Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A Chinese-speaking threat actor has conducted attacks since January 2025 against government and public organizations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria. The intrusions are linked to OctLurk and SilkLurk toolsets; MSPs and sysadmins should review detection, network segmentation and incident response preparedness.
Blackpoint Cyber researchers uncovered a campaign using the Go-based HollowFrame loader and Rust-based Matryoshka malware against a law firm. The attack starts from a link to an encrypted archive that contains a Windows LNK; executing it launches a multi-stage infection chain. Admins should tighten email filtering, restrict LNK execution and reinforce EDR and monitoring.
The developer who named HashiCorp has released a new, faster terminal multiplexer that offers persistent session support. For sysadmins this can improve session continuity and reconnection speed; check compatibility with tmux/screen, integration points and security before adopting.
A sub-cluster of Russian actor Midnight Blizzard, Storm-2945, has been compromising hospitality sign-in portals since May 2026 to push malware to travelers and harvest credentials. MSPs and sysadmins should verify portal integrity, enforce MFA and WAF protections, and increase logging and endpoint defenses.
Since May 2026, Storm-2945, a Midnight Blizzard sub-cluster, has been compromising hotel and hospitality login portals to infect guest devices with malware and harvest credentials. MSPs and sysadmins should audit captive portal security, enforce MFA, segment networks, strengthen endpoint defenses and monitor access logs while tracking related threat intelligence.
Bitsight says some low-cost Android TV boxes include apps that alter device identity to impersonate Samsung, Huawei, Xiaomi or Vivo phones and click ads on sites run by the same operators; researchers named the campaign Fuyao and tied it to Zhejiang Fengwo IoT Technology Co., Ltd. The same apps also turn boxes into outbound proxy exits using owners' broadband, creating bandwidth, IP reputation and abuse risks for MSPs and admins.
Threat actor ShinyHunters accessed the SaaS environment of a prominent physical security vendor. MSPs and sysadmins should assume integrations, API keys and credentials may be exposed; review access controls, rotate credentials and enable monitoring for suspicious activity.
Google patched 1,072 security issues across Chrome 149 and 150, a total that exceeds the fixes in the prior 23 releases combined. The subsequent Chrome 151 update fixed another 370 bugs, 349 of which were reported by Google itself. MSPs and sysadmins should prioritize testing and deploying these updates promptly.
Amgen reported that attackers accessed corporate and patient data across multiple cloud environments managed by external providers. For MSPs and sysadmins, such supplier-side breaches underline the need to review vendor security, encryption, access governance, logging and incident response for customer-hosted data.
A US bank relied on a ransomware group that claimed it would delete stolen data; trusting such promises is risky. For sysadmins and MSPs this highlights the need for robust backups, protections against data exfiltration, forensic preservation and timely regulatory or law enforcement engagement.
Arch Linux has paused allowing others to adopt AUR packages following a rise in incidents where attackers took over package maintainership. MSPs and sysadmins should treat AUR as a higher supply-chain risk and verify maintainers, signatures and update provenance before deploying AUR-sourced software.
Researchers at Nanyang Technological University in Singapore found 84 vulnerabilities in 4G/5G core infrastructure. Several issues could cause denial-of-service or allow attackers to hijack user sessions, creating direct risks for operators and MSPs responsible for customer connectivity and core systems.
A malicious script injected into Adform's ad code modified wallet addresses copied to users' clipboards, substituting attacker-controlled addresses. Sites running Adform could expose users' crypto to theft; managed service providers and sysadmins should treat third-party ad scripts as a supply-chain risk.
Anthropic and OpenAI are pushing autonomous agent capabilities in a competitive race, which raises the chance of unexpected harmful behaviors. For server and MSP operators the concern is agents causing data leaks, unauthorized access or misuse of cloud resources, creating operational and financial risks.
The misuse of the OAuth 2.0 device authorization flow to capture access tokens, called device code phishing, escalated from a niche red-team tactic to large-scale attacks in months. For MSPs and sysadmins this enables token-based takeover of customer cloud and API access; review OAuth policies, conditional access and user training.
Unit 42 of Palo Alto Networks found a Chinese-speaking actor using DeepSeek embedded in the open-source Hermes Agent to scan internet-facing systems and select public exploits after a single Telegram instruction; no further operator activity was observed. The actor is tracked as knaithe / KnYuan. MSPs and admins should monitor for Hermes Agent, block Telegram-based C2, patch exposed services and tighten network segmentation.
Microsoft warns that some versions of the Teams mobile app could stop showing or syncing calendar data after October. MSPs and admins should enforce the update or roll it out to devices to avoid calendar access disruptions for users.
CAF Bank's online banking has been unavailable for a week, with about 14,000 customers still without a restoration date. Some charities cannot complete staff payments, so MSPs should review contingency payment methods and emergency access for affected clients.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.