Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A point release, Ubuntu 26.04.1, is due soon and may include updates affecting the GRUB bootloader. Server admins should read the release notes, validate the upgrade in staging, and schedule planned rollouts to avoid boot or compatibility surprises.
A Microsoft veteran describes a Word 97 crash that occurred under specific conditions but disappeared when a debugger was attached. The root cause was a CPU erratum interacting with in-circuit emulation and a single NOP prevented the failure. This underlines how hardware bugs can produce non-deterministic software faults and the need for firmware fixes and thorough low-level testing.
A vulnerability tracked as CVE-2026-65643 in cPanel and WebHost Manager (WHM) affects handling of parked and addon domains and can be exploited to execute code as root. cPanel has released patches for all supported releases; operators should apply updates immediately because one hosted account could compromise the entire host.
PaperCut released a second emergency update after researchers showed ways to bypass the initial fixes for two actively abused flaws in PaperCut NG and MF. Administrators and MSPs should patch print-management servers immediately, reassess temporary mitigations, and review logs for suspicious activity.
Paused Chinese controls on rare-earth exports are scheduled for a licensing review in November, raising the prospect of supply disruption for components used in datacenter hardware. MSPs and sysadmins should review inventories, alternative suppliers and hardware life‑cycle plans to prepare for delays and higher costs.
A U.S. court found the Pentagon's decision to bar Anthropic from procurement relied on security concerns that were compiled after the fact and referenced capabilities Claude did not possess. The ruling highlights potential instability in vendor access and supply chains; sysadmins should review contracts, contingency providers and compliance exposure.
A critical unauthenticated vulnerability was found in the GiveWP plugin that can let attackers execute commands on the hosting environment. For admins and MSPs this raises the risk of full site compromise, data exposure and outages—apply the vendor fix or mitigations immediately.
Microsoft has moved Windows 11 26H2 into the Release Preview channel. The update runs on the same servicing stream used for 24H2 and 25H2, so earlier update instability could reappear. MSPs and sysadmins should run pilot deployments and compatibility checks before wide rollout.
PaperCut announced a zero-day vulnerability is being used in attacks against PaperCut NG/MF releases. Emergency patches were issued for v25 and v26 and the company reports confirmed customer incidents. MSPs and sysadmins should prioritize applying the fixes and inspect print servers for signs of compromise.
Recorded Future Insikt Group identified campaigns from late Sep 2025 to early Apr 2026 targeting government and diplomatic entities in Romania, Spain and Türkiye. The intrusions deployed a previously undocumented backdoor called HOOKEDGE, a lightweight Windows batch-script; the alleged APT28 tie and script-based approach can complicate endpoint defenses.
CISA warns that many of the vulnerabilities attackers exploit stem from long-standing design and implementation shortcomings, and that poor uptake of Secure by Design plus organizational culture gaps have worsened the situation. For MSPs and sysadmins this signals the need to prioritise secure architecture, timely patching and stronger supplier oversight to reduce repeat incidents.
More than 100 technology companies warn of increasing AI-driven attack risks while simultaneously marketing paid security products. This raises conflict-of-interest and cost-shifting concerns; MSPs and sysadmins should prioritize detection, patch management, monitoring and independent validation of vendor claims.
Cloudflare released an operator-facing interface in the dashboard to manage bot and agent listings via BotBase. It adds submission state tracking, the ability to edit listings, and a behavior model for declaring how bots use content—helpful for monitoring client environments and integrations.
In the UK a 68-year-old was jailed for over six years after running an illegal IPTV service that brought in £980,812 ($1.3M) across three years. For MSPs and sysadmins this is a reminder that illicit streaming creates legal exposure and can abuse hosting and bandwidth—monitor unusual traffic and hosting usage closely.
AI is accelerating the finding of software flaws, increasing pressure on traditional vulnerability management workflows. Action1 recommends combining multiple intelligence feeds and moving faster from detection to prioritization and remediation.
Shadowserver reports that more than 8,300 internet-accessible Gitea instances have not been patched for a critical vulnerability. The flaw is being used in active remote code execution attacks, putting customer data and infrastructure at risk; admins should apply updates or mitigations immediately.
Hasbro reported that attackers accessed employees' personal and financial records, and has not disclosed how many were affected. This creates risks to payroll systems, identity theft and phishing; MSPs and sysadmins should review access controls, increase log monitoring and ensure staff are notified and protected.
ServiceNow issued patches for three critical vulnerabilities in its AI Platform that permit code injection, SQL injection and privilege escalation. Administrators and MSPs should treat these flaws as high-risk — apply updates promptly and review access controls to prevent data exposure or account compromise.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.