The last day brought fresh data on just how hard ransomware gangs are leaning on small and midsize businesses, a cautionary tale out of one of the country’s largest healthcare companies, and a couple of moves that will shape how AI actually shows up in your tech stack this fall. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
Ransomware gangs are targeting SMBs harder than ever, new data shows. Fresh research compiled by security firm NordStellar found more than 2,500 ransomware attacks in the second quarter of 2026 alone, with US small and midsize businesses absorbing the largest share, 769 incidents, well ahead of Canada, Germany, and the UK. Two rival gangs, Qilin and The Gentlemen, are driving much of the spike as they compete for high-profile hits the way rival gangs chase reputation, and attacks on billion-dollar enterprises are up sharply too, but researchers note SMBs remain the preferred target because they typically have thinner defenses. If you run a small or midsize business, you are not flying under the radar the way you might think, you may be exactly the size these groups are hunting right now, so this is a good week to confirm your backups are actually tested and that multi-factor authentication is enforced everywhere, not just switched on somewhere. Read more at TechRadar Pro
A single phone call breached Abbott Laboratories’ single sign-on, and the fallout is still unfolding. The extortion group ShinyHunters says it gained access to Abbott Laboratories by vishing, a voice phishing call, targeting employees in mid-June, which was enough to compromise a Microsoft Entra single sign-on account and pull data from connected systems. Abbott is still investigating two separate incidents and has been negotiating with the group, which has repeatedly extended its leak deadline, most recently to July 21, and the company says no stolen data has been released and no customer operations have been affected so far. A company with Abbott’s security budget still lost ground to a phone call, so if your team has not been specifically trained to spot vishing, and your SSO login does not require phishing-resistant MFA, that is a gap worth closing before someone tests it on you. Read more at BleepingComputer
Pax8’s new “Managed Intelligence” program for IT providers goes live this month. Pax8, one of the largest marketplaces IT providers use to sell cloud and security tools, is rolling out general availability this month for its Managed Intelligence Provider program, first unveiled in June, bundling an AI readiness assessment, a workflow automation service, and custom agent builds that IT providers can resell to their clients. If your IT provider starts pitching an “AI transformation” package this fall, this is likely where it is coming from, and it is worth asking exactly what is custom to your business versus what is a repackaged assessment everyone is getting, so you know what outcome you are actually paying for. Read more at Pax8
Copilot is no longer an add-on for small Microsoft 365 plans, it is built in. As of July 1, Microsoft made Microsoft 365 Business Standard with Copilot and Business Premium with Copilot permanent SKUs for companies with 1 to 300 seats, priced at $23.50 and $32 per user per month, and it is also rolling out “Copilot in 30” starting August 1, a 25-user, 30-day Copilot trial aimed at helping smaller companies test the waters before committing. This is separate from the broader Microsoft 365 price increases already in effect, it is specifically about how AI is now packaged for smaller businesses. If you are on Microsoft 365 with fewer than 300 seats, Copilot is no longer a side decision, it is baked into your renewal math now, so before you upgrade tiers or add seats, it is worth actually running the numbers on whether your team will use the AI features enough to justify the jump, rather than paying for capability that sits unused. Read more at Windows Forum
A $1.2 billion startup wants to rethink endpoint security for the age of AI agents. Glow, a Tel Aviv-based security startup founded by former engineering leaders from Meta, Snowflake, and Claroty, emerged from stealth this week with $180 million in funding at a $1.2 billion valuation, building tools to give security teams visibility and control over what AI agents and copilots are actually doing on company laptops, arguing that traditional endpoint security was not built for software that can act on its own. This is a signal of where the market is heading: as more employees run AI copilots and agents on their machines, “what is this thing allowed to do” is becoming its own security question, and if your team is already using AI tools day to day, it is worth asking whoever manages your IT how those tools are being monitored today, since that oversight gap is exactly what this new wave of products is built to fill. Read more at TechCrunch
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox: