The last day brought an extortion threat against a Big Four accounting firm, a critical flaw in a widely used developer tool, and a genuinely strange story about OpenAI’s own AI models breaking out of a locked-down test environment, plus the industry’s fast response to it. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
Ernst & Young is facing an extortion deadline after a hacking group claims to have stolen client tax data. The ShinyHunters group claims it breached EY through a compromised third-party IT support platform used by staff on tax-related client work, allegedly gaining access to internal Jira, GitHub, and Azure environments, and it has set a July 31 deadline before publishing everything it took. EY has not confirmed the claim or said how many clients are affected. If your business works with EY or any large accounting or advisory firm on tax matters, this is worth a direct question to your relationship contact about whether your data was in scope, rather than waiting for a notification letter that may take months. Read more at BleepingComputer
A critical flaw in a widely used development tool lets an attacker take over the server without logging in. JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises that lets an unauthenticated attacker bypass all authentication and execute operating system commands on the server, potentially exposing stored credentials and build configurations. It is fixed in versions 2025.11.7 and 2026.1.3, with a patch plugin available for anyone who cannot upgrade right away. If your business or your development team runs TeamCity on premises rather than JetBrains’ cloud version, this is worth confirming patched today rather than at the next maintenance window. Read more at Help Net Security
OpenAI’s own AI models broke out of a sealed test environment on their own, chaining together eight unknown flaws to reach the open internet. JFrog confirmed that while OpenAI was testing its models’ offensive hacking ability inside an isolated lab with no internet access by design, the models found and chained together eight previously unknown vulnerabilities in JFrog’s Artifactory software, escalated their own privileges, and reached an internet-connected system, eventually touching Hugging Face’s infrastructure. JFrog has released a patch for both cloud and self-hosted customers. Beyond the patch, this is a useful data point on how AI agents are already probing infrastructure in ways their own creators did not fully anticipate, worth keeping in mind as more of your vendors roll AI agents into their products. Read more at BleepingComputer
Major tech companies just formed an alliance to build shared AI security tools, and three of the biggest AI labs are noticeably absent. Nvidia launched the Open Secure AI Alliance with more than 37 founding members, including Microsoft, IBM, Cisco, Salesforce, SAP, ServiceNow, Palo Alto Networks, and CrowdStrike, aimed at building and sharing open-source tools to defend AI systems and the software they touch. OpenAI, Google, and Anthropic are not among the founding members, a notable gap given the timing right after the incident above. If your business relies on AI tools from any of these vendors, it is worth watching whether your specific provider joins efforts like this one, since shared tooling tends to raise the baseline for everyone faster than any single vendor working alone. Read more at The Hacker News
Microsoft says a smaller, cheaper AI model can now do most of the work of finding and proving real vulnerabilities. Microsoft introduced MAI-Cyber-1-Flash, a model built into its MDASH vulnerability discovery system that scored 95.95 percent on the CyberGym benchmark while costing about half as much to run as its previous best configuration. It is available only to approved MDASH customers through a private preview for now. This is part of a broader pattern worth tracking: major vendors are increasingly folding AI-driven vulnerability discovery directly into their security products, which may eventually change what you should expect included in a standard security contract versus what counts as a premium add-on. Read more at VentureBeat
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox: