The last day brought a fresh SharePoint escalation worth acting on immediately, a wave of enterprise AI product launches from OpenAI, Microsoft, and Google, and new data on the gap between using AI and actually profiting from it. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
A fourth SharePoint flaw is under active attack, and this one steals the keys needed to forge trusted logins. Researchers confirmed active exploitation of CVE-2026-50522, a critical SharePoint Server flaw that lets attackers steal “machine keys,” the credentials SharePoint uses to sign valid authentication tokens, after a public proof-of-concept exploit appeared on July 20. Microsoft patched the underlying bug on July 14, but stolen keys remain useful to an attacker even after patching, so security researchers are urging affected organizations to rotate those keys, not just install the update. If your business or your IT provider runs on-premises SharePoint Server, patching alone will not close this door. It is worth explicitly asking whether machine keys have been rotated, not just whether the patch was applied. Read more at BleepingComputer
OpenAI launched a platform meant to make AI agents safe enough to actually run a business function. OpenAI introduced Presence, a managed system for building and governing production AI agents that bundles company policies, permission controls limiting what data an agent can touch, rules for escalating to a human, and pre-launch testing against edge cases before an agent goes live. OpenAI says it has used Presence to power its own support line, where it now resolves about 75 percent of inbound requests at a quality bar matching human staff. This matters less for the specific product than for the shift it signals: the leading AI labs increasingly think the real product businesses want is not a model, but a supervised, accountable way to let AI agents touch real systems and real customers. Read more at Help Net Security
Microsoft is putting multibillion-dollar money behind European AI capacity through an expanded Mistral partnership. Microsoft and Mistral expanded their partnership with a multibillion-dollar deal for Microsoft to use capacity from new Mistral data centers in Europe built on Nvidia’s latest chips, structured as a compute purchase rather than new equity to avoid additional antitrust scrutiny. Mistral’s models are also now built into Microsoft Foundry and Copilot Studio. If your business is in Europe or has data residency requirements, this is a sign that a real, well-funded alternative to US-only frontier AI infrastructure is being built out, worth watching if data sovereignty has been a blocker for your AI plans. Read more at Microsoft Source
Google released three new AI models at once, including one built specifically to hunt security vulnerabilities. Google launched Gemini 3.6 Flash and 3.5 Flash-Lite as cheaper, faster replacements for its mid-tier models, alongside Gemini 3.5 Flash Cyber, a version fine-tuned specifically for finding and fixing security vulnerabilities. Flash Cyber is not available through the public API or app yet, limited instead to a pilot program for governments and trusted partners. A security-specialized AI model is a preview of where vendor tools are headed: worth asking your security software provider whether similar AI-assisted vulnerability scanning is on their roadmap, since attackers are already using AI agents offensively, as this week’s other stories make clear. Read more at Google
New survey data: 90 percent of companies say AI is transforming how they work, but only 18 percent see it show up in revenue. A HCLTech study of 500 enterprise decision-makers found that 90 percent report GenAI and agentic AI transforming workflows and 91 percent cite improved data access, yet only 18 percent say AI is delivering a significant revenue impact. The research found that companies actually capturing value share a pattern: they define measurable use cases up front and invest in structured training, rather than rolling out AI broadly and hoping results follow. If your business has adopted AI tools but cannot point to a specific number that changed because of them, this data suggests you are in the majority, and the fix is fewer tools with clearer success metrics, not more tools. Read more at Webnewswire
Follow up to last Friday’s story: the ransomware group behind the fairlife attack is now threatening to leak a terabyte of stolen data. The Anubis ransomware gang claimed credit for the attack that halted Coca-Cola subsidiary fairlife’s US production, saying it stole roughly one terabyte of corporate data and giving the company about a week to pay before publishing it. Anubis is also known for a “wiper mode” that can permanently destroy files rather than just encrypt them, raising the stakes if negotiations fail. This is a reminder that the initial production outage was not the end of the story. The data exposure and extortion phase often follows days or weeks later, and your incident response plan should account for both phases, not just the initial recovery. Read more at BleepingComputer
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox: