execution. MSPs and sysadmins should apply the update immediately; if patching isn't possible, restrict management access and monitor network traffic and device logs. Check the vendor advisory for affected versions.
A joint analysis by Citizen Lab and the SHARE Foundation found NSO Group's Pegasus on an iPhone owned by a Serbian student movement member, delivered via an iMessage attack that required no user interaction. Because zero-click compromises can evade typical defenses, MSPs and sysadmins should review mobile device management, patching and monitoring for related indicators.
Uber has stopped operating in Nigeria and Uganda. For MSPs and sysadmins this requires reviewing region-specific services: decommissioning or migrating endpoints, handling credential and billing fallout, and checking integrations with local payments and data residency commitments to avoid customer impact.
A recent Windows 11 update caused some desktops to switch unexpectedly to a dark theme or altered color settings. MSPs and sysadmins should identify affected devices and plan rollbacks or use Group Policy/Intune/SCCM to restore settings and control the update centrally.
A registry inspection prompted a renewed debate over whether the Windows 95 taskbar or the NeXT Dock came first; the evidence found does not support either being a direct predecessor. No immediate operational risk for admins, but a useful reminder that legacy artifacts and registry data can reveal surprising provenance details.
Researcher Chaotic Eclipse published a FalconFlank PoC that abuses the Office macro remediation mechanism in the CrowdStrike Falcon sensor to achieve local privilege escalation. This weakness could allow attackers to leverage endpoint protection to gain higher privileges and move within customer environments; MSPs and admins should monitor sensor updates and settings.
Microsoft says the known issue that restores mouse preferences after installing KB5120998 (August 2026 preview) occurs only on non-English Windows 11 builds. Admins and MSPs should test the preview before wide deployment or consider delaying to avoid user configuration loss.
OpenAI acknowledged a widespread outage affecting ChatGPT and Codex, with many features returning errors. The disruption occurred just before the 'Astra' model launch; MSPs and sysadmins should check API availability and prepare for higher support demand.
Anthropic's Claude service is currently experiencing an outage with requests failing across multiple models. If you operate services that depend on Claude, enable fallbacks, adjust retry logic and inform customers to limit disruption.
CISA added seven actively exploited vulnerabilities to its KEV list. A prominent entry is CVE-2026-83548 (CVSS 10.0), an SSRF in SonicWall SMA 1000 that can permit unauthenticated remote actors to install malware or spawn reverse shells. MSPs should prioritize patches and monitor traffic and signs of crypto-mining.
Microsoft reported that installing the KB5120998 (August 2026) preview can result in loss of desktop layout and user settings on some Windows devices. Administrators should test and back up profiles before wide deployment and consider delaying rollout until Microsoft issues a fix or guidance.
Plex reported multiple security flaws in its desktop applications and media servers and is urging immediate application of released patches. For MSPs and system admins, unpatched hosts could enable unauthorized access or service disruption, so apply updates promptly and review access logs and permissions.
Microsoft has identified that New Outlook and Microsoft Teams may crash or fail to launch on ARM-based Windows machines after the August 2026 security updates and is working on a fix. Administrators and MSPs should be prepared to roll back or block the problematic updates and follow Microsoft's guidance to restore service for affected customers.
Meta says it will publish Muse's weights soon and has trained the model to use fewer tokens and to be more likely to request assistance when needed. Open weights let MSPs and sysadmins run the model on their own infrastructure for better cost control and compliance, while token efficiency lowers inference expenses.
Major AI vendors unveiled cybersecurity-focused models including Google’s Gemini 3.8 Flash Cyber and introduced restricted-access programs for trusted defenders. These releases expand defensive tooling but raise operational questions for MSPs and admins about integration, data handling and vendor controls.
VMware says it has adjusted sales incentives that previously pushed customers toward full private clouds and is refocusing on lower-end server virtualization. Planned updates to vSphere Standard could affect licensing costs, migration choices and how MSPs manage existing infrastructure.
The Cyber Weapon Index report identified Claude Mythos as the sole examined model capable of carrying out a complete cyber kill chain, while other models handled only parts of an attack. For MSPs and sysadmins this raises urgency: AI-enabled attacks may accelerate, so review detection, access controls, patching and incident response processes.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.