Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A custom Java web shell attributed to the Clop group targets PTC Windchill and FlexPLM servers and can decrypt credentials, enumerate repository files and exfiltrate data. MSPs and admins running these products face an elevated risk of breach and data loss; strengthen access controls, enable monitoring for web shells and rotate credentials.
The Register reports a disruption to passport control at a French airport linked to Windows-based software. Such outages can impact passenger flow and operations, so MSPs should review redundancy, monitoring and incident response for identity and border-control systems.
A sponsor has funded long-term support for KDE Plasma 6.6, providing three years of fixes for the desktop, frameworks and apps on Kubuntu 26.04. For MSPs and sysadmins this extends the maintenance window for user workstations and security fixes; review deployment and package management workflows accordingly.
Picus Security's Blue Report 2026 finds that defenses which stop familiar methods can miss quieter, behavior-based approaches. The report shows prevention effectiveness differs widely by technique; for those managing servers and customer infrastructure, adding behavioral tests helps reveal coverage gaps.
Microsoft is trialing a faster File Explorer and a simplified, customizable context menu in Windows 11 preview builds for Insiders. MSPs and sysadmins should check shell-extension compatibility, review Group Policy/Intune implications, and run lab tests before broad rollout.
CISA has confirmed that a high-severity Windows Task Host vulnerability, noted as actively exploited in April, is now being used by ransomware operators. Administrators and MSPs should prioritize patching, enhance monitoring, and verify backups and incident response readiness.
Microsoft reports that some users are unable to get search results in Outlook on the web, Outlook desktop, SharePoint Online and OneDrive. For MSPs and sysadmins this can disrupt email and file retrieval workflows—monitor the Microsoft 365 service health dashboard and inform affected customers promptly.
GitLab issued fixes for a critical GraphQL vulnerability (CVE-2026-19478) affecting Community and Enterprise Editions. In some scenarios an unauthenticated actor can modify or remove public projects and certain user data; the flaw is rated CVSS 9.4. Administrators should apply the update immediately.
Wiz researchers found a vulnerability in the snowflakedb/snowflake-connector-net GitHub Actions workflow. The .github/workflows/jira_issue.yml could be triggered by a malicious GitHub issue to process attacker-controlled input and execute commands using internal Jira credentials, posing risks to CI pipelines and secret management.
A critical flaw in the Forminator Forms plugin (CVE-2026-15748, CVSS 9.8) can let unauthenticated attackers upload malicious PHP and achieve remote code execution on sites with ~600,000 installs. Immediate steps for managed environments: update or disable the plugin, harden upload paths and file permissions, apply WAF rules and scan/restore affected sites.
A recent review found HTML specification errors on about nine in ten leading websites. Those faults impair screen-reader behavior and increase accessibility compliance risk, so admins should include markup validation and accessibility checks in audits.
Payments firm Stripe plans to invest more than $7 billion to position itself as a gateway for AI token offerings. For MSPs and sysadmins this could mean extra integration work around billing APIs, token custody, KYC/AML compliance and securing high-volume transactions.
Siemens and Reinhausen are developing solutions to deliver 800 VDC to high-density AI server racks. Higher voltage can reduce current, lower cabling and conversion losses, and boost data centre efficiency, but it demands compatible UPS, PDUs and updated safety procedures. MSPs should reassess power infrastructure and operational practices.
Servers using the Model Context Protocol (MCP) can leak sensitive corporate data via unencrypted configuration files, excessive permissions and prompt-injection flaws, sometimes before teams notice the server. Adding AI agents can widen this gap because MCP provides channels for agents to reach tools and data.
On August 17, 2026 SSD Secure Disclosure published the second stage of an exploit that uses a VoLTE video call to achieve kernel-level control on devices with Unisoc modem firmware. Unisoc has not issued a patch; MSPs and administrators should treat this as a high-risk remote compromise vector that can lead to persistent, low-interaction takeover of customer devices.
A threat actor says they accessed Microsoft Azure environments with compromised credentials and is offering employee databases from several Fortune 500 customers—totaling 3.6 million records—for sale. Server admins and MSPs should prioritize credential rotation, enforce MFA, tighten access controls and review audit logs.
Pokémon Center told customers in the UK and Germany that a breach at CEVA Logistics exposed personal and order information and caused some orders to be cancelled. MSPs and sysadmins should reassess vendor access, data‑sharing arrangements and incident response procedures.
Researchers discovered a new Linux botnet family called Evooo1Bot that builds on Mirai’s leaked DDoS engine and can turn internet-exposed edge devices into SOCKS5 proxies. For MSPs and admins this means risk of anonymized malicious traffic and infrastructure abuse — prioritize changing default credentials, disabling unused services and monitoring outbound connections.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.