Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed attackers accessed its DAVID driver records using stolen credentials tied to a police department employee. The breach underscores the danger of compromised internal accounts and potential exposure of personal data; MSPs and sysadmins should prioritize credential hygiene, MFA and log audits.
A Ukrainian lawyer who left legal practice to develop malware for Conti was extradited to the US, pleaded guilty and received a four-year prison term. The case highlights that attackers can come from professional backgrounds and that international cooperation is effective in prosecuting them — MSPs should be aware that skilled developers may be recruited into ransomware operations.
Actors tied to ShinyHunters, Helix and other extortion groups are using social-engineering lures that mimic passkeys and SSO to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365. MSPs and admins should tighten SSO monitoring, conditional access, session logging and user awareness to lower risk.
Wiz found attackers combined two vulnerabilities in self-hosted JFrog Artifactory to obtain administrator access and deploy backdoors. Incidents were seen between Aug 15 and Sep 8; only unpatched instances were impacted — MSPs and admins who missed updates are exposed.
Cloudflare CASB now provides a built-in automation engine to address SaaS risks. Security teams can create event-driven rules to revoke risky file shares and trigger webhooks, cutting manual steps and helping reduce customer data exposure.
Gen Digital reports that China-linked UNC3569 exploited a vulnerability in the widely used Sogou Input Method for Windows via a crafted link to install the GRAYRABBIT backdoor. The compromise allows attackers to operate with the logged-in user's permissions; administrators should scan affected endpoints, hunt for indicators and apply updates or mitigations.
Attackers chain critical and high-severity JFrog Artifactory flaws to bypass authentication, gain admin privileges and deploy a Rust backdoor on self-hosted servers. MSPs and sysadmins should patch affected versions immediately, reset credentials, inspect logs and binaries, and isolate any suspected hosts.
PaperCut published maintenance releases that replace earlier emergency fixes; PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are available for download. Administrators of print infrastructure should update quickly to remediate the two actively exploited vulnerabilities and replace temporary patches with the full fixes.
Cisco says three distinct threat clusters abused two recently patched Secure Firewall Management Center (FMC) vulnerabilities to exfiltrate credentials and deliver Qilin ransomware. The attacks leveraged critical flaws including CVE-2026-20079 (CVSS 10.0). MSPs and sysadmins should apply FMC updates, audit access and rotate credentials.
Digital Research's project GEM presents an alternative design for the Linux graphics stack. It aims to reduce incompatibilities between X11 and Wayland, which could affect GUI app compatibility, remote desktop and container display workflows. Server admins should watch for impacts on remote access and virtualization setups.
A content-management system lost roughly 500 pages of company documentation. Check backups, access controls and audit logs immediately; prioritize recovery, versioning and continuity plans to protect customer material.
Threat actors are abusing popular AI services to host malicious content, manipulate search results and trick users into installing malware. Campaigns target Claude Artifacts, shared AI conversations, sponsored search listings and ClickFix-style lures; MSPs and sysadmins should strengthen output validation, access controls and download protections in customer environments.
DeepSeek's V4.1 Flash shows a larger LLM can be served with the same or fewer GPUs. That can reduce GPU costs, simplify hosting and improve capacity and latency planning for MSPs and sysadmins.
GitLab is advising administrators to immediately apply fixes for CVE-2026-85706, a maximum-severity path traversal flaw. Path traversal bugs can allow attackers to reach files outside intended locations and risk system compromise; operators should install the update and review access controls.
Microsoft resolved a bug introduced by updates since the August 2026 Patch Tuesday that stopped Teams and Outlook from starting on ARM-based Windows devices. MSPs and sysadmins should deploy the patch to affected machines, verify user access, and roll out updates in controlled rings with testing.
Trezor reported a phishing campaign after the Brevo breach that targeted 347,000 email addresses and saw 2,500 users click a malicious link. MSPs and sysadmins should audit client accounts, enforce 2FA, tighten email filtering and notify affected customers.
A Ukrainian national was sentenced to four years for involvement in Conti ransomware incidents during 2021–2022. For MSPs and sysadmins this underlines that law enforcement can disrupt criminal infrastructure but threats persist; keep backups, tighten access controls and validate incident response plans.
OpenAI introduced GPT-Live-1, which enables simultaneous speaking and listening for more fluid, low-latency voice applications. For MSPs and sysadmins this raises considerations around real-time audio streaming, scaling and compute costs, plus handling and securing voice data.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.