The last day brought a massive open source supply chain compromise, a widely used app server flaw that undid a previous fix, and two social engineering campaigns worth warning your team about. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A single compromised developer account poisoned open source packages downloaded more than 2 billion times a month. Attackers took over the GitHub account of the maintainer behind keyv, a caching library, and used that access to push a credential-stealing worm into keyv and several related packages the same maintainer owns, including some downloaded hundreds of millions of times a month. At least 434 packages across 1,381 versions were affected, each carrying a hidden install script that quietly harvested cloud credentials, GitHub tokens, and crypto wallets from any computer that installed them. You almost certainly do not install these packages directly, but your software vendors and any in-house developers likely depend on them indirectly. This is a good week to ask your development team or software vendors whether they have checked their dependencies against this incident. Read more at The Hacker News

A fix for a serious Apache Tomcat flaw quietly broke, and CISA confirms attackers are already exploiting the gap. CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog this week, a flaw where the patch for an earlier Tomcat bug can itself be bypassed, allowing sensitive data in cluster communications to travel unencrypted. It is fixed in Tomcat versions 11.0.21, 10.1.54, and 9.0.117. Apache Tomcat runs quietly underneath a huge number of business web applications, so if your business or your developers run any Java-based web app, this is worth confirming with whoever manages that infrastructure rather than assuming last year’s patch still holds. Read more at Acunetix

A popular AI tool for building automation workflows had a flaw that handed out full admin access to anyone who asked. CISA confirmed active exploitation of CVE-2026-9198, a critical flaw in IBM’s Langflow tool that let an unauthenticated attacker request an administrator token from one API endpoint and then use it to run arbitrary code through another, gaining full control of a default installation. It is fixed in version 1.10.1. If your business has started experimenting with Langflow or similar low-code AI agent builders, this is a reminder that these newer tools have not had the years of security hardening that traditional business software has, so patching promptly matters even more. Read more at The Hacker News

A fake Bank of America email is tricking people into installing remote access software disguised as a security tool. Researchers identified a phishing campaign that mimics Bank of America’s branding and directs victims to a fake “Security Centre,” which then delivers a disguised installer for the legitimate remote access tool ScreenConnect. The malware silently grants itself elevated privileges, renames itself to look like a Windows security service, and resists normal uninstallation. The campaign even shows Mac users a different, simpler credential-phishing page while reserving the full remote access attack for Windows users. This is a good one to flag to your team directly: if a banking security alert asks you to download and run a program, that is a red flag regardless of how official it looks. Read more at Infosecurity Magazine

A WhatsApp scam is spreading itself by hijacking accounts through a legitimate feature, no password required. Researchers detailed a campaign nicknamed GhostPairing, where messages asking recipients to vote for a friend in a contest actually come from already-compromised contacts, and clicking through walks the victim into approving a scammer’s device on their own WhatsApp account using the app’s normal device-linking feature. Once linked, the attacker can read messages, impersonate the account owner, and send urgent-sounding requests to the victim’s contacts, spreading itself further. If your business uses WhatsApp to talk with customers or staff, it is worth a heads-up to your team that a message from a real contact is not proof the request behind it is legitimate. Read more at Security Affairs


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox: