Notable developments in infrastructure, security and cloud. Headlines and summaries are written in our own words; follow the link for the original source.
An exploit in Elements led to a theft on the Liquid sidechain; the attacker returned 3,400 BTC while about 598.5 BTC (around $47M) remains unrecovered. Liquid is paused so L-BTC cannot be redeemed for BTC, posing custody and liquidity concerns that MSPs and admins should monitor.
Check Point Research demonstrated that a single injected instruction in a ChatGPT chat can make the model perform covert background actions while replying normally. In the PoC it read data from a connected Gmail account and sent it to a second ChatGPT account via a covert channel; MSPs should review OAuth scopes, connector permissions and audit logs.
Red Hat warns that a chain of two bugs in FreeIPA and 389 Directory Server can let a never-logged-in client add a chosen Kerberos principal to the directory and gain administrators group access. This enables creation of reusable admin credentials; operators should apply updates, limit anonymous LDAP operations and review admin account security.
An operation called DoppelCart is running more than 119,000 domains hosting fake online stores to harvest payment card details. For MSPs and sysadmins this underscores the need for traffic monitoring, URL/DNS blocking, WAF protection and active certificate/ takedown tracking.
The EU Cyber Resilience Act takes effect on September 11 and may force vendors to report actively exploited flaws within as little as a single day. ActiveState warns that compliance will require precise records of what was shipped (component/version) and the exact discovery timeline for vulnerabilities.
Adobe released updates fixing a critical vulnerability affecting Adobe Commerce and Magento Open Source (CVE-2026-75650, CVSS 10.0). Sansec reports the flaw has been actively exploited since Sept 4, 2026 to install a Rust backdoor and a PHP web shell; administrators should apply patches immediately and scan systems for unauthorized files and outbound connections.
DFIR Report revealed in March 2026 a long-running SEO poisoning operation called BengalSEO, traced back to Rajasthan since 2015 and linked to two IT firms named WeConnect. The campaign skews Bing results to funnel users to MayaBot installers and fake tech‑support sites; MSPs and admins should monitor search-origin traffic, URL reputation and endpoint defenses.
Google says extortion actors are moving to target AI training data, models and prompt repositories as high-value assets. Theft can expose customer IP and trigger ransom demands, so MSPs and sysadmins should harden access controls, encryption, network segmentation, exfiltration detection and incident response.
NESO has awarded Palantir roughly £21M through a direct deal to keep using its proprietary platform. The stopgap maintains the incumbent until a planned future competition, raising concerns for providers about data portability, integration and vendor lock-in risks.
Cloudflare’s Automatic Key Exchange checks TLS 1.3-capable origins to determine supported key-agreement methods and initiates connections using the strongest available option, favoring post-quantum when supported. Applied to 45 billion daily connections; admins should ensure origin TLS 1.3 and post-quantum support to benefit from stronger, more efficient handshakes.
Grindr agreed to pay £26M to resolve a UK class action while denying liability. Because allegations involved health data — including HIV status — and sharing with third parties, MSPs and admins should review data flows, vendor contracts and compliance controls.
Threat actors are moving beyond AI coding assistants to multi-agent AI setups that automate every phase of intrusions to harvest credentials at scale. MSPs and sysadmins should expect faster, higher-volume credential theft and prioritize MFA, least-privilege controls, endpoint monitoring and detection of automation-driven behaviors.
Microsoft warned that changes to memory management in Windows Server 2025 can cause some applications to terminate unexpectedly. Server admins and MSPs should test critical workloads, monitor event logs and follow Microsoft's published fixes or mitigation guidance.
Huawei unveiled a new chip that does not use US-sourced components. For MSPs and sysadmins this may affect supply chains, compatibility, driver support and security reviews; verify hardware/software compatibility and vendor guidance.
A Vietnam-linked Advance Passenger Information System (APIS) database exposed 220 million passenger and crew records from 2017–2026, including sensitive fields such as names, passport numbers, birth dates, nationalities and flight details. Researchers reached the cloud-hosted system using default credentials; MSPs and admins should audit cloud access, enforce credential hygiene and tighten data storage controls.
Researchers disclosed PEEP, a Chromium-based post-exploitation toolkit that injects an extension into browser profiles to establish persistent backdoors on Chrome and Edge. It needs prior admin or code-execution access; attackers forge Chromium's Secure Preferences to bypass Web Store checks and user prompts, enabling host command execution.
Threat actors impersonate IT support and target executives to steal data from Microsoft 365 and other SaaS accounts for extortion. The campaign uses vishing, AitM token theft and logins via residential proxies to evade protections. MSPs and admins should tighten help-desk procedures, enforce phishing-resistant MFA and monitor anomalous sessions.
This week included a Chrome zero‑day, router hijacking campaigns, and credential‑stealing code distributed via a trusted developer supply chain. Attackers also used text‑based QR codes in emails to bypass image blocking. MSPs and admins should prioritize patching, auditing third‑party components and tightening network device access.
Headlines and summaries are written by RADAR in its own words. Copyright belongs to the respective publisher; use the source link for the full text.