It’s a quieter Tuesday on the surface, but a few stories are worth your attention if you run a small or midsize business. Ransomware crews are back to hammering the VPN appliances a lot of you rely on, another financial-data vendor got breached, and Microsoft’s August packaging changes quietly reshuffled what your 365 licenses include. Here are the five that matter most.
A ransomware group is actively breaking into SonicWall VPN appliances to take over the networks behind them. The INC ransomware operation has ramped up sharply since the start of August, and researchers now tie its recent run to active exploitation of SonicWall Secure Mobile Access 1000 series VPN appliances, tracked as CVE-2026-15409 and CVE-2026-15410. The attackers chain the flaws to gain root access on the appliance and then move laterally into the network it protects. Remote access boxes like these sit right at the edge of your network, which is exactly why attackers keep circling back to them, and this group is picking targets opportunistically without caring how big you are. If your business uses a SonicWall SMA appliance for remote access, treat this as a today problem: confirm it’s on current firmware and that admin access is locked down. Read more at The Hacker News
A financial-technology vendor breach exposed the data of nearly 800,000 people, and it may be your customers’ data. Marquis, a fintech firm that serves banks and credit unions, disclosed a breach affecting close to 800,000 individuals, including personal and financial information. It’s another reminder that your own security posture is only half the picture, because when a vendor holding your customers’ data gets hit, that breach becomes yours in the eyes of your customers and your regulators. This is a good week to ask your key vendors two plain questions: what data of ours do you hold, and how would you notify us if you were breached. Read more at Tech.co
Microsoft’s August 365 changes quietly added security features many businesses were paying extra for. As of August 1, Microsoft folded Defender for Office 365 Plan 1 into the base E3 plan and completed the rollout of several Intune management and security features. It’s part of the same July shift that raised list prices, but the practical upshot this month is that a lot of businesses now have email security and device management included that used to be paid add-ons. This one is a rare chance to save money instead of spend it: if you were buying Defender for Office 365 separately, check whether you’re now paying twice, and make sure the security features you’re newly entitled to are actually switched on rather than sitting idle. Read more at Microsoft
Another AI customer-service vendor is going public, this time through a $550 million SPAC deal. Yellow.ai, a conversational AI platform used for customer service, announced a definitive agreement to go public through a $550 million merger with Bluerock Acquisition Corp. The deal shows investor appetite for enterprise AI is still strong even as plenty of agent pilots stall, and it puts another well-funded player in the customer-service automation space businesses are actively shopping in. If you’re evaluating AI chat tools, a vendor going public cuts both ways: it can mean more stability, but SPAC-funded growth also brings pressure to raise prices and chase bigger accounts, so pick tools based on how well they fit your workflow today rather than the funding headline. Read more at AIwire
The IT services industry is gathering this week, and its agenda is a useful tell for where your provider’s attention is going. The Global Technology Industry Association is running ChannelCon 2026 in San Diego from August 3 through 5, with a program heavy on AI, cybersecurity, partner growth, and the workforce squeeze across IT services. It’s an inside-baseball event for providers, but those priorities are a decent read on where the companies serving your business are focused. If you outsource any part of your IT, use the same themes as a checklist for your next conversation: ask how they’re using AI to support you, how their own security has matured, and whether they have the staff depth to keep up as you grow. Their answers tell you whether they’re investing or coasting. Read more at The MSP Summit
Follow Up
Follow-up to Monday’s N-able N-central story: CISA has now added the N-central authentication-bypass flaw (CVE-2026-18577) to its Known Exploited Vulnerabilities catalog, confirming active exploitation, and N-able has shipped a complete fix in version 2026.3 HF1 after its earlier patch fell short. If your IT is managed through N-central, that’s the version to be on, and if a provider runs it for you, it’s fair to ask them directly whether their platform is fully patched. Read more at The Hacker News
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox: