Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft Threat Intelligence reports the campaign tracked as TerminalFix tricks users with fake CAPTCHAs, uses DLL sideloading to load malicious components, then establishes a reverse tunnel for remote access. This enables stealthy, persistent access to servers and customer environments; Microsoft published detection and hunting guidance.
Berlin's state government said it will not pay extortionists after a breach of its state administrative network in August. Forensics uncovered additional data exfiltration affecting the senate department responsible for mobility, transport, climate and environment. MSPs and admins should review access logs, backups and watch for indicators of data leakage in client environments.
Cosmos Labs reported that a critical balance-handling bug in the shared Cosmos EVM module was exploited from August 20–25, 2026 to siphon funds from six blockchains. The issue is tracked as GHSA-7g4w-cg88-2cq2 and no CVE, weakness classification or CVSS score was published; operators should verify affected nodes, apply vendor patches, monitor transactions for anomalies and review key security.
A researcher demonstrated that Claude Code can execute hidden malicious instructions when asked to summarize a webpage, revealing a prompt-injection weakness. This behavior poses risks to client data and automated workflows; operators should validate inputs, sanitize content and filter outputs.
Two chained vulnerabilities in PaperCut NG and MF could allow unauthenticated attackers to run Java code by tampering with the trusted configuration. The vendor released an emergency patch and added hardening. Administrators should deploy the update promptly and restrict access to PaperCut configuration and print services.
Researchers in Germany and Japan have introduced a cooling approach that works without electricity and could lower datacenter cooling demands. For MSPs and sysadmins this could cut energy costs and improve resilience during outages, but real-world deployment, scaling and integration need further work.
Android 17 adds Encrypted Client Hello (ECH) across the OS to stop network operators from seeing which websites users access. Google also announced additional network protections to address cellular weaknesses and bolster home-network privacy. MSPs and admins should expect reduced visibility for network-based filtering and TLS inspection and plan alternative endpoint or logging controls.
Cloud professionals mocked a portrayal of AWS Route 53 presented with a file-system-like concept. For infrastructure teams this is a reminder to scrutinize DNS feature descriptions and integration assumptions, since misinterpretation can lead to configuration or compatibility issues.
CISA added the critical ownCloud flaw CVE-2023-49105 (CVSS 9.8) to its KEV list after a Chinese-speaking actor exploited it to exfiltrate records from a Philippine nuclear research body. MSPs and sysadmins running ownCloud should apply patches immediately, review logs and indicators for compromise, and tighten access controls.
Researchers identified 18 Google Chrome and 1 Microsoft Edge extensions published over the past six months that include components able to exfiltrate browser wallet keys and drain crypto funds. Similar code and tactics point to an organized campaign that may remain active; sysadmins and MSPs should tighten extension policies, use allowlists and block suspicious add-ons.
McKesson reported unauthorized access to third-party applications and that the ShinyHunters group claims to have taken 284 million patient records. Providers and sysadmins should urgently review third-party integrations, access rights, credentials, logging/monitoring, and have incident response and notification procedures ready.
LibreOffice 26.8 has been released; the update prioritizes running on the end user's machine and does not include AI-based features. Administrators and MSPs should review packaging, deployment paths and data-privacy implications before rolling it out to clients.
Researcher Olivier Laflamme disclosed two separate root RCE chains affecting the Unitree G1 EDU. Tracked as CVE-2026-76639 and CVE-2026-76640, one route leverages BLE to reach the robot's Locomotion PC while the other abuses chat_go and bashrunner via a network-adjacent vector. This allows full control and potential lateral movement, so operators and MSPs should prioritize isolation and patching.
The Green Party proposes removing blanket critical-infrastructure status for datacentres and halting new builds until their water and energy impacts are clarified. For providers and MSPs this could mean project delays, shifts in capacity planning and procurement, and a need to produce clearer sustainability and resource-management documentation.
A US IT specialist pleaded guilty to leaking state secrets after contacting a foreign government shortly after being assigned to a DIA insider-threat unit. Insider risks from staff with privileged access are critical for MSPs and sysadmins; enforce strong access controls, session logging and separation of duties.
Identity Fabric brings together dispersed identity systems to track how identities act across apps, APIs and infrastructure. As cloud services and automated workloads grow, runtime visibility and centralized control become essential; without them unmanaged service accounts and privilege misuse become bigger risks.
ServiceNow released fixes for four vulnerabilities affecting the ServiceNow AI Platform; three are rated CVSS 10.0 and, in certain scenarios, can be exploited by unauthenticated actors to execute code or SQL. The vendor applied updates to hosted tenants and provided patches to partners and self‑managed customers, so unpatched self‑hosted deployments remain exposed.
VulnCheck discovered two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, in firmware for Shenzhen Zhibotong Electronics (ZBT) routers. Both allow unauthenticated remote execution of commands with root privileges (CVE-2026-74232, CVE-2026-74233). Inventory affected units, isolate vulnerable devices, restrict access and follow vendor advisories.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.