Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
LG Electronics USA plans to suspend smart TV apps that turn televisions into always-on residential proxy nodes. Researchers found about 42% of apps in the webOS store allowed third parties to route users' traffic, creating bandwidth, security and abuse risks that MSPs should watch for.
Match schedules, streaming choices and short breaks shifted global HTTP traffic timing and load, producing spikes during late-night games and at halftime. For MSPs and sysadmins this signals the need to revisit CDN configuration, caching, autoscaling and maintenance windows to maintain service quality.
Cloudflare has released Internal DNS to general availability, offering authoritative plus recursive name resolution for private networks managed via Cloudflare’s worldwide fabric and centralized control plane. This gives MSPs and sysadmins a unified way to manage internal DNS with Zero Trust and networking integrations and smoother scaling.
Cloudflare implemented two new WAF rules after the WordPress security team reported two high-severity flaws. The rules filter traffic for customers running affected WordPress versions, but administrators should still deploy the vendor patch immediately for their servers and clients.
Microsoft Security will be at Black Hat USA 2026 with supply chain research, hands‑on security sessions, expert discussions and a reception. The event gives MSPs and sysadmins practical insight into AI-driven risks and supply‑chain attacks, plus training and networking opportunities.
From late April to mid-June 2026 Microsoft Defender Experts recorded a rise in ACR Stealer activity. Campaigns use ClickFix-themed lures to harvest browser credentials, authentication tokens and sensitive documents; MSPs and sysadmins should prioritize credential/token protection and monitoring for related indicators.
Microsoft highlights the need to limit privileges for autonomous AI agents using strong identity, access controls, tool binding and audit logging. For MSPs and sysadmins, scoping agent permissions and keeping audit trails lowers the risk of unauthorized access or harmful actions on customer infrastructure.
Microsoft issued updates that fix at least 570 vulnerabilities in Windows and other products, nearly three times the number patched last month. The company attributes part of the increase to AI-assisted discovery; MSPs and sysadmins should test and deploy these updates promptly and watch for compatibility or regressions.
A failed DNSSEC key rollover caused an outage for the .al TLD. Cloudflare used a Negative Trust Anchor to restore resolution, and 1.1.1.1 now returns EDE 33 in DNS responses to indicate when DNSSEC validation was bypassed — useful for MSPs and sysadmins to detect and report validation skips.
A contractor left internal CISA credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months before the problem was reported. CISA’s postmortem points to shortcomings in the agency’s response and third-party oversight; MSPs should reinforce secret management, repository scanning and continuous monitoring to prevent similar incidents.
Krebs on Security reports a startup offering millions for zero-day flaws in popular software is operated by people with criminal records who previously ran fake intelligence firms and a defunct AI lobbying project under aliases. For MSPs and server admins this raises the risk from vulnerabilities traded via opaque buyers and underscores the need to review supplier trust, patching and monitoring practices.
The FBI, working with industry partners, took control of hundreds of domains tied to NetNut. NetNut is a residential proxy service run by Alarum Technologies [NASDAQ: ALAR]; the move followed reporting that linked NetNut to the Popa botnet, which involves at least two million compromised devices. MSPs and server admins should monitor outbound proxies, tighten filtering and scan endpoints for compromise.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.