The last day brought a maximum-severity flaw under active attack in widely used SD-WAN gear, a chained WordPress exploit that can hand an attacker admin access on a default install, a dental benefits breach touching more than 23 million people, and a quarter-trillion-dollar sign of how shaky the financing behind AI’s buildout really is. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
A maximum-severity flaw in a popular SD-WAN management tool is under active attack right now. Attackers are exploiting CVE-2026-16812, a command injection flaw in on-premises versions of Arista’s VeloCloud Orchestrator that scores a perfect 10.0 for severity. No login is required, just network access to the web interface, and a successful attack can hand attackers control of the orchestrator and the edge devices it manages. Arista has patched the flaw and CISA has ordered federal agencies to patch by July 30. If your business or your IT provider runs VeloCloud Orchestrator on premises, this is not a patch to schedule for next month. It is worth confirming today that you are on a fixed version. Read more at BleepingComputer
A chained WordPress bug lets an anonymous visitor take over a default install with no plugins required. Security researchers disclosed a way to chain two WordPress Core flaws, a REST API logic bug (CVE-2026-63030) and a SQL injection in WP_Query (CVE-2026-60137), into a pre-authentication path that creates an administrator account and then executes code on the server. Both were patched on July 17, but CISA confirmed active exploitation was already underway before most sites had a chance to update. If your website runs on WordPress, whether you manage it yourself or a vendor does, this is worth a same-day confirmation that you are running version 6.9.5 or 7.0.2 or later. Read more at The Hacker News
A dental benefits breach exposed the personal and health information of more than 23 million people. DentaQuest, a Sun Life subsidiary that administers dental benefits for tens of millions of Americans, disclosed that attackers had access to its network for several days in May, stealing names, addresses, Social Security numbers, and Medicaid and Medicare details. The ShinyHunters extortion group claimed responsibility and published the stolen data after negotiations broke down. If your company offers dental benefits through a third-party administrator, this is a good prompt to ask your benefits broker whether any of your carriers were affected, since these vendor breaches tend to surface employee exposure well after the fact. Read more at SecurityWeek
A previous Fortinet patch did not actually close the door, and CISA just flagged it. CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog this week, a FortiOS flaw that lets an unauthenticated attacker bypass an earlier fix for a symbolic link persistence issue using crafted HTTP requests. In plain terms, some organizations that believed they had already patched this class of bug are still exposed. If your business runs FortiGate or FortiOS, it is worth checking with whoever manages that firewall whether this specific bypass has been addressed, not just whether “the Fortinet patches” went in. Read more at Security Affairs
Nvidia is reportedly weighing a $250 billion guarantee just to help OpenAI rent a data center, a sign of how thin the financing behind the AI buildout has become. Nvidia is in talks to backstop as much as $250 billion in financing so OpenAI can lease a massive data center campus planned for Ohio, with a separate discussion underway for Nvidia to finance up to $350 billion of the chips inside it. The arrangement is reportedly needed because OpenAI, still unprofitable, cannot get an investment-grade credit rating on its own. Whatever AI tools your business depends on, it is worth remembering that the vendors behind them are often financed in ways that would not pass muster for an ordinary company, and that is worth factoring in if you are building critical workflows around a single AI provider. Read more at Tom’s Hardware
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox: