Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
SAP released fixes for CVE-2026-58231 affecting Commerce Cloud (Data Hub Adapter); the issue carries a CVSS score of 10.0. Due to inadequate authorization and input checks, unauthenticated actors could execute code remotely; managed service providers should apply patches immediately, restrict access and review logs.
Demand from AI workloads allowed major cloud providers to secure scarce servers and accelerators first, pushing enterprises toward renting capacity instead of buying hardware. For MSPs and sysadmins this raises procurement, cost and vendor-dependency risks; consider hybrid, colocation or long-term contract options.
Researcher Chaotic Eclipse released a PoC called ShieldBreak that reportedly bypasses fixes for CVE-2026-50656 (RoguePlanet) in Microsoft Defender and allows SYSTEM-level escalation. MSPs and sysadmins should immediately verify Defender updates, review configurations and detection rules, and monitor for exploitation attempts.
The "Plug and Pwn" attacks exploit Windows Plug and Play to cause automatic installation of vendor software when a device is connected, enabling attackers to escalate to SYSTEM. For admins this turns physical USB devices into a high-risk vector; restrict USB usage, enforce driver install policies, and deploy vendor fixes or blocking rules.
A vulnerability in Cisco Secure Firewall ASA and FTD, tracked as CVE-2026-20349 (CVSS 8.6), is being exploited in the wild; improper handling of HTTP requests can allow an unauthenticated remote attacker to trigger a denial-of-service. Administrators should apply Cisco patches immediately, restrict HTTP access to management interfaces and block risky traffic via network filters.
After Rapid7 published a PoC, attackers began using it to exploit a critical Microsoft SharePoint flaw. Server admins and MSPs should promptly apply patches or mitigations if available, monitor for suspicious activity and audit exposed SharePoint instances.
Signal introduced Automatic Key Verification to automate verification of encryption keys and help detect man-in-the-middle interception. For admins and MSPs this raises the importance of keeping clients updated and encouraging secure communication practices to ensure message integrity.
Threat actor Nightmare Eclipse released a new zero-day exploit called 'ShieldBreak' targeting Microsoft Defender that enables escalation to the Windows SYSTEM account. The disclosure followed Microsoft's August 2026 Patch Tuesday; MSPs and sysadmins should verify updates, monitor for exploitation and apply mitigations promptly.
India's central bank is encouraging the use of AI to accept some loan applications that were previously declined, aiming to widen financial access. That direction increases demands for model governance, explainability and audit trails, affecting infrastructure, monitoring and compliance tasks for teams managing lender systems.
Modular's Mojo programming language has reached version 1.0. Developers expect the promised open-source compiler after Qualcomm's acquisition to clarify the project's direction; compiler availability and licensing will affect build pipelines and deployment choices for admins and MSPs.
Microsoft's monthly update fixes 398 vulnerabilities, including a kernel-level network driver flaw under active exploitation (CVE-2026-68820, CVSS 7.0). The bug can be used to escalate to SYSTEM when an attacker already has code execution on a host; MSPs and admins should prioritize this patch and tighten monitoring.
Discovered in February 2026 by Palo Alto Networks Unit 42, Kimwolf v7 is an updated Android/IoT botnet. It abuses HTTP/2 to make attack traffic resemble legitimate browser connections, complicating detection and mitigation of DDoS activity. MSPs and admins should pay closer attention to anomalous HTTP/2 flows and insecure IoT endpoints.
A vulnerability in Zoom's annotation feature used during screen sharing could allow a participant to take control of another attendee's machine, and vice versa between viewers and presenter. Because the issue worked without user interaction, MSPs and sysadmins should urgently apply Zoom patches, restrict annotations and tighten meeting access and endpoint controls.
CERT-UA says UAC-0145, tied to Sandworm/APT44, has targeted Ukrainian IT staff with fabricated recruitment approaches to get them to install a malicious VPN. The VPN can execute remote commands, threatening servers and customer infrastructure; MSPs should verify recruitment contacts and tighten installation and VPN policies.
Signal introduced a verification feature to help confirm that the person you are messaging is the intended contact. The feature requires knowing the contact's phone number, so it can be limited if numbers change or are unknown; it's relevant for MSPs and admins aiming to reduce impersonation risk.
Researchers, aided by an AI agent, developed an exploit chain that allows attackers to take on any account, including administrators, and achieve unauthenticated remote code execution on SharePoint servers. The issue is CVE-2026-55040 (CVSS 9.1) affecting SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016; MSPs should prioritize patches and reduce public exposure.
The DeadLock group is running victim communications and leak operations on decentralized infrastructure, combining Session messaging with Polygon smart contracts to host extortion resources. This makes takedowns and evidence collection harder; MSPs and admins should monitor blockchain activity and review backups and incident communication procedures.
Microsoft released patches addressing at least 398 vulnerabilities in Windows and supported software. One flaw is already being actively exploited and two were publicly disclosed earlier; administrators should test and prioritize these updates, starting with the exploited and publicly detailed issues.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.