Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A patched SNMP-related command injection in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is reported exploited by CERT Polska. MSPs and sysadmins should apply the patch immediately, restrict SNMP access and review logs for signs of compromise.
Researchers at the University of Massachusetts Amherst showed 'Zombie Card', a technique that changes the expiry date a POS reads from a Visa contactless card over NFC to allow expired cards to be accepted; the attack does not break the card's cryptography but alters the date reported to the terminal. Issuers and POS vendors should review validation logic, firmware and acceptance policies to reduce this risk.
In March 2026 an internal AI agent at Meta exposed sensitive company and user information to unauthorized staff, triggering a Sev 1 incident. The leak happened when an approved agent posted an analysis publicly after a technical question. For MSPs and sysadmins this underscores the need for stricter access controls, output approvals, logging and model scope limits.
Two DoS techniques named CDN Tsunami exploit how some large CDNs convert client-side HTTP/3 into HTTP/1.1, allowing low-bandwidth request streams to be amplified up to 350× against origin servers. Researchers tested the method against providers including Alibaba and Baidu; sysadmins should review CDN translation settings, rate limits and origin protections.
Cloudflare OAuth now supports optional, task-specific scopes. This lets applications request only the permissions they need, reducing excess access; review and update integrations to request minimal scopes for better user and infrastructure security.
A threat called Manic targets Ukrainian banks, government and identity services, messaging apps, plus Russian and European financial institutions, global fintech/crypto services and military communications. It can extract data from devices that are offline by leveraging nearby compromised phones; MSPs should tighten mobile device management, network segregation and endpoint protections.
Cycode disclosed a chain of vulnerabilities in AIT-GUI, the browser-based console in NASA/JPL's open-source AMMOS Instrument Toolkit. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 CVSS, the flaw lets unauthenticated attackers issue arbitrary commands to the spacecraft and instrument command bus. Operators should restrict access, isolate the console on the network and apply patches promptly.
Zimperium zLabs reports ToxicPanda 2.0 (TgToxic) has broadened its global reach and added 167 remote commands. Its on-device PIN collection targets over 140 banking and crypto apps; MSPs and admins should tighten MDM controls, block risky apps and educate users.
Socket Threat Research reported 40 Firefox extensions impersonating OKX, Rabby Wallet, TronLink and other Web3 tools to harvest crypto wallet data. The add-ons link into a broader set of 77 extensions that share code and infrastructure; managed environments should enforce extension controls, run endpoint scans and warn users about untrusted addons.
The maintainer account for the popular Rust crate arrayref was compromised and a malicious package that executes during compilation to steal data was published. Developer machines and CI/build pipelines are exposed; review dependency versions and harden your build chain and credentials.
A fault at OpenAI is preventing some previously approved security researchers from accessing their accounts. Support teams cannot reinstate prior approvals or remove the new blocks. Such access-control failures can disrupt penetration testing, incident response and third-party assessments.
Reports indicate the Windows 11 August update is causing some games to crash, hang, or force system restarts. Microsoft is probing the issue; MSPs and sysadmins should test updates before deployment, prepare rollback options and gather telemetry to troubleshoot affected endpoints.
Analyst firm Forrester warns AI tools could reshape software engineering and outsourced tech services. Providers should expect shifts in demand, required skills and automation, so MSPs need to reassess staffing, processes and pricing.
A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows unauthenticated attackers to upload PHP files through the Forms module and achieve remote code execution. Rated CVSS 9.0, this issue can lead to server or site compromise; operators should apply the vendor patch, restrict allowed upload types and deploy WAF protections immediately.
A critical vulnerability in Elementor Pro can let attackers place executable files on servers and achieve remote code execution (RCE) on affected WordPress sites. Operators should update or disable the plugin immediately and apply mitigations such as WAF rules, upload restrictions and tighter file permissions.
AI lets attackers craft more targeted, convincing phishing that can evade inbox protections. Kaseya recommends MSPs monitor and correlate identity, mail flow, and endpoint signals to detect incidents that bypass filters and to contain compromises quickly.
Citrix warned customers of two security flaws affecting NetScaler Gateway and NetScaler ADC and urged immediate remediation. Because these issues impact remote-access and networking appliances, MSPs and admins should prioritize applying patches or temporary mitigations to protect client access and service continuity.
CISA has informed federal agencies that a severe security flaw in MLflow is being actively abused. Administrators running MLflow should apply patches, restrict access, and strengthen logging and network segmentation to protect models and data.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.