There is a thread running through today’s news about time, specifically how long a problem stays a problem once it is inside your systems. A manufacturer still not shipping a week later, a botnet that outlasted two decades of cleanup efforts, and a model built to shrink the gap between a flaw being announced and being exploited. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT.

SonicWall is warning that attackers are chaining two brand new zero-days in its SMA1000 remote access appliances to run commands on the box. The first, CVE-2026-83548, is a maximum-severity command injection flaw in the SMA1000 WorkPlace interface that starts as a server-side request forgery weakness. The second, CVE-2026-83549, is a command injection flaw in the Appliance Management Console, and chaining the two gives an attacker arbitrary operating system commands on the appliance. Models 6210, 7210 and 8200v are affected, and hotfixes 12.4.3-03526 and 12.5.0-02952 or later close the hole. What makes this worth stopping for is that it is the second round this year, since two different SMA1000 flaws were quietly exploited for weeks over the summer before anyone knew and later picked up by ransomware crews. Your remote access appliance is the front door to everything, it is exposed to the entire internet by design, and it is usually owned by nobody in particular once it is installed. If you have one of these, the useful question this morning is not whether it is patched but who is responsible for noticing the next time it needs to be. Read more at BleepingComputer

A week after a cyberattack knocked out its systems, Boston Scientific still cannot fully manufacture or ship its products. The medical device maker detected the intrusion on August 25 and disclosed it the next day, and the resulting network outage has stopped production, order processing and shipping across its global operations, with staff at its Cork, Ireland plant sent home because there was no work they could do. CrowdStrike and other outside specialists were brought in, the company says it has seen no malicious activity on its networks since August 25, and the damage appears limited to on-premises systems while cloud applications kept running. The company hoped to partially resume shipping some products this week but could not give a full restoration timeline, and no group has claimed responsibility. The detail worth carrying into your own business is that split between on-premises and cloud, because it decided which parts of the company kept working and which stopped cold. Most smaller businesses have a similar map without ever having drawn it, and the exercise of writing down what runs where, and what stops if the on-premises half goes dark for a week, costs nothing but an afternoon. Read more at SecurityWeek

OpenAI says its upcoming Astra model is the first to cross its own “Critical” cybersecurity threshold, and it is restricting who gets that capability. Under the company’s Preparedness Framework, Critical means a model can independently find previously unknown vulnerabilities in hardened real-world systems and build working exploits for them without a person guiding each step. During testing, Astra reportedly discovered and chained together two zero-days on its own. OpenAI is limiting access to the strongest cyber capabilities, adding monitoring across its development process, and moving safeguards earlier in the pipeline. Defenders get this technology too, and eventually the same capability will show up inside the security products you already buy, but the side that scales first is the side with no approval process. The practical consequence for a smaller business is that the window between a patch being announced and being exploited keeps getting shorter, which means a patching schedule measured in weeks is really a description of how long you are exposed. Read more at TechCrunch

The chair of the Financial Stability Board told G20 finance ministers this week that AI-driven cyber risk is now the most immediate threat to the global financial system. Andrew Bailey, who also runs the Bank of England, wrote ahead of the August 31 and September 1 meetings that frontier AI may materially alter the speed, scale and economics of cyber risk in a way that could undermine market confidence system-wide, and he singled out the concentration of highly connected third-party service providers as a specific worry. His guidance to financial institutions was to prepare for severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies, including the ability to rebuild critical systems and restore data from bare metal. Set aside the fact that this is aimed at banks, because the two ideas underneath it apply to a fifteen-person company just as well. Your business almost certainly depends on a handful of providers that thousands of other companies also depend on, as Monday’s Microsoft outage demonstrated at no charge, and the bare metal question is one you can answer today: if a machine had to be rebuilt from nothing, do you have what you need to do it, and has anyone ever tried. Read more at The Record

A botnet that has been running continuously since 2003 was finally dismantled, and the interesting part is what it was still living on. Sality, a peer-to-peer botnet with a 23 year run, was sinkholed in a joint operation between international law enforcement agencies, CrowdStrike and the Shadowserver Foundation, and it was still infecting more than 15,000 machines worldwide when the plug was pulled. Malware written before the iPhone existed does not survive that long on computers anyone is watching. It survives on the machine in the back room running the label printer, the laptop that belonged to someone who left in 2019, the old workstation kept alive because one piece of software will not run anywhere else. Every business has at least one of these, and the reason it matters is not nostalgia, it is that a device nobody manages is also a device nobody patches and nobody would notice being used against you. The takeaway is unglamorous but real: an accurate list of every machine that touches your network is the cheapest security control you will ever implement. Read more at Help Net Security


Sponsored by Lucky 13 Solutions

Business in Motion. Tech in Sync. Lucky 13 Solutions is a managed services provider helping small and midsize businesses keep their IT reliable, secure, and well-supported, without needing a full in-house team. Learn more at l13s.com.


If your business terminates remote access on a SonicWall SMA1000, that hotfix is worth doing before lunch.

Get the Business IT News Roundup in your inbox:


How this gets made: stories come from my own reading and from AI-assisted research and drafting, all reviewed and edited by me before anything goes out. The commentary is mine, sources are linked so you can read the original, and any errors are mine to own. If something looks wrong, reply and tell me.