Agenda

What is happening in the industry?

Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.

Search
6 sources, 1000 stories last updated 16.09.2026 16:45
Infrastructure / Cloud Cloudflare

cdnjs (9 billion requests/day) migrated to Cloudflare Developer Platform

Cloudflare moved the open-source CDN cdnjs—handling about 9 billion requests per day—onto the Cloudflare Developer Platform. The migration led to higher Workflows and Workers limits, indicating the platform can run high-traffic services and that platform limits may influence infrastructure decisions.

30 Jul 2026 blog.cloudflare.com
Security The Hacker News

FCC adds foreign-made mobile robots and networked inverters to Covered List

On July 28 the FCC added foreign-produced mobile robots and networked power inverters to its Covered List. The change makes it harder for new models to obtain the authorizations needed to enter the US market, while previously authorized and already-owned devices remain unaffected. MSPs and admins should review procurement and compliance for these device classes.

30 Jul 2026 thehackernews.com
Security BleepingComputer

ShinyHunters claims Brinks Home breach, threatens to publish data

Brinks Home says ShinyHunters allegedly accessed parts of its internal systems and is threatening to make purportedly stolen data public. Providers and MSPs should audit logs, rotate credentials and keys, and check for exposed customer information or lateral movement.

30 Jul 2026 bleepingcomputer.com
Security The Hacker News

Amazon links September 2025 hijack of debug and chalk npm packages to North Korea

Amazon attributes the September 2025 compromise of debug and chalk to North Korea’s Sapphire Sleet. The attackers phished a maintainer via a fake npm domain and injected malicious code into at least 18 packages that together see billions of weekly downloads. MSPs and admins should audit dependencies, monitor maintainer accounts and pin versions.

30 Jul 2026 thehackernews.com
Security The Hacker News

Cisco FMC zero-day (CVE-2026-20316) actively exploited

CISA added CVE-2026-20316, which affects Cisco Secure Firewall Management Center (FMC), to its KEV list after reports of active zero‑day exploitation. The CVSS 5.3 vulnerability may permit unauthenticated remote access and risk exposing static credentials on appliances; MSPs should apply vendor fixes and audit credentials immediately.

30 Jul 2026 thehackernews.com
Industry The Register

Qualcomm not yet a major data center player

Qualcomm does not currently hold a strong position in the data center market, and losing Apple business limited its reach. Its shift toward AI accelerators could compensate for that loss and create opportunities in cloud and edge infrastructure, but server adoption remains limited for now. MSPs should monitor its product roadmap before committing.

30 Jul 2026 theregister.com
Infrastructure / Cloud The Register

Cisco retires Azure Local offering over Microsoft hardware requirement changes

Microsoft now mandates tightly integrated software-plus-hardware systems for on‑premises hyperconverged Azure. Cisco opted not to supply or certify such integrated rigs and has withdrawn its Azure Local offer; MSPs and admins should revisit support, upgrade and migration plans.

30 Jul 2026 theregister.com
Industry The Register

Microsoft cloud revenue strong, M365 AI earnings remain modest

Microsoft's cloud services continue to generate strong revenue, but AI features added to M365 have delivered only modest direct incremental income. For MSPs this underlines ongoing demand for cloud and infrastructure, while M365 AI has yet to become a major standalone revenue source.

30 Jul 2026 theregister.com
Security The Hacker News

Critical Active Storage flaw in Rails allows server file reads via image uploads

Ruby on Rails released patches for an unauthenticated Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5). Crafted image uploads can enable attackers to read arbitrary files on application servers and expose secrets such as secret_key_base, the Rails master key, database passwords and cloud storage credentials. MSPs and sysadmins should apply updates and tighten upload handling immediately.

29 Jul 2026 thehackernews.com
Security The Hacker News

Ruflo CVE-2026-59726: unauthenticated RCE and AI memory poisoning

A critical flaw in Ruflo (agent meta-harness for Anthropic Claude Code and OpenAI Codex), tracked as CVE-2026-59726 (CVSS 10.0), affects all releases before 3.16.3. Unauthenticated actors can execute remote commands and corrupt AI agent memory; Noma Security calls it RufRoot — upgrade to 3.16.3 immediately.

29 Jul 2026 thehackernews.com
Security The Hacker News

Three critical VMware vulnerabilities: auth bypass, code execution and VM escape

Broadcom released patches for VMware ESX, vCenter, Workstation and Fusion; three are rated critical. CVE-2026-59309 (CVSS 9.8) can allow attackers to circumvent authentication on vCenter if they can reach it over the network; other critical flaws may enable remote code execution and VM escape. Prioritize patching vCenter and restrict its network access.

29 Jul 2026 thehackernews.com
Security BleepingComputer

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper for persistent mailbox access

Russia-backed Laundry Bear (Void Blizzard) is exploiting a zero-day in Exchange OWA to deliver a backdoor called OWAReaper via email campaigns. The implant can give long-term mailbox access; MSPs and sysadmins should apply patches, monitor OWA and mailbox activity, and hunt for related indicators.

29 Jul 2026 bleepingcomputer.com
Security The Hacker News

Coordinated cyberattack hit 30+ Minnesota water systems; one plant offline

Between July 26–27 a coordinated intrusion into operational technology disrupted operations at over 30 community water utilities in Minnesota. The Braham facility went offline while Plymouth, South St. Paul and Maple Plain reported communication and automated-control issues, prompting a statewide cybersecurity response. MSPs should reassess OT segmentation and incident readiness.

29 Jul 2026 thehackernews.com
Security The Hacker News

Mythos warns: AI is shortening exploit timelines

Mythos highlights that AI is compressing the time to develop exploits, forcing a reassessment of which part of your vulnerability management is failing. The piece doesn't offer fixes; MSPs and sysadmins should urgently review prioritization, asset visibility, compensating controls and detection/response processes.

29 Jul 2026 thehackernews.com
Artificial Intelligence BleepingComputer

Anthropic: global access issues for Claude and API models

Anthropic confirmed widespread errors affecting Claude and models that rely on its API; some requests return a 529 Overloaded response and dependent integrations fail. Customers using AI automations, chatbots or third‑party tools may be impacted—check monitoring, retries/fallbacks and notify affected clients.

29 Jul 2026 bleepingcomputer.com
Security BleepingComputer

Cisco warns of CVE-2026-20316 static credential flaw in FMC

Cisco reports that a static credential flaw in Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, has been leveraged in zero-day campaigns to obtain unauthorized access to appliances. Administrators should quickly apply Cisco fixes, restrict management access, rotate credentials and review logs for signs of compromise.

29 Jul 2026 bleepingcomputer.com
Security The Hacker News

JIT bug (CVE-2026-10702) can compromise Tor Browser and Firefox via single webpage visit

Nebula Security reports a JIT flaw (CVE-2026-10702) in Firefox that can be exploited by visiting a malicious page and was used to compromise Tor Browser. Mozilla rated it High and fixed it in Firefox 151.0.3; admins should deploy the update immediately and consider browser isolation and URL filtering.

29 Jul 2026 thehackernews.com
Security The Hacker News

Study: 73% of organizations not fully ready for a major cyberattack

The State of Incident Response Readiness 2026, based on a January Vanson Bourne survey of 600 senior IT security decision makers, finds 73% of organizations are not fully prepared for a serious attack. While many have plans, tools and teams, shortfalls in coordination, visibility and executive buy-in raise risks for those managing infrastructure.

29 Jul 2026 thehackernews.com

Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.