Good morning. Today brings what is being called the largest AI supply chain breach of the year, a batch of maximum-severity Adobe flaws worth patching fast, and fresh data on whether AI is actually paying off for businesses your size. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A breach in a popular AI tool leaked the cloud keys of thousands of companies. Researchers published a 153GB trove of credentials stolen through a supply chain attack on LiteLLM, a widely used open-source tool that sits between companies and the AI models they call, with data tied to more than 2,400 corporate domains including big names like Cisco, Samsung, and Nvidia. The stolen material was not just passwords but the deeper stuff: cloud access keys, code repository tokens, and the secrets that run automated build systems, all harvested after attackers slipped malicious code into a software update back in March. The uncomfortable lesson for any business is that the AI tools your team or your vendors bolt on can quietly become the crack that exposes everything behind them, so it is worth asking what AI software touches your systems and what credentials it can see. New tools deserve the same scrutiny you would give any vendor with a key to the building. Read more at Help Net Security

Fresh data says AI is paying off for small businesses, not just big ones. Intuit’s new 2026 AI Impact Report, built on more than 34,000 survey responses and data from over 5 million QuickBooks businesses, found that 77 percent of US small and midsize businesses now use AI regularly, up from 48 percent just eighteen months ago, and that 78 percent say it has made them more productive. Notably, roughly 8 in 10 businesses that paid for AI in 2024 were still paying for it in 2025, which suggests the value is real enough to keep, not just try. If you have been waiting for proof before committing, this is about as close as it gets, but the report also names the real barriers, which are not cost so much as data privacy worries and simply not knowing what AI can do. The move is to pick one clear use, learn it well, and let a small win build your confidence. Read more at QuickBooks

Adobe shipped fixes for three perfect-10 flaws, and internet-facing servers should patch now. Adobe released emergency-grade updates for three separate maximum-severity vulnerabilities in ColdFusion and Campaign Classic, including one (CVE-2026-48362) that lets an unauthenticated attacker run commands on a vulnerable ColdFusion server with no login and no user interaction. On any server exposed to the internet, that is a straight path to full takeover, which is why Adobe is urging customers to patch within 72 hours rather than waiting for the usual maintenance window. If your business runs ColdFusion anywhere, especially anything reachable from outside your network, this is the item to hand your IT team or provider today. Even if you are not sure you run it, that question is worth asking out loud, because forgotten servers are exactly what these attacks find. Read more at The Hacker News

Airtable is being acquired, a reminder that the tools you build on can change hands. Bending Spoons, the company known for buying up well-known apps like Evernote and WeTransfer, has agreed to acquire the workflow and database platform Airtable in a deal valued at roughly $1.3 billion. Airtable is a backbone tool for a lot of small teams that use it to run projects, track inventory, or stand in for a custom app, and new ownership often brings changes to pricing, plans, and features over time. If your business runs on Airtable or a similar platform, this is not a reason to panic, but it is a reason to know how hard it would be to get your data out and move if the terms shifted. Owning an export of your critical data, and knowing your alternatives, is cheap insurance against a tool you depend on changing the deal. Read more at SiliconANGLE

One phished employee handed attackers a company’s entire mailbox. Aerospace parts supplier IEH Corporation disclosed that a criminal got into its Microsoft 365 email after a single staffer fell for a phishing message, one that impersonated a business contact and used a convincing fake Microsoft file-sharing link to harvest the employee’s login. The intruder reached email, attachments, customer communications, purchase orders, and sensitive technical documents before being caught. The point is not that this was a sophisticated attack, it is that it was an ordinary one, the kind that lands in your team’s inbox every week, and it worked. A short, plain reminder to your people that a Microsoft or DocuSign link asking them to log in again is the classic trap, plus turning on the sign-in alerts your email platform already offers, closes a lot of this door. Read more at The Register


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.