Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Security The Hacker News

Mass-scanning campaign exploiting Vite flaw targets cloud credentials

Per F5 Labs, an automated campaign scanning publicly accessible Vite dev servers aims to harvest AWS and Microsoft Azure credentials, configurations, and infrastructure state files. For MSPs and sysadmins this is critical: secure dev environments, remove secrets from development hosts, restrict access and increase monitoring.

15 Sep 2026 thehackernews.com
Security BleepingComputer

Backdoor in Admin Menu Editor Pro affects ~1,500 WordPress sites

Malicious builds of the Admin Menu Editor Pro plugin were pushed after the maintainer's site was compromised, distributing to customers and installing a hidden administrator account on roughly 1,500 WordPress sites. MSPs and sysadmins should audit plugin versions, remove unknown users, and rotate credentials and keys.

15 Sep 2026 bleepingcomputer.com
Security Cloudflare

Finer access controls and restricted roles for Cloudflare Workers

Cloudflare now supports scoping access at the individual Worker level and assigning narrower Developer Platform roles. Team members, CI tokens and automation agents can be limited to only the permissions needed for debugging, deploying and monitoring, enforcing least-privilege. This helps lower misconfiguration and operational risk.

15 Sep 2026 blog.cloudflare.com
Artificial Intelligence Cloudflare

Cloudflare: stay searchable while blocking AI training

Cloudflare rolled out controls and an 'Accountable' label that let site owners keep pages indexed by search engines while opting out of use in AI training. Coordinated with Apple, Google and Microsoft, the change helps MSPs and admins separate indexing behaviour from model data use and adjust hosting policies.

15 Sep 2026 blog.cloudflare.com
Security BleepingComputer

CenterPoint Energy confirms theft of some customer data

CenterPoint Energy acknowledged a breach after an attacker allegedly leaked data taken from the utility, affecting some customer records. For MSPs and sysadmins this elevates risks like phishing, credential compromise and regulatory notifications; review access logs, permissions and customer communication plans.

15 Sep 2026 bleepingcomputer.com
Infrastructure / Cloud The Register

Mac and Unity-style layouts proposed for Xfce

The Xfce community is discussing proposals to add Mac- and Unity-like layouts, aiming to expand options beyond the current templates. For administrators, this could simplify standardizing user desktops, reduce training and deployment overhead, and let lightweight installations offer alternative interface styles.

15 Sep 2026 theregister.com
Artificial Intelligence The Register

Why "open weights" may not equal open source

Downloadable model weights often come without training code, datasets or clear licensing, so the "open" label can be misleading. For MSPs and admins this limits auditing, patching and customization and creates supply-chain, compliance and security risks; verify provenance and rights before deployment.

15 Sep 2026 theregister.com
Artificial Intelligence The Register

Everpure: AI solutions to prevent GPUs idling while waiting for data

Everpure offers AI tools designed to reduce GPU idle time when models are waiting for input. For MSPs and sysadmins this can lower GPU costs, improve throughput and latency, and introduce new considerations for resource planning and integration.

15 Sep 2026 theregister.com
Security BleepingComputer

CISA: Ransomware gangs exploiting critical VMware vCenter RCE

The U.S. CISA warned that ransomware groups are now exploiting a critical VMware vCenter remote code execution flaw patched in July. Service providers and administrators should confirm patches, review access logs and increase monitoring on management servers for suspicious activity.

15 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Five alleged Black Axe leaders extradited to the US

Five suspects tied to Black Axe were sent to the United States to face prosecution over alleged global cyber-enabled financial crimes and related laundering offenses. The case highlights that organized groups can run cross-border financial attacks; MSPs and sysadmins should strengthen monitoring, fraud controls and client authentication.

15 Sep 2026 bleepingcomputer.com
Security BleepingComputer

Microsoft confirms KB5002914 causes copy‑paste failures in Excel

Microsoft confirmed the September 2026 KB5002914 security update can cause copy-and-paste to silently fail for some Excel users. For MSPs and sysadmins this may disrupt workflows and raise support volume; test the update and prepare rollback or mitigation steps before wide deployment.

15 Sep 2026 bleepingcomputer.com
Artificial Intelligence The Register

Microsoft issues draft AI model guidelines and requests feedback

Microsoft published a draft of principles defining expected behaviours for AI models and invited public comment. The draft includes carve-outs that limit Microsoft’s accountability for model errors, so MSPs and sysadmins should review integration, monitoring and compliance implications for customer deployments.

15 Sep 2026 theregister.com
Security The Register

HBO Max Reddit account hijacked to serve ClickFix malvertising

Attackers took over HBO Max's official Reddit account to channel the ClickFix malvertising campaign. The incident was part of a short, high-intensity ad-driven infection wave aimed at macOS and Windows endpoints; MSPs and admins should review ad networks, account credentials and endpoint defenses.

15 Sep 2026 theregister.com
Security The Hacker News

DDRop undermines Intel TDX and AMD SEV‑SNP confidential computing

DDRop is a new hardware attack that blocks memory write operations so CPUs can keep reading stale encrypted data, undermining TDX and SEV‑SNP confidentiality. It requires an attacker who already controls server software and briefly gains physical access to attach a small circuit. Providers should harden physical access and follow vendor security updates.

14 Sep 2026 thehackernews.com
Security The Hacker News

MeshCentral backdoor gave root access in 3BB network; subscriber credentials targeted

An attacker gained persistent root-level remote control inside 3BB by exploiting a backdoor in the MeshCentral management tool, a breach uncovered by Hunt.io. An internet-exposed server left by the attacker stored their tools and lists of subscriber credentials; operators should audit remote-management access and credential protection.

14 Sep 2026 thehackernews.com
Security The Hacker News

Telegram Desktop flaw: JavaScript in HTML exports can exfiltrate messages

ExPatch reported a Telegram Desktop weakness that allowed a bot to embed hidden JavaScript into chats; the script executes when an exported HTML file is opened in a browser and can collect and transmit the messages contained in the file. For MSPs and admins this means exported chat archives can leak sensitive customer data; avoid opening HTML exports in browsers, inspect or sanitize files, and apply vendor fixes when available.

14 Sep 2026 thehackernews.com
Industry The Register

Oracle announces another round of layoffs after strong quarter

Despite strong AI cloud growth under Larry Ellison, Oracle has initiated another round of layoffs. MSPs and sysadmins should watch for effects on support, project continuity and contracts, while departures could also open hiring opportunities for experienced staff.

14 Sep 2026 theregister.com
Security The Hacker News

AI accelerated vulnerability discovery; validation and prioritization must adapt

AI-driven tools have increased the speed and scale of vulnerability discovery; 35,853 CVEs were published in H1 2026, roughly a 49% rise versus the prior period. MSPs and sysadmins must update validation and triage workflows to avoid alert fatigue and concentrate on genuine risks.

14 Sep 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.