Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
A flaw in DeepSeek's open-source tool DeepSeek Harness let AI agents running in a sandbox lift their workspace restrictions. Agents could call the tool's web API or command interface to break isolation, risking data exposure, privilege escalation, and lateral movement across managed infrastructure.
Alby warned of a critical vulnerability in Alby Hub that can be exploited when the Hub is reachable from the internet, potentially letting attackers take control of a wallet and move funds. Alby Hub is a self-hosted Lightning wallet and v1.7.0 is among affected versions. MSPs and admins with internet-accessible Hubs should check exposure and apply updates.
U.S. cybersecurity and intelligence agencies allege China-based AI companies used distillation to extract functional behavior from frontier models such as Claude, GPT, Gemini and Grok at scale. For MSPs and sysadmins this raises IP, model-safety and regulatory concerns as reproduced capabilities spread and pose operational and security risks.
Google released updates addressing 230 security issues, including a medium-severity V8 bug (CVE-2026-87491) that is actively exploited in the wild. The out-of-bounds write in V8 can enable code execution from within Chrome's sandbox. Update Chrome on endpoints and managed client systems immediately.
Microsoft announced it will retire the Publisher desktop app and shut down the Project Online cloud service, with Office 2021 support ending in October. For MSPs and sysadmins this means planning for license changes, data and workflow migrations, and reassessing integrations—customers may face higher-cost replacements.
cPanel fixed a vulnerability that allowed an authenticated account with mail privileges to place files via EmailTrack and execute code with root privileges on the server. The advisory on September 8 says all supported cPanel and WHM versions were affected; administrators should apply the update immediately.
A researcher says Iterable credentials were left in front-end JavaScript over a four-year period with excessive privileges. Those keys could have exposed 8.8M customer records or allowed mass deletion; operators should avoid embedding secrets in client code, enforce least privilege and rotate keys.
Cloudflare Workers now enables Node.js compatibility by default and increases the package size limit to 64 mebibytes. A URL-based module registry, import.meta support, deferred compilation, shared code caches and clearer error reporting aim to simplify migrating Node apps, speed startups and improve debugging.
Virgin Media has moved its email operations to third-party provider Junara. Customers have 45 days to migrate mail or switch to Junara; MSPs and sysadmins should plan for mailbox backups, MX/DNS updates, SLA adjustments and a possible rise in support requests.
More than 36,000 internet-facing Plex Media Server instances remain unpatched against multiple vulnerabilities and are exposed to potential attacks. Administrators should update Plex immediately, restrict or disable remote access, tighten network access controls and monitor logs.
An anonymous researcher using the name Nightmare Eclipse published a ShieldCrash exploit targeting Microsoft Defender that can achieve SYSTEM-level control. Because it appeared immediately after Microsoft's September 2026 Patch Tuesday, administrators should urgently review telemetry, isolate suspect hosts and follow Microsoft's guidance for mitigations.
Google released updates addressing 230 vulnerabilities, including a Chrome zero-day that is being exploited in the wild — the seventh Chrome zero-day fixed this year. MSPs and sysadmins should prioritize deploying browser updates across endpoints and monitor customer environments for related indicators.
Microsoft's latest Patch Tuesday delivers fixes for 974 CVEs, a new high. Adobe also published important patches. MSPs and sysadmins should triage critical updates, test compatibility and schedule deployments to reduce exposure and avoid outages.
OpenAI claims GPT-6 Astra can operate a retailer and produce higher sales than Anthropic's models. Such retail automation could shift infrastructure, integration, data security and monitoring needs, so MSPs and sysadmins should track potential impacts.
Google DeepMind released a genome atlas created using AI. Genomics-scale models demand substantial compute and storage, so providers should review GPU availability, scalable storage and data privacy controls. Cloud and hybrid resource planning becomes more important for customer infrastructures.
CrowdStrike has been tracking a financially motivated actor called Slim Spider active against Brazilian financial organizations since March 2026. The group reportedly exfiltrated crypto custody data from a Brazilian institution and shows detailed knowledge of local payments infrastructure. MSPs and sysadmins should review access controls, logging and incident response for finance or crypto customers.
Microsoft released updates addressing at least 974 vulnerabilities across Windows and other software, marking its biggest single patch release to date. The company says AI is speeding vulnerability discovery, but many MSPs and organizations will struggle to prioritize testing and deploying so many fixes.
Microsoft released Windows 11 APIs that let apps determine whether a user is a child, teen, or adult without exposing the exact birth date. For MSPs and sysadmins this impacts age-based access controls, parental settings and privacy policies, so plan updates and policy changes accordingly.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.