Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft Threat Intelligence observed an operation using over 250 ClickFix front-end domains that fingerprint visitors and only show fake software download pages to selected macOS users. The server-side gate prevents crawlers and sandboxes from seeing the lure; administrators should monitor those domains, web traffic and macOS protections.
OpenAI shut down a coordinated set of ChatGPT accounts believed to operate from Poipet, Cambodia, which were being used to support investment, romance, gambling and law-enforcement impersonation scams. For MSPs and sysadmins this underscores attackers' use of generative AI and the need to tighten account vetting, monitor API usage and implement abuse detection.
In Gartner's 2026 Magic Quadrant reports Cloudflare is the sole vendor named Visionary in both SASE Platforms and Security Service Edge. For MSPs and sysadmins this indicates market recognition of Cloudflare's combined SASE/SSE capabilities and may influence procurement and integration choices.
Researchers found services on underground forums offering access to Anthropic models (Opus 4.8, Opus 4.7, Opus 4.6 and Sonnet 4.6). Poison Claude advertises discounted Claude access but its operator can see every customer prompt. For admins this raises data-leak and rogue API-use risks; monitor third-party access and API keys.
Maksim Silnikau, the developer and operator behind Ransom Cartel, received a 16-year sentence for ransomware campaigns that impacted at least 18 companies. The conviction underscores law enforcement progress and serves as a reminder for MSPs to harden backups, network segmentation and detection/response measures.
A Canadian admitted to accessing Snowflake cloud accounts to steal data from at least 165 organizations and to participate in extortion attempts seeking millions of dollars. The case underlines the importance for MSPs and sysadmins of protecting credentials, enforcing MFA, applying least-privilege and maintaining detailed access logging and fast incident response.
A memory-corruption bug in the Open vSwitch datapath (CVE-2026-64531, dubbed OVSwrap) allows local accounts to escalate to root on many default-configured Linux distributions. A public exploit ships with prebuilt entries for roughly 800 kernel builds; admins should apply patches, audit kernels and tighten local access.
The Kali365 phishing kit directs users to Microsoft’s real sign-in page where they approve attacker-controlled device codes. Once attackers obtain access and refresh tokens they can reach email, documents and cloud services and persistently access corporate resources, increasing data-exposure and fraud risk for MSPs and admins.
A vulnerability in Gitea versions 1.22.1 through 1.27.0 lets unauthenticated attackers read any file accessible to the service account (CVE-2026-59774, CVSS 9.8). Exploitation only needs a public repository plus a specially crafted Org-mode file; no authentication or commit privileges are required. Fixed in 1.27.1 — apply the patch promptly.
KuppingerCole's Cloud Native Application Protection Platforms report ranks Microsoft as a Leader. For MSPs and sysadmins this indicates mature cloud-native security capabilities and is a relevant consideration when choosing or justifying CNAPP tools for Azure and multi-cloud environments.
Using a SQL injection flaw, attackers deployed the khunt post-exploitation toolkit into an Oracle database and leveraged it to breach a corporate network. Tools operating inside databases can bypass typical host defenses and complicate cleanup; MSPs and admins should prioritize input validation, patching, restricting DB access and close database activity monitoring.
A macOS-focused ClickFix campaign moved from openly presenting infostealer lures to hiding them behind a browser fingerprinting gate. That makes the malicious infrastructure harder to spot, but creates traffic and behavior signals defenders can use for hunting.
The macOS ClickFix campaign has moved from openly serving infostealer lures to hiding them behind a gate that fingerprints browsers to screen visitors. This makes detection and takedown harder, but gives admins new hunting signals to track malicious infrastructure.
Attackers are leveraging the recently disclosed COLDCARD flaw and the alleged $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. For MSPs and sysadmins this is critical: ScreenConnect can give attackers persistent remote access—block installers, monitor for unexpected ScreenConnect services, enforce MFA, and strengthen user training.
Cloudflare presented the Agent Access Model to rethink how task-scoped agents get permissions. It emphasizes short-lived credentials, strict identity brokering, ongoing mediation between components and trust tied to agent state to restrict agent actions. For MSPs and admins this can reduce the attack surface from compromised agents and improve least-privilege controls.
Cloudflare released Cloudflare OS to help teams adopt AI-driven workflows. The platform integrates Compute primitives and the Zero Trust suite to deliver managed AI capabilities securely; this may affect identity, access controls and deployment practices for infrastructure teams.
Cloudflare has placed Identity-aware AI Gateway into open beta. User Insights builds behavioral baselines per person and per agent from traffic and flags insider-risk when behavior diverges, helping MSPs and sysadmins detect compromised agents or malicious user activity faster.
Cloudflare developed WriteGuard to avoid relying on flawless agent and tool setups, and is rolling it out for MCP server portals in a private beta. Granular write permissions reduce the risk of accidental or overly broad changes, helping MSPs and sysadmins maintain tighter control over customer infrastructure.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.