Good morning. Friday brings a run of stories about trust in the plumbing you never think about: the identity service that signs you in, the search result that hands you an installer, the open source package buried three layers under software somebody built for you. None of it is glamorous, and all of it is load bearing. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
Microsoft confirmed a perfect-score flaw in Entra ID was exploited before anyone outside the company knew about it. CVE-2026-69836 carries a CVSS score of 10.0 and comes from Entra ID mishandling untrusted serialized data, letting an unauthenticated attacker execute code remotely with no credentials and no user interaction. Because Entra ID is a cloud service, Microsoft says it fixed the problem on its side before publishing, so there is no patch for you to install and no customer action required. The reason to care anyway is that Entra ID is the front door to Microsoft 365, Azure, and every third-party app you have wired into single sign-on, which means a successful attack there is not a server problem, it is an everything problem. This is a good week to look at who holds Global Administrator in your tenant, confirm those accounts are protected by phishing-resistant MFA, and ask whoever manages your tenant whether sign-in logs are actually being reviewed by a human rather than just retained. Read more at The Hacker News
Someone tricked an employee into installing a fake Google Gemini app, and it quietly emptied the browser. Darktrace investigated an incident at a company in Europe where a user searched for a Gemini download for Windows, and the top result pointed to a file hosted on Google Colab, a legitimate Google platform, which then redirected to a site posing as a “Windows Software Hub” serving an executable named Download_Google_Gemini_For_Windows.exe. The bundle even included a README telling the user to run it as administrator and add it to their antivirus exclusions, and the payload turned out to be a Vidar infostealer variant that harvests saved passwords, session cookies, autofill data, and crypto wallet files. The reason this one is worth passing along to your team is that the victim did nothing reckless by their own standards, they searched for a real product from a real company and clicked the first result on a real Google domain. Employees are downloading AI tools right now whether or not you have a policy about it, so the practical move is to name the two or three AI tools your business actually sanctions, tell people where to get them, and make it clear that any instruction to disable antivirus is the end of the conversation. Read more at Help Net Security
Attackers hijacked a tiny open source package with 245 million downloads and used it to run malware on developers’ machines during compilation. Early Thursday morning, someone published a poisoned version of the Rust crate arrayref through a compromised maintainer account, pulled the previous versions to force upgrades, and slipped in a dependency on a lookalike package that executed a payload at build time rather than at runtime. Two more packages were poisoned inside a 23-minute window, and Wiz researchers say the infrastructure overlaps with recent North Korean supply chain campaigns. If your business runs custom software, whether it is an internal tool, a customer portal, or a product a contract developer maintains for you, this is the pattern that keeps recurring across npm, RubyGems, PyPI, and now Rust. You do not need to understand the code to ask the right question, which is simply: when a dependency your software relies on gets compromised, how would we find out, and how fast could you ship a clean build. Read more at BleepingComputer
Federal agencies say attackers are now using AI to write custom exploitation tools for industrial controllers, and disguising them as legitimate monitoring software. The NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory on Wednesday about an ongoing campaign against Siemens S7 series programmable logic controllers in US critical infrastructure, with attacks reported in at least 12 states and a surge in incidents in late July. What makes it notable is the method: the crews are pairing open source industrial automation libraries with AI-assisted scripting to produce tools that look and behave like ordinary operational technology monitoring software, which is exactly the kind of thing security teams are trained to leave alone. Manufacturing, food and agriculture, water, chemical, and commercial facilities are the named targets, so if you run a plant, a warehouse, a cold storage operation, or a building with networked controls, this is your sector. The broader shift worth absorbing even if you have no PLCs at all is that AI has lowered the cost of building bespoke, convincing-looking tooling, which means “it looks like something our vendor installed” is no longer evidence that it is. Read more at Cybersecurity Dive
A critical Zimbra mail server flaw is now under active attack, a month after the patch shipped. CVE-2026-73570 is an OS command injection bug in Zimbra’s SNMP monitoring path that lets an unauthenticated attacker run commands as the zimbra user by sending a specially crafted SMTP request, and CERT Polska has confirmed exploitation in the wild. Zimbra fixed it in version 10.1.20 back on July 20, which is the part that should sting, because the patch has been available for a month and attackers are still finding servers to hit. Most small businesses run Microsoft 365 or Google Workspace and can skip this one, but plenty of professional firms, schools, and municipalities still run Zimbra on their own hardware, and if that is you the guidance is to patch immediately and then go looking for files created by the zimbra account over the last 30 days. The larger point applies to everyone: a patch that exists is not a patch that is installed, and the gap between those two things is where most breaches actually live. Read more at SecurityWeek
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.