Good afternoon. Tuesday’s news had an unusually clear theme, which is that the gap between what technology can now do and what an ordinary business can actually govern keeps getting wider. Attackers know exactly which companies sit in that gap, regulators have started writing checks against it, and the fixes on offer are mostly about who is watching, not what you buy. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.
Companies in the $10 million to $1 billion revenue range are now taking roughly three out of every four ransomware hits. Black Kite analyzed 13,336 publicly disclosed ransomware and data extortion incidents with known revenue across North America and Europe between January 2023 and June 2026 and found mid-sized companies accounted for 73% of them, a share that stayed between 72% and 75% for the entire period. More than half of those victims sat at the smaller end, between $10 million and $50 million in revenue, manufacturing was the hardest hit industry at more than a quarter of victims, and an assessment of over 120,000 mid-market organizations found 54.7% had at least one significant patch-management problem on a public-facing system while nearly a third showed credentials sitting in infostealer logs. If you have been quietly assuming your company is too small to be interesting and too small to be newsworthy, this is the report that says the opposite, because that revenue band is precisely where attackers have concentrated. The two questions worth asking this week are simple: what is exposed to the internet with our name on it, and would we know today if an employee’s credentials had already been stolen. Read more at Help Net Security
Your biggest AI risk is not the whole staff dabbling with ChatGPT, it is the handful of people who have already wired AI tools into how the work gets done. Akamai’s Enterprise AI Usage Risk Report 2026, published Monday, found the top 5% of enterprise AI users interact with models at 12 times the rate of the bottom half of the workforce, running conversations of 18 prompts or more while the average employee stops around five. The report also found that 47.11% of enterprise AI conversations happen through personal accounts rather than company-managed ones, that 14.4% run through corporate email addresses attached to personal freemium subscriptions where prompts may feed public model training, and that 17.7% of employees at midsize companies have at least one AI browser extension installed, with about 16% of those extensions carrying known vulnerabilities. That last number should land, because midsize companies had a higher extension rate than large ones, which likely reflects less central control rather than more enthusiasm. The practical move is not a policy memo, it is finding out which three or four people in your company have made AI part of their daily workflow and having a real conversation with them about what data is going where. Read more at The Hacker News
Microsoft is giving admins a switch to keep outside AI bots out of Teams meetings entirely, and it is off by default. The new meeting protection policy, announced in a Message Center update on Friday and rolling out in targeted release through the end of August with general availability expected in late September, automatically blocks identified external bots from joining rather than parking them in the lobby for organizer approval, which was the behavior added back in June. It lives under the “Manage bots” settings in the Teams admin center and can be scoped to specific users or groups. The obvious use case is the third-party note-taker somebody on the other side of the call invited without telling you, but the same door has been used by attackers impersonating IT and helpdesk staff, which Microsoft flagged as a surging pattern in April. If your team runs client calls, board meetings, or anything covered by a confidentiality agreement, this is worth a fifteen-minute conversation with whoever administers your Microsoft 365 tenant, and the honest first step is deciding which transcription bots you actually want in the room. Read more at BleepingComputer
AI can now produce a serious vulnerability report in hours, but fixing and shipping the patch still takes weeks, and that mismatch is the whole problem. Christopher Robinson, chief security architect at the Open Source Security Foundation, wrote Monday that discovery was never the bottleneck and that the flood of AI-generated findings is landing on maintainers and vendors who cannot absorb it, with multiple organizations independently scanning the same obscure library and filing separately without coordinating. He cites IBM’s Cost of a Data Breach Report 2026, which found one in four malicious breaches last year were AI-enabled, up 56% over the prior year, and that those breaches cost about $6 million on average, roughly a million more than the overall average. The number that says the most about where businesses actually are is that only 18% of organizations use AI agents for vulnerability management, while more than half already use them for threat detection. Translated to your business, it means the alerts will keep arriving faster than anyone can act on them, so the useful investment is not another scanner, it is a clear, written rule for how your team decides what gets fixed first. Read more at Dark Reading
A European regulator just fined Uber 825 million euros over automated decisions made about people without adequate human review. The Dutch Data Protection Authority imposed the penalty, reported Monday and worth close to a billion dollars, over Uber’s automated suspension of driver accounts, finding the practice violated the EU’s General Data Protection Regulation. Most American small businesses will never face a Dutch regulator, and the fine reflects Uber’s scale rather than anything a local company would see, but the principle underneath it is spreading and it is worth understanding now. As AI tools start showing up in hiring screens, credit and collections decisions, fraud flags, and employee monitoring, the recurring question from regulators is whether a real person reviewed a consequential decision and whether the affected person could contest it. If your company is putting automation anywhere near decisions about people, write down who reviews the output and how someone appeals it, because that record is the difference between a defensible process and an expensive one. Read more at SecurityWeek
Follow Up
Follow-up to Friday’s Zimbra story: CISA has now ordered federal agencies to patch the actively exploited Zimbra flaw within three days. The emergency timeline is far shorter than the usual federal remediation window, which is the government’s way of saying exploitation is happening at a pace that makes a normal patch cycle irrelevant. Zimbra is a mail and collaboration platform used by plenty of mid-sized organizations, schools, and service providers, so if you run it or a vendor runs it for you, the fix should be applied today rather than scheduled. Read more at BleepingComputer
Sponsored by Lucky 13 Solutions
Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.
Get the Business IT News Roundup in your inbox:
How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.