Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 45 stories last updated 29.07.2026 12:45
Security BleepingComputer

vBulletin fixes critical pre-auth RCE flaw; public exploit released

A critical flaw in vBulletin allows unauthenticated attackers to run PHP via template processing and a patch has been released. A public exploit is available, so administrators managing forums should apply the update immediately.

28 Jul 2026 bleepingcomputer.com
Infrastructure / Cloud Cloudflare

Q2 2026: Natural disasters, government shutdowns and DNSSEC key rollovers' impact on the Internet

Cloudflare Radar used traffic telemetry to analyze how natural disasters, government-ordered shutdowns and DNSSEC key rollovers affected connectivity in Q2 2026. For MSPs and sysadmins the takeaway is clear: ensure DNS resilience, multi-path network design, active monitoring and concrete failover plans to handle regional or policy-driven outages.

28 Jul 2026 blog.cloudflare.com
Security BleepingComputer

Is your SSO resilient to modern credential attacks?

A single compromised SSO login can give attackers access to multiple enterprise applications. Specops Software recommends stronger passwords, phishing-resistant MFA and identity hardening to reduce risk; MSPs and admins should prioritize user controls and configuration checks to protect customer environments.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

20-year-old BMC flaw leaks password hashes on over 24,000 servers

A two-decade-old vulnerability in BMC interfaces has exposed authentication hashes on more than 24,000 internet-reachable servers. Providers and admins should inventory and isolate exposed BMCs, apply firmware updates or patches, rotate credentials, and restrict network access to block attacker access.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

MCBS breach exposes data of 1.26 million people

Medical Computer Business Services (MCBS) disclosed a 2025 network breach that affected sensitive information for more than 1.26 million people. The incident underlines the need for providers and admins to prioritise third‑party risk management, encryption, access controls and incident detection/response.

28 Jul 2026 bleepingcomputer.com
Security BleepingComputer

FastJson zero-day RCE exploited against US companies

A zero-day flaw in the FastJson Java library is being abused to execute code remotely without authentication or user interaction, with attackers focusing on US firms. Infrastructure teams should urgently apply updates, tighten WAF/IPS protections and restrict incoming traffic to mitigate risk.

27 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Arista patches zero-day in VeloCloud Orchestrator exploited in active attacks

Arista issued a patch for a command-injection zero-day affecting on-prem VeloCloud Orchestrator that has been exploited in the wild. MSPs and sysadmins should apply the update immediately, isolate management interfaces, rotate credentials, audit logs for suspicious activity, and tighten network access controls.

27 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Dysphoria botnet spreads to 200,000 devices, used for DDoS and traffic relay

The Dysphoria botnet has taken control of about 200,000 devices worldwide to conduct DDoS attacks and relay traffic. MSPs and sysadmins should watch for unusual outbound traffic and abuse, ensure vulnerable devices are patched or isolated, and apply edge filtering or rate limits to reduce impact.

27 Jul 2026 bleepingcomputer.com
Security Microsoft

Microsoft unveils Project Perception, a security stack for the AI era

Microsoft introduced Project Perception as a new cyber security stack tailored for the AI era. As AI workloads and threats evolve, telemetry, detection and control models need updating; managed service providers and sysadmins should plan for greater visibility and automation.

27 Jul 2026 blogs.microsoft.com
Artificial Intelligence Microsoft

Microsoft's EXTRA global AI red teaming program

Microsoft brings together universities, researchers and regional experts under EXTRA, a global red teaming effort. The program aims to surface emerging AI risks, improve security testing and harden frontier models — a signal for MSPs and sysadmins to review testing, monitoring and incident response for AI-related threats.

27 Jul 2026 microsoft.com
Security Cloudflare

Cloudflare open-sources pvcli CLI for testing OHTTP and privacy protocols

Cloudflare published pvcli as an open-source command-line tool that offers a curl-like interface to simplify testing of privacy protocols such as OHTTP. For server admins and MSPs it helps validate implementations, simulate requests, troubleshoot privacy proxies and integrate tests into automation.

27 Jul 2026 blog.cloudflare.com
Infrastructure / Cloud Cloudflare

BGP ORIGIN attribute rewrites affect roughly 70% of transit paths

Cloudflare testing shows transit providers rewrite the ORIGIN attribute to shift traffic, impacting about 70% of BGP paths. This can skew route selection and enable traffic steering—operators should audit transit policies, reduce reliance on ORIGIN for path choice, and monitor for unexpected routing shifts.

24 Jul 2026 blog.cloudflare.com
Infrastructure / Cloud Cloudflare

Cloudflare Cache Response Rules for controlling edge caching

Cloudflare's Cache Response Rules let you change how edge caches handle response headers from the origin. When headers like Set-Cookie or Cache-Control cause responses to bypass cache, you can override that behavior at the edge to keep responses cached, reduce origin load and latency, and avoid changing the backend.

23 Jul 2026 blog.cloudflare.com
Security Microsoft

Q2 2026 email threats: trends after Tycoon2FA disruption

Microsoft's action against Tycoon2FA coincided with declines in several common phishing methods. Attackers moved into Teams-based social engineering and increasingly used automated, multi-stage attack chains; MSPs and sysadmins should monitor Teams traffic, automation indicators and multi-stage attack signs rather than rely solely on email filters.

23 Jul 2026 microsoft.com
Security Microsoft

Microsoft and AXA XL launch collaboration on incident response

Microsoft is partnering with AXA XL to provide cyber insurance policyholders access to Microsoft Incident Response services. The alliance is designed to help organizations coordinate technical response, business actions and insurance workflows to strengthen resilience against incidents.

22 Jul 2026 microsoft.com
Security Krebs on Security

LG to ban residential proxy use in smart TV apps

LG Electronics USA plans to suspend smart TV apps that turn televisions into always-on residential proxy nodes. Researchers found about 42% of apps in the webOS store allowed third parties to route users' traffic, creating bandwidth, security and abuse risks that MSPs should watch for.

22 Jul 2026 krebsonsecurity.com
Infrastructure / Cloud Cloudflare

How the 2026 World Cup altered internet traffic patterns

Match schedules, streaming choices and short breaks shifted global HTTP traffic timing and load, producing spikes during late-night games and at halftime. For MSPs and sysadmins this signals the need to revisit CDN configuration, caching, autoscaling and maintenance windows to maintain service quality.

21 Jul 2026 blog.cloudflare.com
Infrastructure / Cloud Cloudflare

Cloudflare Internal DNS is now generally available

Cloudflare has released Internal DNS to general availability, offering authoritative plus recursive name resolution for private networks managed via Cloudflare’s worldwide fabric and centralized control plane. This gives MSPs and sysadmins a unified way to manage internal DNS with Zero Trust and networking integrations and smoother scaling.

20 Jul 2026 blog.cloudflare.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.