Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1011 stories last updated 17.09.2026 01:28
Infrastructure / Cloud The Register

Tesco store scales return 404/403 errors, disrupting customer transactions

In some UK Tesco stores, scale units or their web services became unreachable, returning 404 or access-denied responses. When in-store IoT or service endpoints fail or are misconfigured it impacts sales and checkout flows; monitoring, access control and prompt patching are essential.

26 Aug 2026 theregister.com
Security BleepingComputer

Microsoft begins testing privacy controls for Windows 11 desktop apps

Microsoft is trialing new Windows 11 settings that let users and admins control desktop apps' access to camera, microphone and precise location. For MSPs and sysadmins this brings stronger endpoint privacy options, potential app compatibility checks and a need to review management policies (Group Policy/MDM).

26 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Critical code-injection flaw in Gitea being actively exploited

CISA reports a critical flaw in self-hosted Gitea instances is being actively exploited for code-injection attacks. Service operators should apply available patches immediately, tighten access controls, review logs and repositories for unexpected changes, and be ready to follow incident-response procedures.

26 Aug 2026 bleepingcomputer.com
Artificial Intelligence The Register

Perplexity moves toward local AI deployments

Perplexity is turning attention to on-premises and enterprise deployments amid talk of a potential Nvidia tie-up. This shift could force MSPs and sysadmins to reassess GPU capacity, data residency, latency and operational monitoring when running models outside the cloud.

26 Aug 2026 theregister.com
Infrastructure / Cloud The Register

Intel 256-core Xeon 7: delayed and flawed but still promising

Intel's 256-core Xeon 7 CPUs have been hit by delivery delays and reported technical issues, yet they offer very high core density for heavy compute workloads. Service providers and sysadmins should validate compatibility, firmware/OS support, and power/cooling requirements before deploying to production.

26 Aug 2026 theregister.com
Security The Hacker News

U.S. sanctions Iran-linked cyber actors over infrastructure breaches

The U.S. Department of the Treasury announced sanctions on Iranian cyber actors accused of intrusions into critical infrastructure. By targeting financial channels the move seeks to disrupt attacker funding; MSPs and sysadmins should update threat intel, review access controls and assess compliance effects.

25 Aug 2026 thehackernews.com
Infrastructure / Cloud The Register

Apple launches new Mac mini models amid memory shortage

Apple introduced a new Mac mini line despite ongoing memory supply challenges. Higher memory prices push up the total cost for ML and memory-heavy workloads, so MSPs and sysadmins should reassess pricing and capacity planning for customer deployments.

25 Aug 2026 theregister.com
Security The Hacker News

NVIDIA NemoClaw flaw could let malicious webpage manipulate Ollama instance and model

Oasis Security disclosed a flaw in NVIDIA NemoClaw that could allow a malicious webpage to access a local Ollama instance without authentication and inject hidden instructions into the model serving an AI agent. Administrators should isolate model services, restrict access and monitor for NVIDIA patches.

25 Aug 2026 thehackernews.com
Security The Hacker News

WhatsApp adds multiple passkeys to a single account for iOS and Android

Meta rolled out support for multiple passkeys per WhatsApp account, enabling phishing-resistant sign-ins across iOS and Android devices. This reduces reliance on passwords, eases managing access across several devices, and helps mitigate account takeover risks. Over 1 billion users already use passkeys; Android support launched in October 2023.

25 Aug 2026 thehackernews.com
Security BleepingComputer

LACMA breach last year exposed social security and medical data

Los Angeles County Museum of Art (LACMA) disclosed that a breach last year released social security numbers and medical information for customers and staff. For MSPs and sysadmins this underscores the need to protect PII and health data with encryption, strict access controls, monitoring and a rapid incident response and notification process.

25 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Attackers use npm and mirrors to mimic Cloudflare CAPTCHA

Threat actors are placing malicious HTML on npm repositories and mirrors that impersonate Cloudflare CAPTCHA to redirect users to attacker-controlled sites. For MSPs and sysadmins this is dangerous because the content can appear to come from trusted sources, enabling credential theft or unwanted redirects; monitor mirror content and block suspicious redirects.

25 Aug 2026 bleepingcomputer.com
Security BleepingComputer

AnonyMousKIT PhaaS: voice AI agents targeting iPhone passcodes

A new PhaaS called AnonyMousKIT leverages voice-based AI agents to automate harvesting of verification codes used to open locks on stolen iPhones and circumvent Activation Lock. For MSPs and sysadmins this raises the need to reinforce customer Apple ID protections, device tracking and defenses against social engineering.

25 Aug 2026 bleepingcomputer.com
Security Microsoft

Patch window is shrinking — security needs a new control plane

Microsoft warns the time between finding vulnerabilities and applying patches is shrinking, creating a need for protections that work while issues remain unpatched. For MSPs and sysadmins this means implementing a control plane to enforce compensating controls, automation and centralized telemetry between discovery and fixes.

25 Aug 2026 azure.microsoft.com
Security The Hacker News

miniOrange SAML flaw allows WordPress admin access (CVE-2026-61979)

Two authentication-bypass flaws in the Xecurify miniOrange SAML 2.0 Single Sign On plugin let attackers log in as any WordPress user, including administrators. Patchstack disclosed the issues and CVE-2026-61979 is rated high severity. Service providers and sysadmins should apply updates, review sessions and access logs, and enforce extra access controls until patched.

25 Aug 2026 thehackernews.com
Security The Register

Ukraine unveils pickup-transportable jet-powered counter-drone system

Ukraine revealed a fast, lightweight jet-powered counter-drone platform designed for rapid field deployment and compact enough to be moved in a pickup. MSPs and data centre operators should assess how such tactical systems could affect hosted sites and update airspace monitoring, physical security and incident response procedures.

25 Aug 2026 theregister.com
Security BleepingComputer

Large DDoS attack hits Norway's shared government digital infrastructure

A large DDoS campaign that began on Monday disrupted shared online services used by Norway's public agencies, causing outages across government platforms. For MSPs and sysadmins this highlights the need to review DDoS defenses, capacity planning, failover arrangements and monitoring to reduce customer impact.

25 Aug 2026 bleepingcomputer.com
Security The Hacker News

CVE-2026-21962: Active exploitation affecting Oracle WebLogic and HTTP Server

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities list after evidence of active exploitation. The CVSS 10.0 flaw in Oracle HTTP Server and Oracle WebLogic Server can allow unauthenticated attackers to access critical data over HTTP; apply patches, restrict network exposure and monitor logs urgently.

25 Aug 2026 thehackernews.com
Security The Register

Fake OpenAI Codex ads used to push ClickFix to Macs

Attackers are leveraging sponsored search listings and fake OpenAI Codex ads to trick Mac users into downloading ClickFix malware. This developer-focused lure can bypass casual checks, so endpoint protection, download verification and monitoring ad-related traffic should be prioritized by service providers.

25 Aug 2026 theregister.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.