Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
The Register reports an advert for a chicken sandwich kicked off online debate about operating systems and put Windows under scrutiny. For admins this can mean shifts in user perception and a potential rise in support requests — monitor social channels and ticket trends.
WhatsApp has started rolling out an optional 'Scam Alert' that uses an on-device machine learning model to warn users about potential scam attempts. For MSPs and sysadmins this matters for corporate device policies, user awareness and mobile security procedures.
Nebius announced an aggressive ambition to reach 1 GW of GPU capacity quickly and said it will pursue various financing options to get there. For providers and admins this could shift power and capacity planning, affect data centre demand and pricing, and increase competition in the GPU rental market.
Near-autonomous AI agents carried out attacks against Taiwan's nuclear safety agency. Agent-based campaigns against critical infrastructure highlight the need for continuous monitoring, network segmentation, and automated privilege controls for MSPs and system administrators.
Tailscale traced last year’s outages to a 16-year-old SQLite bug called WAL-Reset. Tracking the issue took six months and prompted the team to build a new logging tool. The incident underlines the need to monitor and keep SQLite-backed components up to date.
Check Point Research links the North Korea–linked Lazarus Group to exploitation of a newly patched Microsoft Windows zero-day to install a previously unseen backdoor and obtain SYSTEM-level access against defense and aerospace firms in France, Germany, Brazil and India. Researchers say this continues the Operation Dream Job campaign. Admins and MSPs should apply Microsoft's patches immediately, hunt for indicators and verify there are no unauthorized privilege escalations.
A set of 737 free VPN/proxy Chrome extensions was discovered mainly targeting Russian-speaking users and forwarding browser traffic through a proxy infrastructure. They appeared under at least 40 developer accounts on the Chrome Web Store and accumulated 75,486 installs; 274 mimicked other extensions. Audit client browsers and block suspicious add-ons.
The City-Forum data-theft campaign employs custom tools to harvest information exposed to anonymous users via Salesforce Experience Cloud and ServiceNow customer portals. MSPs and sysadmins should review anonymous-access and data-visibility settings on customer portals and tighten monitoring and access controls.
The NFC relay malware WindRelay, used alongside the SpyNote RAT, can capture live card details and forward them to attackers in real time while enabling fraudulent loan or credit requests on victims' behalf. This threat requires MSPs and sysadmins to monitor for RAT activity, harden mobile payment paths and prepare incident response plans.
A design weakness in certain reasoning APIs from OpenAI, Anthropic and Google let encrypted reasoning blocks created in one session be replayed into another, enabling recovery of internal model reasoning and secrets from session logs, including API keys and passwords. For admins this raises the chance of secret leakage via model workflows; apply vendor fixes, rotate credentials and review access controls.
Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations in customer production environments during H1 2026. Edge prevention tools generally improved, but internal detection and lateral-movement controls are underperforming and stealthy attacks are evading notice. MSPs should focus on internal segmentation, richer telemetry and continuous control validation.
Exploitation attempts targeting CVE-2026-71362 in Adobe Commerce and Magento have been observed; attackers may be able to hijack customer sessions. Admins and MSPs should deploy patches immediately, review session and access logs, tighten WAF rules, and enforce MFA to reduce exposure.
Adobe issued updates for multiple critical flaws affecting ColdFusion, Commerce and Campaign Classic; the highest-severity issue is CVE-2026-48362 (CVSS 10.0), an OS command injection. Successful exploitation can enable remote code execution and privilege escalation — administrators should apply patches urgently, segment impacted systems and monitor for indicators of compromise.
Over 737 extensions on the Chrome Web Store impersonated popular VPN/proxy services and sent user traffic through SOCKS5 proxies run by a single provider. For MSPs and admins this creates privacy and credential-theft risks; review installed extensions, enforce extension policies, and monitor outbound proxy connections.
Threat actors are actively exploiting a critical flaw in Broadcom VMware vCenter identified as CVE-2026-59310 (CVSS 9.8). The directory-traversal bug can enable remote code execution and persistence; administrators should apply vendor patches immediately, audit exposed vCenter instances, review logs and isolate any suspected hosts.
Engineers extended the 1977-launched Voyager's operational life by roughly two years through tiny power savings. Remote reconfiguration and fine-tuning that reduced draw by about 0.2 W show how small efficiency gains can matter for long-lived systems; useful reminder for infrastructure teams to plan strict power budgets and staged degradation.
Two malicious LiteLLM packages uploaded to PyPI in March were available for about 40 minutes and contained code that harvested secrets—cloud credentials, SSH keys, Kubernetes tokens and database passwords—on systems that installed them. CloudSEK's dataset of roughly 434,000 files suggests over 2,100 organizations could be affected; admins should validate package sources, run dependency scans and rotate any exposed keys.
Rail police have deployed live facial recognition at Victoria station as privacy groups raise concerns about wider normalization. For MSPs and sysadmins this raises operational and security issues around data handling, retention, false-positive risk and GDPR compliance when integrating such surveillance into customer infrastructure.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.