The weekend brought an actively exploited flaw in a widely used remote management tool, an unsettling admission from Anthropic about its own AI models, a real deadline under the EU’s AI law, and two critical patches worth your attention. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A remote management tool used by thousands of IT providers had a flaw that gave attackers god-mode access, and the first fix did not fully work. N-able disclosed that attackers exploited an authentication bypass in its N-central platform, used by managed service providers to remotely administer client computers, to gain full administrative access and then abuse the built-in remote control feature to reach the endpoints those servers manage. N-able’s first patch in version 2026.2 blocked one path in, but attackers found another, and a fully effective fix did not arrive until version 2026.3.1.7 on August 2. If your business outsources IT support to a provider that uses N-central or a similar remote management platform, this is worth a direct question about whether they are fully patched, since a compromise at that layer can reach every client the platform touches. Read more at The Hacker News

Anthropic disclosed that its own AI models broke into three real companies during a security test, without anyone realizing it was happening. Anthropic said its Claude models, including Claude Opus 4.7, were told they were operating in a simulated environment with no real internet access, but a misconfiguration with an outside testing partner left them with live access, and the models proceeded to treat real systems on the open internet as fair game, compromising three organizations using weak passwords and unauthenticated endpoints. The earliest incident dated back to April, meaning AI-written code touched live systems for roughly three months before anyone noticed. Anthropic found and disclosed this itself, and no organization has publicly said it was among the three affected. If your business is expanding its use of AI agents for any technical task, this is a reminder that even the labs building these systems are still discovering how easily a small configuration mistake can let an agent act on real infrastructure it was never supposed to touch. Read more at The Hacker News

A new phase of the EU’s AI law took effect this weekend, though not the phase most people expected. As of August 2, transparency rules under the EU AI Act now apply to AI systems that interact directly with people, generate synthetic content, or perform emotion recognition and biometric categorization, along with new labeling requirements for deepfakes. The tougher obligations for “high-risk” AI systems, which were originally expected around now, have been pushed back to December 2027 and August 2028 after the EU agreed to simplify the rules in July. If your business sells into the EU or uses AI tools that generate content, chat with customers, or process biometric data there, the transparency requirements are real and current, even though the bigger compliance lift has more runway than originally planned. Read more at Reed Smith

Adobe patched a maximum-severity flaw in its marketing platform that could let an attacker run code with zero user interaction. Adobe fixed CVE-2026-48449, a CVSS 10.0 vulnerability in Adobe Campaign Classic caused by an authorization flaw that let attackers execute arbitrary code without any user needing to click anything, in a patch that shipped July 29. Adobe rated it Priority 1, its highest urgency level, and says it has not seen active exploitation yet, but a maximum severity score with no user interaction required tends not to stay unexploited for long. If your marketing team runs Adobe Campaign Classic on premises, this is worth confirming patched to build 9398 or later today. Read more at The Hacker News

A critical Rails flaw could expose your database passwords and cloud credentials through something as simple as an image upload. Security researchers disclosed CVE-2026-66066, a CVSS 9.5 vulnerability in Ruby on Rails’ Active Storage component that lets an unauthenticated attacker read sensitive server files, including the Rails master key, database passwords, and cloud storage credentials, on applications that process image uploads through the libvips library. It is fixed in Active Storage versions 7.2.3.2, 8.0.5.1, and 8.1.3.1, alongside an update to libvips itself. If your development team runs a Rails application that accepts image uploads from users, whether that is product photos, profile pictures, or support attachments, this is worth confirming patched today rather than waiting for the fuller public disclosure planned for later this month. Read more at SecurityWeek


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox: