Good morning, and welcome to the Monday catch-up. Over the weekend a Mac remote-access flaw got a lot more dangerous, Stripe made a $7 billion bet on the plumbing behind AI, and Microsoft set a date for the end of passwords in its business identity platform. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A Mac remote-access flaw is being used to hijack machines, and its severity just got bumped to critical. Attackers are actively exploiting a flaw in macOS Screen Sharing, the built-in remote desktop feature, to get root-level control of internet-exposed Macs and quietly install cryptocurrency miners, and CISA raised its severity rating to a near-maximum 9.8 after the attacks emerged. The catch is that the usual hardening steps, like removing approved users or changing the VNC password, do not help, because the system treats the connection as already trusted. Apple shipped a patch on August 6, so the fix is to make sure every Mac in your business is updated to the current version and that Screen Sharing is not open to the internet. It is easy to forget Macs in a mixed office get security updates too, and this is a clean example of why that matters. Read more at BleepingComputer

Stripe is buying the company that quietly routes a lot of the world’s AI traffic. Payments giant Stripe agreed to acquire OpenRouter, a service that lets businesses reach more than 400 different AI models through a single connection, for over $7 billion, more than five times its valuation from just three months ago. OpenRouter has been called the “Stripe for AI” because it spares companies from wiring up each AI provider separately and helps them avoid getting locked into one. The takeaway for a business owner is less about this specific deal and more about the trend: the boring infrastructure that sits under AI is consolidating into a few big hands fast, which is convenient but worth watching, since the companies that control the plumbing eventually shape the pricing. For now it is a reason to keep your own AI setup flexible rather than welded to a single vendor. Read more at TechCrunch

Microsoft is making passkeys the default for business sign-ins, starting in two weeks. Beginning September 1, Microsoft will start rolling out passkeys as the default sign-in method across Entra ID, its identity platform behind Microsoft 365, and it plans to retire its own text-message and voice-call authentication entirely by early 2027. Passkeys replace passwords with a cryptographic key tied to your device, which removes the thing attackers phish for in most of the breaches we have covered this month. If your company uses Microsoft 365, this change is coming to your users whether you plan for it or not, so the smart move is to get ahead of it: decide how your team will register passkeys and brief them before the prompts start appearing. Handled well, this is one of the few security changes that makes life easier and safer at the same time. Read more at BleepingComputer

High-severity flaws in common TP-Link networking gear can hand attackers the keys to your network. TP-Link disclosed a batch of serious vulnerabilities in a range of its routers, mesh systems, and modems, including an authentication bypass and hardcoded encryption keys baked into the firmware, that could let someone on the network slip past login, gain admin control, and read sensitive data. Networking gear is the definition of set-it-and-forget-it, which is exactly why these flaws are dangerous: the box in the closet rarely gets a second look after the day it was installed. If your business runs TP-Link equipment, it is worth checking for a firmware update and confirming the admin interface is not reachable from the open internet. Your router is the front door to everything else, and a compromised one undermines every other protection you have. Read more at SecurityWeek

AI agents are starting to run whole workflows from inside the chat apps you already use. A new tool called Kinetik, from a company spun out of software maker JetBrains, launched an agent that runs content and influencer marketing directly inside Slack and WhatsApp, handling the busywork of finding and vetting creators, drafting outreach, and reporting on results. Whether or not marketing is your use case, it is a preview of where this is heading: instead of logging into yet another dashboard, you hand a task to an agent in the messaging tool your team already lives in. The opportunity for a small business is real, but so is the caution, because an agent acting on your behalf needs clear guardrails and a human checking its work before anything goes out the door. Start it on a low-stakes task and watch closely before you let it loose on anything that touches customers. Read more at Solutions Review


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.