Good morning. The last day gave us a nasty WordPress supply chain attack aimed squarely at small business sites, two more signs that AI is moving from experiment to line item, and, right on cue, the actual August Patch Tuesday we flagged on Monday. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A WordPress supply chain attack is quietly minting rogue admin accounts on small business sites. Attackers poisoned a promotional data feed used by several popular BdThemes plugins, including widely installed Elementor add-ons like Element Pack and Prime Slider, and used it to create hidden administrator accounts and drop web shells on affected sites. They never touched the plugin code in the official WordPress repository, so nothing looked out of place, and WordPress has since pulled the plugins while it investigates. If your company website runs on WordPress, this is a good week to have someone check your installed plugins and your list of admin users for anything unfamiliar, because a fake admin account is exactly the kind of thing that sits unnoticed until it is used against you. A website is easy to treat as set-and-forget, and that is precisely why it gets targeted. Read more at BleepingComputer

OpenAI bought a startup so ChatGPT can build your slides. OpenAI has acquired NextSlide, a startup whose product turns notes, documents, and prompts into finished, editable presentations, and folded its team into ChatGPT. It is a small deal, but the direction is the story: the everyday business tasks that eat your team’s afternoons, like building a deck for a client or a board meeting, are becoming things you describe rather than things you assemble. If a chunk of your week goes into slide decks and proposals, it is worth testing what these tools can already do before you assume the output is not good enough, because the gap is closing fast. The win is not novelty, it is the hours you get back. Read more at TechCrunch

Ransomware crews are moving their operations onto the blockchain to survive takedowns. A newer group called DeadLock has started hiding its infrastructure using the Polygon blockchain and the decentralized Session messaging network, so there is no central server for law enforcement to seize and no easy way to knock its leak site or negotiation channels offline. The group has claimed more than 80 victims and leans on the usual double-extortion playbook of encrypting your systems and threatening to leak your data. The practical takeaway is not the technical wizardry, it is that the crews behind these attacks are getting harder to disrupt, which means waiting to be a target is a worse bet than it used to be. Tested backups you can actually restore from, and a plan for the day something gets encrypted, remain the cheapest insurance you can buy. Read more at BleepingComputer

A new tool from Rippling points at a bill you may not be watching: your AI spend. HR and payroll platform Rippling launched an AI Spend Console that tracks which AI tools employees are using, what they cost, and whether that spend is tied to any real productivity, after the company admitted its own AI token bill had jumped 80 percent without anyone tracking it. Whether or not you use Rippling, the reason it exists is worth sitting with: AI costs are quietly moving from a few pilot licenses into everyday work, often on individual employees’ cards, with no one adding it up. Before your AI spending sprawls the way SaaS subscriptions did, it is worth knowing what your company is actually paying for across all these tools and what you are getting back. Unmanaged, this is the next line item that balloons before anyone notices. Read more at ITBrief

Google’s new hardware is here, and the whole lineup got more expensive. At its Made by Google event, the company unveiled the Pixel 11 line, a new Pixel Watch, and a Tag tracker, with the AI features front and center, and a roughly $100 price increase across nearly every Pixel model plus $50 more on the watch. Phones are consumer gear, but the pricing signal is not: the big vendors are nudging hardware costs up across the board heading into refresh season. If you are budgeting to replace phones, laptops, or other devices for your team over the next year, build in some cushion rather than assuming last year’s prices hold, and weigh which of the new AI-on-device features your people would actually use before paying up for them. Read more at Android Central

Follow Up

Follow-up to Monday’s Patch Tuesday forecast: the actual release landed, and it is a big one. Microsoft’s August Patch Tuesday shipped more than 400 fixes, including three zero-days. The one already being exploited is a Windows WinSock flaw (CVE-2026-68820) that lets an attacker who is already on a machine grab full SYSTEM control, and the scariest of the rest is a wormable Windows DNS Server bug (CVE-2026-62878, CVSS 9.8) that could spread on its own across exposed servers. As we said Monday, the move is not to panic-patch all 400, it is to make sure whoever handles your IT is prioritizing the internet-facing and actively-exploited items first, which this month means the WinSock and DNS fixes near the top of the list. Read more at BleepingComputer


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.