Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1011 stories last updated 17.09.2026 01:28
Infrastructure / Cloud The Register

Debian turns 33, Haiku turns 25 — both continue to evolve

Debian marks its 33rd year; its large package ecosystem and long-term support keep it relevant for servers and hosting infrastructure. Haiku reaches its 25th anniversary while carrying on the BeOS lineage; its community activity and development are worth watching for hobbyist desktops or lightweight embedded uses.

21 Aug 2026 theregister.com
Security BleepingComputer

Strengthening online privacy with separate digital identities

Reusing email, phone and payment details makes it easier for brokers and attackers to correlate user activity. Anonyome Labs recommends creating separate digital personas to reduce linkage and limit the impact of breaches, spam and identity theft. For MSPs, this approach can lower customer risk and simplify incident response.

21 Aug 2026 bleepingcomputer.com
Infrastructure / Cloud The Register

EE offers paid 5G network slicing for prioritized mobile connectivity

EE has started offering a paid 5G network slicing option that gives prioritized handling to selected mobile traffic. For MSPs and sysadmins this can change mobile access performance, SLA planning and network segmentation — review customer connectivity guarantees and security separation when relying on operator slices.

21 Aug 2026 theregister.com
Infrastructure / Cloud BleepingComputer

Microsoft begins rolling out Classic Outlook theme for New Outlook users

Microsoft has started rolling out the Classic Outlook theme to Outlook on the web and New Outlook for Windows users. Letting users return to the familiar interface can ease migrations; MSPs and sysadmins should consider potential changes in support tickets, user training and corporate appearance settings.

21 Aug 2026 bleepingcomputer.com
Security BleepingComputer

CISA orders feds to urgently patch TrueConf Server flaws

CISA directed U.S. federal agencies to prioritize fixes for two actively exploited vulnerabilities in TrueConf Server. Because these flaws affect a self-hosted communications platform and can enable unauthorized access or disruption, MSPs and sysadmins should apply updates and review network and authentication controls.

21 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Microsoft patches critical Entra ID flaw that was actively exploited

Microsoft released a patch for a high-severity vulnerability in the Entra ID identity and access management platform that was used in attacks. For service providers and admins, this risk can enable token theft, account takeover and lateral movement, so apply the update and review identity/access logs and service accounts.

21 Aug 2026 bleepingcomputer.com
Security BleepingComputer

Commands hidden in FTP banners used to deliver E4del and PINHOLE RATs

Threat actors are embedding commands in FTP server banners to deliver two previously unreported Windows RATs, E4del and PINHOLE. The technique can bypass basic traffic controls; MSPs and administrators should monitor FTP banners and logs, update IDS/IPS detections, and strengthen endpoint detection and response.

21 Aug 2026 bleepingcomputer.com
Security BleepingComputer

SickKids third-party software flaw exposed employee and applicant data

Toronto's Hospital for Sick Children (SickKids) reported that a vulnerability in third-party software led to exposure of personal data for some current and former employees and job applicants. Clinical systems and patient records were not affected. The incident underscores the need for MSPs and sysadmins to review vendor integrations and access controls.

21 Aug 2026 bleepingcomputer.com
Security The Hacker News

Rust supply-chain attack: malicious crates on crates.io (245 million downloads) removed

A compromised maintainer republished arrayref 0.3.10, internment 0.8.7 and append-only-vec 0.1.9 on crates.io that added a typosquatted dependency whose build script retrieved and executed a remote payload during compilation. With 245 million downloads across the affected packages, build-time malware can taint CI systems and downstream artifacts; inspect build scripts, pin dependencies and enforce isolated/reproducible builds.

21 Aug 2026 thehackernews.com
Security The Hacker News

Suspected Russian groups hijack accounts via Google OAuth and WhatsApp linking

Three suspected Russian espionage clusters — UNC6293, UNC7005 and UNC5976 — have been observed abusing Google OAuth grants and WhatsApp account linking to hijack accounts at universities, aerospace/defense, government and think tanks in Europe and the U.S. Because these flows can circumvent protections and expose data, MSPs and sysadmins should audit OAuth consents, linked accounts and authentication logs.

21 Aug 2026 thehackernews.com
Infrastructure / Cloud The Register

Go 1.27: Generics now allow type parameters on methods

Go 1.27 extends generics to support type parameters on methods, enabling more expressive APIs. Tooling like compilers, IDEs, linters and CI may need updates; review third-party packages and run tests before upgrading production systems.

20 Aug 2026 theregister.com
Security The Hacker News

ThreatsDay roundup: Gogs 10.0 & n8n RCE, GLM-5.3 exploit, $10M reward

The ThreatsDay roundup highlights RCE in Gogs 10.0, an n8n workflow-to-RCE path, GLM-5.3 exploit research and a $10M reward announcement. It warns that trusted components, signed drivers and legitimate apps are being misused and that exposed services and weak checks lower attacker effort — apply patches and audit exposed workflows and drivers.

20 Aug 2026 thehackernews.com
Security The Hacker News

AI-generated exploit scripts target Siemens S7 PLCs

The U.S. government alerted that AI-generated exploit scripts are being used against Siemens S7 PLCs in critical infrastructure. The scripts masquerade as routine monitoring software to probe networks and improve attacker capabilities; MSPs and sysadmins should restrict PLC access, enforce network segmentation and tighten monitoring.

20 Aug 2026 thehackernews.com
Artificial Intelligence The Register

OpenAI targets Anthropic customers with Private Safety Processing and no-data-retention promise

OpenAI launched Private Safety Processing for enterprise customers; the feature performs automated prompt monitoring while promising not to retain customer data. MSPs and sysadmins should inspect contract terms, logging and data-flow details to ensure compliance and client privacy.

20 Aug 2026 theregister.com
Infrastructure / Cloud The Register

Waymo designed a 5 nm robocar chip to stay ahead of Tesla

Waymo has designed a 5 nm machine-learning accelerator for its vehicles, targeting 1,000+ TOPS and ultra-low latency. Shifting more compute onboard changes power, cooling and deployment needs and will demand dedicated drivers, update paths and security practices from fleet operators and infrastructure providers.

20 Aug 2026 theregister.com
Security The Hacker News

Grok vulnerable to 'Cryptographic Context Injection' that can leak chat data

Adversa AI reported a technique called 'Cryptographic Context Injection' that can cause xAI's Grok to send a user's name, approximate location, subscription tier and conversation prompts to an attacker-controlled server when summarizing a webpage. This can expose customer-identifying and session data, so MSPs and admins should review Grok integrations, limit web-summary requests and monitor outbound traffic.

20 Aug 2026 thehackernews.com
Security The Hacker News

isolated-vm flaw: sandbox escape and potential RCE risk

A critical vulnerability (GHSA-864f-rcv7-6rh4) was disclosed in the isolated-vm Node.js sandbox; versions up to and including 7.0.0 are affected. The bug can allow code inside the sandbox to break out and potentially execute commands on the host; no CVE has been issued yet. If you run isolated-vm in production, prioritize updates and review isolation controls.

20 Aug 2026 thehackernews.com
Security The Hacker News

Critical authentication bypass in Citrix NetScaler — update required

Citrix released patches for two flaws affecting NetScaler ADC and NetScaler Gateway; one is critical and can allow authentication bypass on certain Gateway and AAA servers. Some FIPS and NDcPP builds and SecurAccess are impacted; managed appliances should be patched immediately, access tightened and logs reviewed.

20 Aug 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.