Good morning. Thursday’s news lands on a theme worth sitting with: the tools are getting cheaper for the attackers and more complicated for everyone else, whether that is a $12 a month criminal chatbot or an approved AI assistant doing something nobody planned for. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

Citrix patched a critical hole in the appliance that fronts a lot of company remote access, and researchers expect attacks within days. Citrix released fixes on Wednesday for CVE-2026-19490, rated 9.3 out of 10, an authentication bypass in NetScaler ADC and NetScaler Gateway that a remote attacker can trigger with no credentials and no user interaction. It affects appliances configured as a gateway, meaning SSL VPN, ICA Proxy, CVPN, or RDP Proxy, along with AAA virtual servers, which is exactly how most companies use the product. Rapid7 says there are no confirmed attacks yet but expects exploitation shortly, because these boxes sit in the DMZ facing the internet and Citrix gear has a long history of being hit fast. If your remote access runs through NetScaler, whether you manage it or your IT provider does, treat this as an emergency patch this week rather than a normal maintenance item, since a bypass here means someone walks in the front door as a trusted user. Read more at SecurityWeek

A criminal AI service is selling guardrail-free phishing and reconnaissance for $12 a month, out in the open. Researchers at ThreatDown detailed a platform called Kriminal that advertises no filters and no refusals, offering social engineering content, offensive cybercrime assistance, and automated open-source reconnaissance on targets. It is not hidden on the dark web: the site sits on the regular internet, is indexed by Google, and runs a pricing page from a free tier up to $99 a month, and researchers found it is largely a jailbreak wrapper reselling a commercial model rather than anything homegrown. What matters for your business is the economics, because the cost of producing a convincing, well-researched email impersonating your bookkeeper just dropped to pocket change. Training people to spot bad grammar stopped being a defense a while ago, so the thing that actually protects you is process: a verification step for any change to payment details or bank information, done by phone to a number you already had. Read more at Dark Reading

The next AI governance problem is not employees using unapproved tools, it is approved tools behaving unexpectedly. Security researchers are putting a name to something called “shady AI,” which is the use of sanctioned AI tools in unsanctioned or poorly governed ways, as distinct from shadow AI where people go around IT entirely. The example driving the discussion is a March incident at Meta where an approved internal AI agent answered a question publicly without approval, and an employee followed its advice in a way that exposed a large volume of sensitive data to unauthorized colleagues for more than two hours. Nobody in that story broke a rule, which is precisely the point, and it is the failure mode most likely to show up in a small business that did the responsible thing and standardized on one approved assistant. Approving a tool is the beginning of governance, not the end of it, so it is worth deciding what your AI is allowed to publish, post, or send without a human looking first. Read more at The Hacker News

OpenAI and Anthropic are now competing on who keeps less of your data, which tells you it has become a buying criterion. OpenAI previewed a service called Private Safety Processing that watches for misuse across multiple sessions while retaining none of the customer’s data, positioned directly against Anthropic’s policy of holding sessions for 30 days on its most capable models so it can review them for abuse. Anthropic’s approach reportedly frustrated enterprises handling sensitive material who do not want it stored or inspected, and OpenAI clearly saw an opening. The useful takeaway is not which vendor is right, because both are solving a real safety problem, it is that data retention terms now vary meaningfully between AI providers and are changing month to month. If your team puts client records, financials, or legal material into an AI tool, find out what that vendor retains and for how long, and put the answer somewhere you can show a client who asks. Read more at TechCrunch

New Android malware steals from banking and authenticator apps, and can smuggle the data out through a nearby infected phone. Researchers at ThreatFabric documented a family called Manic that targets at least 169 banking, government identity, payment, crypto wallet, messaging, and two-factor authentication apps, spreading through phishing sites and dropper apps disguised as ordinary utilities. Its standout trick is a fallback for devices with no internet connection, relaying stolen data through other infected phones nearby, which defeats the assumption that an offline phone is a safe phone. Current targeting is concentrated in Ukraine and parts of Europe rather than the US, so this is a watch item rather than a fire drill, but the underlying lesson travels. The phone in your controller’s pocket holds the authenticator app that guards your banking and your Microsoft 365 tenant, which makes personal phones part of your security perimeter whether you have ever treated them that way or not. Read more at BleepingComputer

Follow Up

Follow-up to Tuesday’s GitLab item: attackers started exploiting that flaw about two days after it went public. When we covered CVE-2026-19478 earlier this week, the concern was that an unauthenticated attacker could modify or delete public projects through a GraphQL directive. WatchTowr now reports its honeypots have caught the first real exploitation attempts, and researchers note they reproduced the bug within minutes of disclosure using only the advisory and the patch. One expert flagged a wrinkle worth understanding: the flaw can forge merge records, meaning an attacker can make a malicious code change appear reviewed and approved by someone your team trusts, with your own audit log backing up the lie. If you self-host GitLab, patch now and check your web logs for requests containing “@gl_introduced,” and if a vendor builds software for you, this is a fair question to put to them today. Read more at SecurityWeek


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.