Good morning, and happy Friday. It was a quieter news day but a security-heavy one, with a logistics hack rippling out to ordinary retailers, another maximum-severity flaw being exploited within hours, and a widely used VMware bug we flagged two weeks ago now under real attack. Here are the stories that matter most if you are running a small or midsize business, or leading its IT.
A cyberattack on a logistics provider became a shipping problem for its customers. A ransomware-style attack on Ceva Logistics knocked out order processing at several of its European warehouses, and the fallout landed on the companies that rely on it, with retailers like Bol, De Bijenkorf, and Ace & Tate unable to get goods shipped and some customer data exposed. Ceva’s own transportation systems kept running, but the warehouse outage was enough to stall deliveries for days. The lesson for any business is that your risk does not stop at your own network: when a vendor or logistics partner goes down, your orders, your customers, and your reputation are on the hook too. It is worth knowing which outside providers your operation truly depends on and what your fallback is if one of them goes dark for a week. Read more at The Record
Another perfect-10 flaw was being exploited within hours of going public. A maximum-severity vulnerability in SAP Commerce Cloud (CVE-2026-58231) lets an unauthenticated attacker bypass login and run code on the system, and researchers saw exploitation attempts begin within hours of the flaw being disclosed. SAP shipped a fix in its August security batch and offered a temporary way to lock down the vulnerable component while you patch. If your business runs on SAP Commerce, or a vendor that powers your storefront does, this is a same-day conversation, but the broader point applies to everyone: the window between a flaw going public and attackers using it is now measured in hours, not weeks. Knowing who watches for these alerts and how fast your critical systems can be patched is the real defense. Read more at The Hacker News
Microsoft’s latest Copilot update makes the case for the seats you already pay for. Microsoft rolled out a batch of August updates to Microsoft 365 Copilot, with the most useful gains landing in Excel and Word, where you can now apply AI directly inside your data, get formula help, and pull information from other documents into an analysis with a plain-language prompt. For a lot of small businesses, the Copilot licenses are already on the bill but barely used, so this is a good moment to have someone spend an hour seeing what the newer Excel features can actually do with your numbers. The value in AI right now is rarely a new tool, it is getting real use out of the one already sitting in your subscription. Pick a report you build by hand every month and see if Copilot can take the first pass. Read more at Geeky Gadgets
Ransomware is holding at an elevated ’new normal,’ and the weekend is when it lands. Industry trackers describe ransomware in 2026 as settling into a steady, elevated baseline rather than fading, with a stream of small and midsize victims across ordinary industries like law, staffing, and food distribution week after week. Attackers deliberately favor Friday and weekend timing, when IT coverage is thin and a problem can spread for two days before anyone notices. Heading into the weekend, it is worth a two-minute gut check: do you have backups you have actually tested restoring from, and does someone get alerted if systems start acting strange after hours. Those two things separate a bad Monday from a catastrophic one. Read more at Industrial Cyber
Follow Up
Follow-up to July 30th’s VMware warning: that vCenter flaw is now under active, worldwide attack. When we flagged the critical VMware vCenter vulnerabilities two weeks ago, the concern was that one of them (CVE-2026-59310) had no workaround and demanded prompt patching. That concern has now materialized: researchers are tracking a coordinated campaign hitting hundreds of exposed vCenter servers across dozens of countries, using the flaw to gain remote access and plant persistent backdoors. There is still no mitigation other than the patch, so if your business or your IT provider runs VMware and vCenter is reachable, confirming it is updated is a today item, not a someday item. Virtualization sits under everything else you run, which is exactly why attackers are racing for it. Read more at The Hacker News
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.