Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Mozilla discovered an unencrypted copy of a Firefox signing key on GitHub and revoked the affected key. Audit logs showed no unexpected access, but the event exposes weaknesses in release verification processes. MSPs and admins should review key rotation, signing workflows and verification controls.
Cloudflare recorded a 519% rise in hyper‑volumetric DDoS activity in H1 2026, with many incidents powered by reflections via DNS and CLDAP and some attacks approaching 1 Tbps. Geopolitical tensions altered attacker patterns; MSPs and sysadmins should reassess bandwidth planning, filtering and anti-reflection controls.
Consultancy McKinsey argues that upgrading the US grid for data center and AI loads is justified even if AI demand softens. Underinvestment poses larger long-term risks; MSPs and sysadmins should incorporate capacity, redundancy, backup power and efficiency into their infrastructure plans.
Attackers accessed a private cellular network used by the local grid operator to reach remote devices and disabled a steam turbine and the process-water treatment system at a combined heat and power plant serving about 50,000 residents. Recovery began around 7:30 a.m. while intruders were still active, and customers did not lose heat. The incident highlights the need to harden OT access, segment cellular links and monitor remote connectivity.
Researchers uncovered a supply-chain compromise affecting BdThemes, prompting the WordPress plugins team to pause downloads temporarily. Attackers manipulated distribution metadata (JSON) rather than altering repository source files to inject rogue administrator accounts. MSPs and sysadmins should audit affected plugins, look for unknown admin users, verify package integrity and rotate credentials.
CISA has confirmed that a high-severity Microsoft SharePoint remote code execution flaw has been actively used by ransomware actors since early July. Providers and sysadmins should urgently apply patches or mitigations, tighten access to SharePoint hosts, segment them on the network, and monitor logs and unusual processes to limit exposure.
Cisco reported two high-severity flaws in Secure Endpoint Connector that affect ClamAV; public exploits can be used to crash the scanner and cause denial-of-service. Server admins and MSPs should verify patches and apply mitigations on affected endpoints promptly.
US federal agencies and South Korea's National Police Agency have issued global alerts about Gunra ransomware focusing on government and critical infrastructure. For IT teams: apply patches, verify and isolate backups, enforce network segmentation, strengthen endpoint and log monitoring, and implement the detection indicators and guidance from the agencies.
The Franklin project born from DEF CON is bringing additional security vendors on board and applying digital modeling together with artificial intelligence to reinforce water utility defenses. For MSPs and sysadmins this raises the need to adapt OT risk assessments, monitoring and incident response to new simulation and detection tools.
AI tools can lead to 10–50× more code output, increasing pressure on teams that must find vulnerabilities, handle dependencies and prioritize fixes. The webinar discusses practical strategies to scale security practices so reviews don't become a release bottleneck and you keep control over what ships.
Mark Zuckerberg spoke about superintelligence and the future of civilization, suggesting cutting‑edge AI may concentrate with wealthy backers while open‑weight models become more common for everyone else. For providers and sysadmins this could change hardware demand, deployment patterns and security/governance responsibilities around model weights and data.
Microsoft has observed Storm-1175 using a previously unseen ransomware called StormEncryptor. The malware is implemented in C++, tags encrypted files with .encrypted and marks a shift from the group's prior use of Medusa; MSPs should prioritize N-central patches, endpoint monitoring and backup validation.
Meta unveiled a 30-billion-parameter Llama-based model, Muse Glimmer, marking its first open-weights move in over a year. An open variant of Muse Spark is also planned. MSPs and sysadmins should assess hosting capacity, GPU/CPU provisioning, licensing and security implications for deploying or supporting these models.
The Hacker News summarizes this week’s incidents: unexpected AI behavior, a Metabase 0-day, MCP supply-chain attacks, and router backdoors. Short exploitation paths and default configurations mean MSPs and sysadmins should prioritize audits, patching and tightening deployments.
Attackers accessed the OT network of a small Polish plant that supplies heat to about 50,000 people by abusing a private APN. The case underscores the need to secure remote access, review APN settings, enforce network segmentation and deploy monitoring—items MSPs and sysadmins should reassess.
South Korean security firm Genians reports that North Korea's Kimsuky is running local AI models on its own servers and linking document-search tools to captured files. The group is embedding AI components into malware to automate spear-phishing and payload creation, making detection and response more difficult.
Cloudflare revealed Wallets, Radar and several agent-focused services during Agents Week. These additions tackle monitoring, authentication and edge agent management, which can change how MSPs deploy, secure and integrate customer infrastructure.
An attacker compromised BdThemes' upstream infrastructure and altered a JSON endpoint that administrators' browsers request to insert rogue admin accounts. Sites using BdThemes components risk unauthorized admin access and data exposure; immediately audit user accounts, plugin updates and revoke sessions/keys for affected customers.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.