Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Trend Micro researchers found trojanized npm packages posing as calendar and streak utilities that install an AI-assisted Linux backdoor, RedC2 4.0. When loaded, the module makes the bundled binary executable and launches it in the background, enabling a stealthy C2 channel. Audit dependencies and restrict executable permissions.
Cloudflare's Bot Preference Sync keeps your robots.txt aligned with AI bot policies for Search, Agent and Training. It cuts down manual file upkeep and helps prevent misconfigured bot access, aiding administrators and MSPs who manage customer infrastructure.
Reports indicate Salesforce partners are not generating significant revenue from the Agentforce AI platform. For MSPs and infrastructure providers this signals risk around integration, resale and training investments and may require re-evaluating go-to-market and support plans.
Rights advocates have complained to the FTC that some AI companies used books to train models without adequate permission. For MSPs and sysadmins this creates vendor due-diligence, data-transparency and licensing risks when adopting or reselling AI-powered services.
Check Point Research demonstrated that Microsoft Defender's signed boot-time driver BTR.sys can be abused to perform kernel-level file and registry operations. The technique does not rely on a software flaw or external drivers and can affect systems from Windows 7 to Windows 11 25H2, so admins should review boot security and driver access controls.
Kaspersky discovered in June 2026 a new malware family targeting DoFun-based Android head unit firmware. It abuses built-in updaters to deploy staged payloads for ad fraud and assembling a proxy botnet; fleet managers and MSPs should validate update channels, isolate telematics networks and enforce firmware integrity checks.
Homeland Security officials recommended immediate patching of vulnerabilities in TrueConf. Reports say Ukrainian hacktivists are exploiting the flaws, and because TrueConf is used beyond Russia, administrators should promptly check and apply updates.
Musk has walked back the optimistic schedule he gave on an earnings call, lowering expectations for when SpaceX will achieve the first Starship 'catch'. With an orbital test approaching, the revised timing increases uncertainty for satellite customers and launch planners; sysadmins and MSPs should monitor launch schedules and payload manifests for downstream impacts.
Toronto's SickKids hospital discovered an intruder on its careers site and restricted access while applying fixes. The organization says the issue stemmed from a third‑party software flaw affecting multiple entities; MSPs should audit vendor components, credentials and logs.
Malicious updates were pushed to popular Rust crates so normal build and install workflows delivered an information‑stealing payload. Developer credentials and CI environment secrets may be exposed; sysadmins and MSPs should audit dependency management and secret handling immediately.
Integrating Wazuh with AI and machine learning aims to improve alert prioritization, cut false positives, and speed up automated response processes. For MSPs and sysadmins, better alert correlation and automation can shorten incident response times and reduce operational burden.
Cisco released fixes for Crosswork platforms and Secure Workload following an internal security review. Nine vulnerabilities were addressed, five rated CVSS 10.0. Four issues affect Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning irrespective of configuration — admins should apply updates and audit impacted systems immediately.
New SynkLoader malware is being delivered through Microsoft Teams phishing messages and uses a fake lock screen to capture user credentials. This poses a risk for MSPs and sysadmins, as stolen credentials can enable lateral movement and account takeover; review MFA and Teams security settings.
A code-injection flaw in GitLab tracked as CVE-2026-19478 (CVSS 9.4) is being actively exploited soon after disclosure. Because it can let unauthenticated actors alter, delete or overwrite public projects, apply vendor patches immediately, restrict public access, and audit repository activity.
More than 9,300 AWS access keys publicly exposed between Aug 2022 and Aug 2026 are still valid and can grant full control of corporate accounts. MSPs and sysadmins should treat this as high risk: revoke and rotate keys, use IAM roles and least-privilege, and monitor CloudTrail/GuardDuty for suspicious activity.
Microsoft issued a patch for an Entra ID vulnerability rated CVSS 10.0 that could enable remote code execution. Early reports suggested exploitation, but Microsoft later stated there was no active exploitation; administrators should deploy the update promptly and review authentication and access logs.
Wi‑Fi 7 strengthens WPA3 security, but CableLabs is urging vendors to use a workaround so legacy clients remain connected. That workaround may reduce protections, so MSPs and sysadmins should review compatibility modes, network segmentation and vendor updates before enabling it.
Microsoft links game crashes and launch failures after the August 2026 Windows updates to peripherals with RGB lighting. For MSPs and sysadmins this may mean more support tickets for gaming PCs and the need to check RGB drivers and lighting software on affected machines.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.