Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
Microsoft introduced Project Perception as a new cyber security stack tailored for the AI era. As AI workloads and threats evolve, telemetry, detection and control models need updating; managed service providers and sysadmins should plan for greater visibility and automation.
Microsoft's External Red Team Alliance (EXTRA) partners with universities, researchers and regional experts to discover risks in advanced AI models and enhance security testing and system resilience. For MSPs and sysadmins, the effort will surface new adversarial techniques and testing practices to consider when deploying and hardening AI-powered services.
Microsoft brings together universities, researchers and regional experts under EXTRA, a global red teaming effort. The program aims to surface emerging AI risks, improve security testing and harden frontier models — a signal for MSPs and sysadmins to review testing, monitoring and incident response for AI-related threats.
Cloudflare published pvcli as an open-source command-line tool that offers a curl-like interface to simplify testing of privacy protocols such as OHTTP. For server admins and MSPs it helps validate implementations, simulate requests, troubleshoot privacy proxies and integrate tests into automation.
Cloudflare testing shows transit providers rewrite the ORIGIN attribute to shift traffic, impacting about 70% of BGP paths. This can skew route selection and enable traffic steering—operators should audit transit policies, reduce reliance on ORIGIN for path choice, and monitor for unexpected routing shifts.
Cloudflare's Cache Response Rules let you change how edge caches handle response headers from the origin. When headers like Set-Cookie or Cache-Control cause responses to bypass cache, you can override that behavior at the edge to keep responses cached, reduce origin load and latency, and avoid changing the backend.
In Q2 2026 Microsoft's action against the Tycoon2FA phishing platform helped reduce several major phishing methods, while attackers moved into Teams-based social engineering and more automated, multi-step attack chains. MSPs and sysadmins should monitor collaboration channels and update email defenses and detections for automated multi-stage campaigns.
Microsoft's action against Tycoon2FA coincided with declines in several common phishing methods. Attackers moved into Teams-based social engineering and increasingly used automated, multi-stage attack chains; MSPs and sysadmins should monitor Teams traffic, automation indicators and multi-stage attack signs rather than rely solely on email filters.
Microsoft and AXA XL's agreement gives AXA XL cyber insurance customers access to Microsoft Incident Response. The collaboration aims to align technical remediation, business continuity and insurance handling to speed response and limit impact. MSPs should notify customers that coordinated incident support and claims assistance are available.
Microsoft is partnering with AXA XL to provide cyber insurance policyholders access to Microsoft Incident Response services. The alliance is designed to help organizations coordinate technical response, business actions and insurance workflows to strengthen resilience against incidents.
LG Electronics USA plans to suspend smart TV apps that turn televisions into always-on residential proxy nodes. Researchers found about 42% of apps in the webOS store allowed third parties to route users' traffic, creating bandwidth, security and abuse risks that MSPs should watch for.
Match schedules, streaming choices and short breaks shifted global HTTP traffic timing and load, producing spikes during late-night games and at halftime. For MSPs and sysadmins this signals the need to revisit CDN configuration, caching, autoscaling and maintenance windows to maintain service quality.
Cloudflare has released Internal DNS to general availability, offering authoritative plus recursive name resolution for private networks managed via Cloudflare’s worldwide fabric and centralized control plane. This gives MSPs and sysadmins a unified way to manage internal DNS with Zero Trust and networking integrations and smoother scaling.
Cloudflare implemented two new WAF rules after the WordPress security team reported two high-severity flaws. The rules filter traffic for customers running affected WordPress versions, but administrators should still deploy the vendor patch immediately for their servers and clients.
Microsoft Security will be at Black Hat USA 2026 with supply chain research, hands‑on security sessions, expert discussions and a reception. The event gives MSPs and sysadmins practical insight into AI-driven risks and supply‑chain attacks, plus training and networking opportunities.
From late April to mid‑June 2026 Microsoft Defender Experts noted increased ACR Stealer activity; campaigns use ClickFix lures to exfiltrate browser credentials, access tokens and sensitive documents from enterprise environments. For MSPs and sysadmins token theft enables lateral movement and customer risk — review logs, rotate credentials/tokens and reinforce user awareness.
From late April to mid-June 2026 Microsoft Defender Experts recorded a rise in ACR Stealer activity. Campaigns use ClickFix-themed lures to harvest browser credentials, authentication tokens and sensitive documents; MSPs and sysadmins should prioritize credential/token protection and monitoring for related indicators.
Microsoft warns that as AI agents become more autonomous, identity, access and auditing controls must be tightened. The post gives practical guidance for limiting agent access—using role-scoped permissions, tool binding, credential management and detailed logging—which matters for MSPs and sysadmins responsible for customer infrastructure.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.