Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft observed attackers abusing Microsoft Teams external collaboration to pose as IT support, obtain remote sessions and deploy a Node.js implant to move laterally across networks. Because legitimate collaboration and support tools are used, MSPs and admins should review external sharing controls, remote-support policies and Microsoft Defender detections.
Microsoft Threat Intelligence found an attack using Microsoft Teams external collaboration to trick victims into remote sessions under the guise of IT support. Attackers install a Node.js-based implant and use legitimate tools to move laterally; Microsoft Defender telemetry and blocking can help detect and stop the activity. Service providers should validate external sessions and monitor Defender alerts.
According to Microsoft, an active campaign uses fake download sites that impersonate trusted vendors to deliver malicious installers. Those installers turn off Windows Update and weaken Microsoft Defender settings, causing exposure across many organizations—especially China-based operations and Chinese-speaking users.
Manifold Security disclosed eight vulnerabilities across seven CLI AI coding agents; four remain unpatched. A malicious repository .git config can cause an agent to run a local command on the developer's machine outside its sandbox and without prompting, using the user's privileges. MSPs and sysadmins should treat untrusted repos cautiously and keep affected tools updated.
Attackers are exploiting an unauthenticated SQL injection (CVE-2026-9586) in Sangoma Switchvox to achieve remote code execution and install reverse shells on compromised devices. Administrators should apply vendor fixes, limit exposure with access controls or WAFs, and monitor logs and unusual connections.
The debate about whether AI adds business value is settled; the priority is deploying it securely at scale. As boards demand speed, service providers and sysadmins must prioritise model access controls, monitoring, supply-chain security and incident response to keep cyber risk under control.
SonicWall issued security updates for two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. Discovered by William Perry and Adam Babis, one flaw is CVE-2026-83548 (CVSS 10.0) — a pre-auth SSRF — and the issues can be chained for remote compromise; operators should patch immediately.
An SQL injection flaw in the All-in-One WP Migration and Backup plugin can let unauthenticated attackers execute code remotely and take over websites. MSPs and sysadmins should urgently update or remove the plugin, review logs and backups, and investigate any potential compromises.
Two vulnerabilities in GeoNetwork can be chained to enable remote code execution without authentication; the software is used behind many government geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026 and published details on August 31, 2026. Patch promptly and audit any hosted GeoNetwork instances.
A recent Microsoft update broke Outlook and Teams on ARM-based Windows PCs, with some users unable to start the apps. Installing an 'AI gaming package' provides a temporary workaround in certain cases, while the update also reset custom cursor settings. MSPs should prepare support steps, rollback options, and watch for an official fix.
A cloud engineer had to relocate a datacenter with a minimal budget while shipping delays (FedEx) and DNS misconfigurations complicated the effort. For MSPs and sysadmins this underlines the importance of factoring logistics, hardware delivery risks and DNS resilience into migration plans.
Ookla data shows mobile connectivity in London Tube tunnels has been improved so 5G coverage now exceeds the city average. This improves continuity for underground IoT and emergency comms, and opens opportunities for MSPs to provide coverage, backhaul and DAS services to transit and venue customers.
A critical authentication bypass (CVE-2026-82329) in JFrog Artifactory is being actively exploited to allow attackers to generate tokens with administrative privileges. Administrators should apply the vendor patch immediately, revoke or rotate existing tokens, and review access logs for suspicious activity.
Microsoft Defender for Office 365 is classifying certain legitimate Google search links as malicious and blocking access. Microsoft is investigating; MSPs and admins should review email/web filters, quarantine logs and whitelists and monitor updates to prevent user impact.
A California grand jury indicted a Russian national accused of infecting about 80,000 freelancers with TVRAT and DarkVNC via phishing. For MSPs and admins this underlines the danger of remote-access trojans: credential theft, covert remote control and data exposure — review email filtering, endpoint detection and enforce MFA.
Law enforcement and private partners executed an operation that seized key components of the Sality peer-to-peer (P2P) botnet and disrupted its distribution network. MSPs and sysadmins should scan and clean affected hosts, monitor network traffic, and apply patches to reduce risk of reinfection.
Shipments of LTO magnetic tapes declined by 16 exabytes in 2025. The LTO program interprets the drop as a temporary market or supply blip rather than permanent obsolescence; sysadmins should recheck capacity, inventory and long‑term backup plans.
A joint action disrupted Sality's command infrastructure and routed infected traffic to sinkhole servers. MSPs should scan and remediate infected endpoints, monitor DNS and network logs, and ensure AV and patching are up to date for customers.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.