Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Alibaba's Qwen team has made Qwen-Max available beyond previous API limits, expanding deployment options for operators. DeepSeek V4-Flash presents a low-cost alternative that intensifies price competition; MSPs should revisit hardware, licensing and security implications for on-prem or hybrid deployments.
Researchers uncovered 18 npm packages that delivered a cross-platform remote access trojan (RAT) targeting users of Alibaba developer tools; the campaign appears to be a supply-chain operation aimed at Chinese-speaking environments. Attackers abused packages like 'lib-mtop' that clash with private Alibaba package names, underscoring the need for dependency audits, lockfile/registry controls and package scanning.
Malicious pull requests carrying prompt injection can be used against Google’s developer kit to make one automated agent influence or control another. For MSPs and sysadmins this raises supply-chain and CI/CD risks—harden repo review, agent permissions and automation safeguards.
Unit 42 described three attack paths against Chrome's Google Password Manager cloud authenticator. Malware running with normal user rights on Windows can authenticate to passkey-protected accounts without any prompt shown to the victim, and the strongest technique targets the master key.
Resecurity reports INC Ransomware has stepped up exploitation of vulnerabilities in SonicWall SMA 1000 VPN appliances since early August 2026 and has listed multiple victims on its leak site. MSPs and sysadmins should deploy vendor fixes, review SMA logs and access, and isolate any suspected compromised devices.
Microsoft links a global campaign against hotel and hospitality Wi‑Fi to the Russian group Midnight Blizzard (APT29). Attackers are using custom malware and techniques that intercept captive portals and network traffic to harvest Microsoft 365 credentials; enforcing MFA, conditional access and network segmentation is advised.
Researchers showed that malware on already-compromised Windows systems can abuse Google Password Manager synced passkeys to take over accounts, bypass user verification, and extract private keys. MSPs and admins should treat passkeys on compromised endpoints as at risk and strengthen endpoint security and access controls.
Platforms such as Claude, Codex and Cursor are being applied to create detection rules, triage alerts, shorten incident reports and automate routine tasks for security teams. The question has shifted from whether AI belongs in the SOC to which models suit which workflows. For MSPs and admins, validating outputs and protecting sensitive data are key operational concerns.
Censys observed a threat actor leveraging a leaked DarkSword toolkit and operating over 100 web properties, most of which are fake AWS sign-in pages hosted on the same domain as the toolkit. The campaign targets iOS devices; MSPs should review DNS/URL filtering, block malicious domains and enforce MDM and patch management.
The Russian DOUBLECUP loader-as-a-service uses a ClickFix technique to embed malicious code in PNG files stored in browser caches, enabling CountLoader on Windows and macOS and the DeviceManager RAT on Windows. This stealthy, browser-based infection route raises detection and containment challenges for MSPs and sysadmins; review cache handling and endpoint defenses.
Fake Xeno Executor installers are distributing malware that provides remote access and steals sensitive data from Roblox users. Compromised endpoints can be abused for credential theft, remote control and pivoting into customer environments, so MSPs should tighten endpoint defenses, patching and user awareness.
PNLD confirmed that names, organisations and work email addresses for police, government staff and some customers were exposed on the dark web; the incident was detected on July 26. Such data can enable targeted phishing and social engineering, so MSPs should review email defenses, MFA and customer contact handling.
The Register uses earnings reports and a podcast discussion to suggest the AI investment surge may be losing steam. For MSPs and sysadmins this could mean customers postpone AI projects, vendor consolidation and shifts in procurement or capacity planning — review contracts and cloud usage.
Cloudflare released @cloudflare/computer, an agent runtime that blends lightweight isolates with full Linux containers as needed. It provides each agent with a separate execution environment, helping MSPs and sysadmins balance performance, resource usage and compatibility when scaling agent fleets.
An internal file with officials' contact details at a UK government investment arm was publicly accessible for about 40 hours. The exposure stemmed from a misconfiguration and staff error and could enable phishing, impersonation or other targeted social engineering attacks; check access controls, audits and configuration scans.
N-able reports that an authentication bypass vulnerability identified as CVE-2026-18577 is being actively exploited against both hosted and on-premises N-central servers. MSPs and sysadmins should promptly apply patches or temporary mitigations to reduce the risk of unauthorized access and takeover of managed systems.
Cloudflare Workers now let Python and JavaScript Workers interact at runtime by passing references to in-memory objects and calling their methods without separate APIs, schemas or serialization code. That speeds cross-language integration but requires rethinking security boundaries, isolation and debugging/compatibility for managed deployments.
To fit Kimi and GLM into limited GPU memory, operators reduce KV cache precision, shrink model weight files and add runtime integrity checks. These optimizations cut latency and infrastructure costs while improving model and data integrity in production.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.