Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
HMRC has opened a procurement worth up to £500M to replace and modernize the National Insurance NPS codebase and delivery model. The programme will demand cloud, integration, data‑migration and security/compliance expertise, creating procurement opportunities and operational responsibilities for MSPs and sysadmins.
Attackers exploited a high-severity Zimbra Collaboration Suite flaw to compromise more than 270 Zimbra instances. MSPs and sysadmins should assume mail servers and credentials may be exposed and perform emergency patching, network isolation and log/incident response to determine scope.
Investigations across 22 countries identified 263 suspects and resulted in 58 arrests, with connections to Africa-based organized crime groups. For MSPs and sysadmins this highlights the need to tighten monitoring, review credentials and validate incident response and detection controls against botnets, ransomware and phishing.
IBM introduced a processor able to execute Arm and IBM Z instruction sets directly on the same hardware. This broadens options for running mixed-architecture workloads on mainframes, but raises compatibility, migration and performance considerations for MSPs and system administrators.
A researcher reported that AI-generated watermarks added by Microsoft Paint and Photos can be traced back to user IDs. For MSPs and sysadmins this raises privacy and compliance concerns; review hosted AI usage, image-handling practices and sharing policies.
Researchers uncovered a Windows backdoor named Sleepwalker that contains a custom command set of 23 operations. The design and instruction complexity point to a planned, resource-backed actor rather than opportunistic malware. MSPs and sysadmins should prioritize detection signatures, network monitoring and incident response.
Researchers found Weedhack being distributed to gamers through fake Minecraft clients and search-result manipulation. McAfee Labs blocked over 6,300 access attempts to malicious sites; infected endpoints can be leveraged to pivot into customer networks or join botnets, so MSPs and sysadmins should monitor gamer-facing downloads.
AI-driven tools are making it easier to exploit PLCs and industrial devices, while GitLab incidents and leaked Stripe API keys were also reported. Trusted packages and internet-exposed services are common factors; admins should prioritize secrets management, package provenance checks and network segmentation.
Cloudflare moved the Cloudflare Blog onto EmDash and tested how it behaves under heavy load. They shifted production traffic in controlled stages and revamped the frontend; the post outlines practical steps MSPs and sysadmins can use when handling migrations and large-scale performance checks.
Gen Digital researchers identified two new malware families, WordlistLoader and SynkLoader. WordlistLoader uses ClearFake campaigns with ClickFix (aka FakeCaptcha) to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer), while SynkLoader focuses on phishing Windows credentials. For MSPs, stolen credentials can enable access resale to ransomware actors and client compromise.
AI-assisted code generation is increasing the number of packages and dependencies faster than security teams can review, causing a backlog of vulnerabilities and patch work. For MSPs and sysadmins, using SCA, SBOMs, automation and risk-based prioritization is essential to keep remediation debt under control.
Red Hat and the Keycloak project issued fixes for a severe vulnerability (CVE-2026-18963, CVSS 9.1) that allows unauthenticated attackers to compromise accounts via the password-reset flow. Administrators and MSPs should update Keycloak immediately, limit public exposure of identity endpoints, and apply temporary mitigations until patches are in place.
Seqrite Labs says Operation QUICSILVER uses fake graduation invitations to target Myanmar government and IT organizations and delivers a backdoor written in Go named QUICAgent. The campaign is linked to a China-associated actor; strengthen email defenses, add detections for QUICAgent and monitor network behavior for Go-based implants.
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows unauthenticated remote attackers to add port-forwarding rules that bypass NAT and can make internal devices reachable from the internet. MSPs and sysadmins should identify affected units, check for unauthorized forwards, and apply mitigations or coordinate with ISPs immediately.
Akamai research finds that a small group (around 5%) of heavy AI users in enterprises are embedding unvetted AI tools into business workflows, raising security exposure. Their integrations, API keys and automations can broaden the attack surface, so MSPs and sysadmins should monitor and audit high-volume AI adopters and toolchains.
Attackers are attempting to exploit two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress; the vulnerabilities can be used to create fake SAML responses and obtain administrator access. Servers running the plugin should be updated or protected immediately to prevent full site takeover or malware deployment.
The data cover the early phase of the AI boom, so actual water use may be higher now. Fragmented reporting obscures the full impact; higher water demand creates operational, cost and compliance challenges for cooling choices and sustainability planning by MSPs and sysadmins.
The U.S. Department of Justice reached a $400 million settlement with TikTok, ByteDance and affiliates over alleged COPPA breaches. The move underscores regulatory risk around minors' data and signals MSPs and sysadmins should review integrations, consent handling and data retention for client environments.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.