Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Oracle has added Google Gemini LLMs as an agent option in its Fusion automation platform. Managed service providers and sysadmins can now direct automation tasks to Gemini, which requires reassessing security, data residency, model governance and cost implications before use.
A patched Azure Cosmos DB flaw could let an attacker bypass Gremlin query isolation and obtain a key usable across the platform to reach databases in other tenants. Wiz named the exploit chain 'CosmosEscape'; this raises data-segregation and credential risks for MSPs.
The Personal Information Protection Commission (PIPC) fined KT Corporation KRW 53.979 billion (~$39M) for shortcomings in protecting customer data. The penalty signals rising regulatory scrutiny; MSPs and admins should reinforce data security, vendor oversight and incident response practices.
JetBrains warned of a critical authentication bypass in TeamCity On-Premises that can enable remote code execution. MSPs and admins running on-prem TeamCity should prioritize applying fixes, restrict network exposure of instances, and review logs for suspicious activity.
Microsoft 365 Copilot for Word can transfer hidden instructions from a source file into the generated document; researcher Håkon Måløy disclosed the technique on July 28 after a 144-day reporting window. If the produced file is reused in another Copilot session it can re-trigger those directives, risking leakage of embedded prompts or unintended edits in client documents.
Network infrastructure and firewalls are turning into the primary control points for AI traffic, enforcing policies and providing visibility. For MSPs and sysadmins this means network-based monitoring, prevention of data leaks and model misuse, and tighter policy integration are now essential.
A new analysis shows cheap 'unlimited content' streaming devices not only share users' internet but also impersonate mobile browsers to click ads on AI-generated sites as part of broad ad and merchant fraud. For admins and MSPs this creates bandwidth drain, IP reputation risk and large volumes of automated traffic originating from customer networks.
South Korean authorities and security firms say state-linked actors compromised trusted domestic websites to exploit vulnerable AnySign4PC installs and silently deliver SIGNBT or COPPERHEDGE backdoors to visitors. Infections occur without user prompts; MSPs and sysadmins should inventory AnySign4PC, apply updates or removals, and strengthen endpoint and network monitoring.
Chinese actor SilverFox targeted a Japanese industrial manufacturer using a three-driver BYOVD chain to deploy ValleyRAT (aka Winos 4.0) and obtain persistent remote access. MSPs and sysadmins should prioritize monitoring driver loads, enforcing driver signing/whitelisting, and detecting kernel-level indicators of compromise.
Microsoft Security’s July 2026 update delivers changes to protect AI workloads, apply AI-based defence capabilities, and reinforce the infrastructure that AI-powered operations require. MSPs and sysadmins should review new controls for access, monitoring and configuration hardening.
In July 2026 Microsoft rolled out security updates aimed at protecting AI environments, applying AI to defence, and strengthening the infrastructure behind AI-powered operations. The improvements help IT teams and MSPs deploy AI workloads more securely and add automated detection and response capabilities to improve threat handling.
Microsoft added a new Copilot button to the Classic Outlook toolbar, making the AI feature more prominent for users. Administrators should review deployment options, licensing, privacy implications and available controls to manage rollout and user experience.
Amazon found that supply-chain attacks involving the npm packages Debug and Chalk are linked to North Korean actors. For sysadmins and MSPs this highlights the need to audit dependencies, tighten CI/CD and registry controls, and use package scanning and signature checks to reduce compromise risk.
Broadcom released patches for five vulnerabilities in VMware vCenter, ESX, Workstation and Fusion; three are critical and can enable authentication bypass, arbitrary code execution, or escape from a VM to the host. Administrators and MSPs should prioritize updating management servers and multi-tenant hosts promptly.
The FTC alleges telehealth provider Hims & Hers passed sensitive patient details to Meta and Snap and made it hard for customers to cancel prescription subscriptions. This raises privacy concerns, potential data sharing to ad platforms and unexpected billing risks that infrastructure teams should review.
Starting July 22, 2026, Russian-linked operators exploited a Microsoft OWA vulnerability to maintain access to mailboxes across US and European government targets and multiple commercial sectors. Access persisted despite credential rotations; admins should apply updates, review active sessions, check mailbox rules and permissions, and revoke suspicious sessions or tokens.
MariaDB has raised new doubts about Galera's open-source status: the vendor will discontinue support for the MySQL variant in September while developing a separate paid replication product. Service providers and sysadmins relying on Galera should review support and licensing, evaluate alternatives and prepare migration or continuity plans.
Google reports it fixed 1,072 security bugs in Chrome across two recent releases after expanding use of AI. AI-assisted scanning and triage sped up discovery and remediation, so admins and MSPs should prioritize installing these updates and review their patch deployment processes.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.