Good morning. Monday started with Microsoft 365 falling over and never fully got back up, which set the tone for a day where the news was less about clever attacks and more about the plumbing everyone assumes will just work. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

A Microsoft 365 outage that started Monday morning is still not fully resolved, and search is the piece that will not come back. Microsoft began investigating Exchange Online problems at 11:55 a.m. UTC on August 31, traced the root cause to an issue inside a core authentication configuration shared by multiple Microsoft 365 services, and watched it spread into SharePoint, OneDrive, Teams and Copilot. Mail flow was largely restored by late Monday, but as of Tuesday morning the company was still restarting infrastructure to fix search across Exchange, SharePoint, OneDrive and Teams, with no estimated time for full resolution. What makes this one worth reading past the headline is the root cause, because a single shared authentication component took down five products that most companies think of as separate purchases. If your continuity plan assumes that a problem in email will not touch your files or your chat, this incident is the cheap version of finding out otherwise, and the question to bring to your next leadership meeting is what your team actually does for the first four hours when the whole suite is degraded rather than down. Read more at Computerworld

Microsoft is warning about a new attack that talks employees into pasting a command into Windows Terminal, and the payoff for the attacker is a tunnel into your network. The campaign, dubbed TerminalFix, is a twist on the familiar fake CAPTCHA trick: a compromised website shows what looks like a Cloudflare verification prompt, preloads a PowerShell command into the clipboard, and instructs the visitor to run it in Windows Terminal, which allows longer and more complex scripts than the usual version of this scam. From there it pulls down a signed executable paired with a malicious DLL, hides later stages inside the pixel data of PNG images, sets itself to run every hour, and quietly maps out domain controllers, databases, backup servers and mail systems before opening an encrypted reverse tunnel that lets the attacker reach anything the infected machine can reach. Microsoft did not observe hands-on activity yet, which is another way of saying the access is being built now and used later. The practical response is not a product purchase, it is a rule your staff can actually remember, which is that no legitimate website ever asks you to copy something into a terminal window to prove you are human. Read more at BleepingComputer

Software vendors are starting to bill for completed work instead of seats, and the contract you sign next year may look very different from the one you signed this year. Zendesk now charges per resolution and only counts an issue if AI handled it end to end, with no credit if a human picks up the last ten percent. Pegasystems charges a fixed fee per completed case and absorbs the underlying AI costs itself. HP is exploring per-seat contracts with guarantees attached around ticket reduction and hardware refresh savings. The catch, according to Gartner analyst Tom Coshow, is that only 19% of services buyers use outcome-based arrangements today and much of the movement is still buzz, with the useful test being whether the vendor is actually taking on risk or just relabeling the invoice. For a smaller company this matters more than it looks, because outcome pricing shifts the hard work to the front of the relationship: you have to define what a good outcome is and what happens when it is not delivered, in writing, before you sign. That is a better conversation than the one most businesses have about software, and it is worth having even with vendors who are not changing their pricing at all. Read more at CIO Dive

A state-linked espionage group has moved from hacking VMware environments to living inside Cisco routers and the servers that authenticate access to them. Sygnia published research Sunday on Fire Ant, the same actor that drew attention in 2025 for abusing VMware hypervisors, now compromising routers running Cisco IOS XR, TACACS authentication servers and the Linux management hosts used to run high-value networks. Sygnia’s director of incident response, Asaf Perlman, described the activity as most consistent with long-term espionage rather than a smash and grab. The reason this belongs on a small business list is the target selection, because network gear and the systems that manage it are the one category almost nobody monitors, patches on a schedule, or includes in a security review. Your firewall, your switches and your VPN appliance are computers running software written by people, and if the last time anyone looked at their firmware version was when they were installed, that is a gap worth closing this quarter rather than next. Read more at Cybersecurity Dive

Berlin’s government confirmed it is being extorted after a ransomware crew walked off with 1.44 million files, and it announced publicly that it will not pay. Governing Mayor Kai Wegner said the city will not meet the demands, which Der Spiegel reports at 30 bitcoin, roughly 2 million euros. The Rhysida gang’s leak site claims 5.79 terabytes covering contracts, HR files, payroll, more than 5,000 personnel files, plaintext credentials from internal systems including a payment processing database, and vulnerability assessments of the city’s water supply. The timeline is the uncomfortable part: the theft is believed to have happened between August 7 and 12, and affected departments were not disconnected from the state network until August 14. Whatever you think about paying, the decision is far easier to make when you already know what was taken and how long they were inside, and that clarity comes from detection and logging you have to buy before the incident, not after. If your business cannot currently answer how quickly you would notice someone quietly copying files out for five days, that is the gap this story is really about. Read more at Help Net Security

Follow Up

Follow-up to yesterday’s PaperCut story: attackers are now installing remote access software on compromised print servers, which changes what a cleanup has to look like. Huntress reports that post-exploitation activity has moved past reconnaissance into deploying SimpleHelp and AnyDesk for persistent access, and watchTowr said on August 31 that it is seeing hands-on-keyboard activity designed to pivot from the PaperCut server into the internal network, behavior it associates with initial access brokers. CISA has added both flaws to its Known Exploited Vulnerabilities catalog with a federal patching deadline of September 14. The practical shift is that patching is no longer enough on its own: if your PaperCut server was reachable from the internet in the past week, the advice from the researchers is to treat it as compromised, look for unexpected remote access tools, and rotate any credentials that server could see. Read more at Help Net Security


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


If you only do one thing today, check whether your PaperCut server picked up any remote access software over the weekend.

Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.