Good morning, and welcome to the Monday catch-up. It was a busy few days while a lot of us were offline, with a record-setting Patch Tuesday bearing down, ransomware crews sharpening their focus on professional services, and the big AI vendors all reshaping themselves at once. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

Brace for the biggest Patch Tuesday yet this Wednesday, August 12. Security researchers are heading into this week’s Microsoft Patch Tuesday warning about what one forecast bluntly calls a “patch apocalypse.” July set a record with well over 600 CVEs across nearly the entire Microsoft portfolio, and August is expected to land in the same range, including another embargoed SharePoint fix. The telling detail is that only three of July’s 600-plus were actually being exploited in the wild, which means the real skill is triage, not blanket panic. You do not have to patch everything at once, and trying to will burn out whoever handles your IT. What matters for your business is that someone is deciding which of these fixes touch your exposed, internet-facing systems and getting those done first. If you cannot answer who owns that call for your company, that is the gap to close this week. Read more at Help Net Security

Ransomware crews are zeroing in on law firms and professional services. Over the weekend the Qilin group added a string of new victims to its leak site, with a heavy tilt toward law firms and other professional services outfits. It is part of a clear pattern this year: firms that hold sensitive client data are prime targets because that data raises the stakes in a double-extortion demand. Qilin alone has claimed more than 1,400 victims over the past year, averaging well over a hundred a month. If your business holds other people’s confidential information, whether that is legal files, financial records, or client health data, you are exactly who these groups are hunting. The value they see is not your bank balance, it is the leverage that leaked client data gives them. Make sure your backups, access controls, and incident plan reflect that you are a target, not an afterthought. Read more at The Cyber Express

The big AI vendors all reshaped themselves in the same week. August 7 brought a cluster of moves that shift the ground under everyone. OpenAI made text chat unlimited for free users, Google reorganized its decade-old AI division for faster decisions, and Anthropic confirmed it is building its own chip team to get its runaway compute costs under control. Different problems, but the same signal: the economics of AI are being rewritten in real time. The practical headline is that capable AI keeps getting cheaper and, in some cases, free. That is good news if you have held off because of cost, but it also means your competitors have the same access you do. The advantage is no longer having the tool, it is knowing where in your business it actually saves time or wins customers. Pick one real workflow and prove it out before you buy anything bigger. Read more at Tech Startups

A critical flaw in a load balancer used by over 100,000 organizations is under active attack, and exploitation attempts started weeks before most people noticed. CISA added CVE-2026-8037, a CVSS 9.6 command injection flaw in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog on August 7, but researchers had already spotted exploitation attempts against it as far back as June 29. The flaw lets an unauthenticated attacker run arbitrary commands on the appliance through a crafted request, no login required. Progress fixed it in June with versions 7.2.63.2 and 7.2.54.18. If your business or your IT provider runs Kemp LoadMaster to balance traffic across your servers, this is worth confirming patched today rather than assuming a June fix means it already happened, since exploitation attempts predate most of the public warnings. Read more at BleepingComputer

Your IT provider is still figuring out how to price AI, and that affects your bill. A recurring theme in the channel press right now is that managed service providers are struggling to turn AI into a service they can price cleanly. Most bill a flat monthly fee, but their own AI costs do not work that way, and the old model of selling hours gets shaky when AI keeps shrinking how long the work takes. Vendors are stepping in with bundled platforms that increasingly shape what providers charge and where their margins come from. If you outsource your IT, expect the conversation about AI-related services and pricing to come up over the next year, because your provider is working through it whether they have raised it yet or not. When it does, push past the buzzwords and ask what specific outcome you are paying for and how you would measure it. A good partner should be able to tie any new AI line item to something concrete in your business, not just a trend. Read more at ChannelE2E


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.