Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
IDC MarketScape placed Microsoft as a leader for enterprise MDR/MXDR in 2026. The report highlights Microsoft Defender Experts MDR's use of AI, threat intelligence and human analysts for detection and response—information relevant when choosing an MDR provider for managed environments.
Microsoft was named a Leader in the 2026 IDC MarketScape for enterprise MDR/MXDR. The assessment highlights Microsoft Defender Experts MDR's mix of AI, threat intelligence and human analysts; this can influence MSPs' and sysadmins' procurement and operational decisions.
OpenAI unveiled GPT 5.6 Cyber, a model aimed at discovering and assessing security flaws, running penetration tests, and assisting incident handling and remediation. Access is limited to approved users, so MSPs and sysadmins should watch availability and plan controls to manage integration and prevent misuse.
Microsoft Threat Intelligence examined DeadLock, a new financially motivated ransomware. The operation uses decentralized services to manage victim contact, negotiations and data leaks while performing double extortion; MSPs and sysadmins should prioritise detection of Rust-built binaries, network indicators, and reliable backups and incident response.
Microsoft analyzed the DeadLock ransomware; the operation uses a Rust-based encryptor and employs decentralized infrastructure for victim communications, negotiations and data-leak operations. Its double-extortion method — encrypting data while threatening publication — makes incident response, negotiations and recovery planning harder for MSPs and administrators.
Researchers identified malicious VS Code extensions helper-beeps.solidity-pro and web3devtoolsx.solidity-pro that install a browser wallet and exfiltrate API keys and credentials. Admins and MSPs should scan developer workstations, remove these extensions, and rotate any potentially compromised keys or tokens.
Cloudflare for Government obtained FedRAMP High (Class D) approval and is preparing to pursue DoD IL4 authorization. That signals Cloudflare services now meet stricter federal controls, a key consideration for MSPs and sysadmins managing customers with U.S. government compliance requirements.
OpenAI halted certain internal activities around its Astra model after an internal review found progress in autonomous agent-style coding and cybersecurity capabilities. The company is introducing isolated environments and additional security controls for higher-capability models; infrastructure admins should reconsider using such models for automation or direct infra changes.
London hosts roughly two-thirds of the nation's datacenter capacity, but large multimegawatt projects are increasingly being developed beyond the M25. For MSPs and sysadmins this changes trade-offs around latency, redundancy and cost and expands regional hosting options for customers.
Smart glasses' usefulness depends as much on human training and labeled data as on sensors and software. For MSPs and sysadmins this means planning for user training, data privacy, patching workflows and real‑world testing (including interactions with animals) to ensure reliability and compliance.
A developer used a hastily made, intended-as-temporary script that surfaced on LinkedIn before the project ended, triggering personal and corporate complications. For MSPs and sysadmins: quick fixes, poor secrets or access handling and lack of code hygiene can expose infrastructure and damage client trust.
LexisNexis took Diligence, Metabase API and Newsdesk offline after suspicious activity was detected on servers managed by an unnamed third-party vendor. The vendor has not been identified; outages can impact client data access and integrations. MSPs and sysadmins should review credentials, check logs and reassess third-party risk controls.
Valve has informed European Steam hardware customers that some customer data was stolen after a breach at shipping partner CEVA Logistics. For MSPs and sysadmins this underlines supply-chain exposure risks—review customer notifications, tighten access controls and monitoring, and be alert for phishing or account abuse.
CISA warned that attackers are actively exploiting a critical command-injection vulnerability in Progress Kemp LoadMaster. For MSPs and server admins this can enable remote code execution and appliance compromise; apply vendor patches immediately, isolate affected units, and review logs and credentials.
The author moved from covering SD‑WAN to relying on it in daily use, aggregating imperfect Starlink and 5G home links under SD‑WAN to improve uptime and balance traffic. For MSPs and admins this reduces dependence on a single ISP for remote sites, though configuration complexity, latency behavior and costs need consideration.
Ransomware groups are increasingly going after mid‑level IT managers in their 40s rather than CEOs, since those staff often hold critical access and can authorize payments. For MSPs and sysadmins this raises the need for strict privilege control, network segmentation, user training and an incident plan (disconnect affected hosts and notify law enforcement).
Researchers scanned social media to gauge developers' concerns about AI coding tools; findings highlight a call for security and privacy to be enabled by default. For admins and MSPs this means vetting tools, protecting secrets and managing telemetry should be treated as priorities when adopting these assistants.
Atlassian's Rovo assistant can be induced to transmit Jira or Confluence content accessible to a signed-in user to a server controlled by attackers. Two security firms independently found different exploitation paths, and only one of those routes is confirmed closed. Administrators should review Rovo permissions, apply patches, and monitor outbound connections and logs.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.