Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Research finds that email content can escape message boundaries and interfere with webmail UIs across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail and AOL Mail. The techniques can lead to credential and token theft, account takeover and manipulation of trusted UI elements and AI mail readers; operators should review isolation and mitigation settings.
Metabase has warned a critical zero-day in its BI and data-visualization software is being actively exploited. The flaw (CVSS 10.0) permits unauthenticated SQL injection into the application's database and can lead to administrator-level access; no CVE has been assigned yet. Administrators should isolate Metabase instances, limit access, monitor logs and apply patches as they are released.
N-able released Hotfix 2 for N-central to address active exploitation of a disclosed flaw. The company reports attackers have accessed managed environments and established persistence; MSPs and admins should apply the patch, follow mitigations and audit logs for indicators of compromise.
CISA added CVE-2026-8037, a critical CVSS 9.6 command injection flaw in Progress Kemp LoadMaster, to its KEV catalog after 792 reported exploit attempts. MSPs operating LoadMaster appliances should urgently apply vendor updates, restrict management-plane access, enforce network controls and monitor logs to limit exposure.
The Danuri orbiter captured before-and-after images of ejecta from a SpaceX impact on the Moon. These images help evaluate damage from lunar collisions, support impact monitoring and highlight demand for ground systems that process space imagery.
The Head Mare hacktivist group exploited unpatched TrueConf video conferencing servers to modify installer packages and implant backdoors. MSPs and sysadmins should patch servers, verify installer integrity, and scan endpoints to detect and remove unauthorized backdoor components.
OpenAI announced plans to add Astra security to its platform while Anthropic has loosened restrictions on its Fable model. For service providers and sysadmins this signals potential shifts in model behavior and higher misuse risk—review API access, logging and network controls for customer deployments.
OpenSourceMalware researcher Paul uncovered about 800 malicious npm packages that use AI‑generated or typo‑squatted names to deliver RATs and info‑stealers targeting Windows, macOS and Linux. The campaign increases supply‑chain risk for servers and customer environments; dependency scanning, lockfiles/allowlists and network/EDR monitoring should be prioritized.
Attackers are using ClickFix-style methods to deploy a Go-written macOS stealer that can drain crypto wallets and exfiltrate browser passwords, Apple iCloud Keychain entries and cached credentials. The infection runs a shell script to fingerprint the host and fetch a payload matched to the CPU architecture; MSPs and admins should monitor for unusual scripts, remote fetches and Keychain/browser access.
Extortion group UNC6671 is using vishing against employees in finance, private equity and professional services, calling personal phones to gain access to SaaS accounts. They impersonate IT support and urge supposed urgent security migrations to harvest credentials or bypass MFA; MSPs and admins should alert staff, require verification via official channels, and enforce strong MFA and monitoring.
A former NSA official warned — after attacks attributed to Iran — that water infrastructure controllers must not be directly exposed to the internet. For MSPs and sysadmins this underlines the need to review network segmentation, access controls and secure remote access for OT environments.
Agent Plugins 1.0 proposes a single-package container format to move tools and capabilities between agent platforms. It can simplify deployment and integration for MSPs and sysadmins, but raises concerns around isolation, permissions and supply-chain risk.
With attention concentrated on AI developments, ransomware incidents have risen. MSPs and sysadmins should prioritize patching, backups, monitoring, phishing defenses and tighten remote-access controls and incident response procedures.
A reflected pre-auth XSS in the WordPress login screen affecting all versions has been fixed (CVE-2026-64638, CVSS 8.9). pwn.ai demonstrated the issue can be chained with a logged-in admin action to achieve PHP code execution on the server. Apply the security update immediately to protect servers and client environments.
The UK's MAST Upgrade tokamak achieved record plasma pressure without destabilization, marking progress in magnetic confinement fusion research. Immediate impact for MSPs and sysadmins is limited, but commercial fusion development could affect future grid capacity and data-center power planning.
The open source ecosystem is moving away from an informal, take-what-you-need era toward a more institutional, accountable phase. For those running servers and customer infrastructure, this raises the need to tighten dependency provenance, maintenance practices and software supply-chain controls.
N-able has confirmed that a 'god mode' privilege flaw in N-central was exploited and attackers accessed some customer networks. The vendor released a second hotfix and urges N-central users to apply it immediately. For MSPs this highlights the risk of a single management platform being used to pivot into client infrastructure.
ShinyHunters called a cancer diagnostics firm, tricked staff into giving access and leaked 10.9M email addresses along with personal and health data. MSPs and admins should urgently review social‑engineering defenses, access controls and incident response plans for customer data.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.