Business IT News Roundup: August 26, 2026

Good afternoon. Tuesday’s news kept coming back to the same quiet problem, which is how often the thing that puts a business at risk is something nobody was told about. A plugin gets patched without an announcement, a vendor bug sits in the wild for months, an AI tool ships with a setting that made sense to an engineer and not to anyone else. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

August 26, 2026 · 6 min · 1209 words · John Shelton

Business IT News Roundup: August 25, 2026

Good afternoon. Tuesday’s news had an unusually clear theme, which is that the gap between what technology can now do and what an ordinary business can actually govern keeps getting wider. Attackers know exactly which companies sit in that gap, regulators have started writing checks against it, and the fixes on offer are mostly about who is watching, not what you buy. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

August 25, 2026 · 6 min · 1262 words · John Shelton

Business IT News Roundup: August 24, 2026

Good morning. The weekend’s news kept circling back to the same uncomfortable idea, which is that the security controls we have been told to trust are only as good as everything wrapped around them. Passkeys, cloud keys, AI assistants, and search results all showed up with the same problem, and none of the fixes are technical heroics. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

August 24, 2026 · 6 min · 1139 words · John Shelton

Business IT News Roundup: August 21, 2026

Good morning. Friday brings a run of stories about trust in the plumbing you never think about: the identity service that signs you in, the search result that hands you an installer, the open source package buried three layers under software somebody built for you. None of it is glamorous, and all of it is load bearing. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

August 21, 2026 · 6 min · 1117 words · John Shelton

Business IT News Roundup: August 20, 2026

Good morning. Thursday’s news lands on a theme worth sitting with: the tools are getting cheaper for the attackers and more complicated for everyone else, whether that is a $12 a month criminal chatbot or an approved AI assistant doing something nobody planned for. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. Citrix patched a critical hole in the appliance that fronts a lot of company remote access, and researchers expect attacks within days. Citrix released fixes on Wednesday for CVE-2026-19490, rated 9.3 out of 10, an authentication bypass in NetScaler ADC and NetScaler Gateway that a remote attacker can trigger with no credentials and no user interaction. It affects appliances configured as a gateway, meaning SSL VPN, ICA Proxy, CVPN, or RDP Proxy, along with AAA virtual servers, which is exactly how most companies use the product. Rapid7 says there are no confirmed attacks yet but expects exploitation shortly, because these boxes sit in the DMZ facing the internet and Citrix gear has a long history of being hit fast. If your remote access runs through NetScaler, whether you manage it or your IT provider does, treat this as an emergency patch this week rather than a normal maintenance item, since a bypass here means someone walks in the front door as a trusted user. Read more at SecurityWeek ...

August 20, 2026 · 6 min · 1157 words · John Shelton

Business IT News Roundup: August 19, 2026

Good morning. Wednesday’s news is mostly about trust misplaced in convenient places: a stranger offering to rescue you mid-breach, an AI assistant that will happily read your inbox for someone else, and a router feature you never asked for. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A ransomware crew has started emailing victims pretending to be the rescue team. GuidePoint’s research group documented a threat actor calling itself Ransom Busters that contacts companies during an active ransomware incident, claims to have broken into the ransomware group’s own servers, and offers to return the files and destroy the criminals’ copies for somewhere between $20,000 and $60,000. The tell is the timing, because these emails arrive before the attack is public knowledge, and legitimate incident response firms only come knocking after a breach is disclosed. Researchers assess with moderate confidence that this is not a good samaritan at all but a single affiliate working across several ransomware operations, trying to divert your ransom conversation away from the crew that actually attacked you. The practical takeaway is that your inbox becomes its own attack surface during an incident, so decide now who is authorized to speak with outside parties and make it a standing rule that nobody negotiates with someone who emailed you first. Read more at Dark Reading ...

August 19, 2026 · 6 min · 1172 words · John Shelton

Business IT News Roundup: August 18, 2026

Good morning. Tuesday brings a critical hole in a WordPress plugin sitting on hundreds of thousands of small business websites, the largest wave of Apple spyware warnings anyone has tracked, and a reminder that the AI tool you standardized on last year may not be around next month. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A WordPress forms plugin running on more than 600,000 sites can hand an attacker complete control. Researchers disclosed a critical flaw in Forminator Forms, tracked as CVE-2026-15748 and rated 9.8 out of 10, that lets an unauthenticated attacker upload executable files and take over a vulnerable site outright. Exploitation requires a form that combines a file upload field with a select field, which describes a lot of ordinary job applications, quote requests, and support intake forms. The fix shipped on July 31 in version 1.56.2, so the real question is whether anyone has logged into your site’s admin panel since then. It is easy to treat the company website as marketing rather than infrastructure, but a compromised site becomes a malware host wearing your domain name, and your customers are the ones who pay for that. Read more at The Hacker News ...

August 18, 2026 · 6 min · 1092 words · John Shelton

Business IT News Roundup: August 17, 2026

Good morning, and welcome to the Monday catch-up. Over the weekend a Mac remote-access flaw got a lot more dangerous, Stripe made a $7 billion bet on the plumbing behind AI, and Microsoft set a date for the end of passwords in its business identity platform. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A Mac remote-access flaw is being used to hijack machines, and its severity just got bumped to critical. Attackers are actively exploiting a flaw in macOS Screen Sharing, the built-in remote desktop feature, to get root-level control of internet-exposed Macs and quietly install cryptocurrency miners, and CISA raised its severity rating to a near-maximum 9.8 after the attacks emerged. The catch is that the usual hardening steps, like removing approved users or changing the VNC password, do not help, because the system treats the connection as already trusted. Apple shipped a patch on August 6, so the fix is to make sure every Mac in your business is updated to the current version and that Screen Sharing is not open to the internet. It is easy to forget Macs in a mixed office get security updates too, and this is a clean example of why that matters. Read more at BleepingComputer ...

August 17, 2026 · 5 min · 921 words · John Shelton

Business IT News Roundup: August 14, 2026

Good morning, and happy Friday. It was a quieter news day but a security-heavy one, with a logistics hack rippling out to ordinary retailers, another maximum-severity flaw being exploited within hours, and a widely used VMware bug we flagged two weeks ago now under real attack. Here are the stories that matter most if you are running a small or midsize business, or leading its IT. A cyberattack on a logistics provider became a shipping problem for its customers. A ransomware-style attack on Ceva Logistics knocked out order processing at several of its European warehouses, and the fallout landed on the companies that rely on it, with retailers like Bol, De Bijenkorf, and Ace & Tate unable to get goods shipped and some customer data exposed. Ceva’s own transportation systems kept running, but the warehouse outage was enough to stall deliveries for days. The lesson for any business is that your risk does not stop at your own network: when a vendor or logistics partner goes down, your orders, your customers, and your reputation are on the hook too. It is worth knowing which outside providers your operation truly depends on and what your fallback is if one of them goes dark for a week. Read more at The Record ...

August 14, 2026 · 5 min · 857 words · John Shelton

Business IT News Roundup: August 13, 2026

Good morning. Today brings what is being called the largest AI supply chain breach of the year, a batch of maximum-severity Adobe flaws worth patching fast, and fresh data on whether AI is actually paying off for businesses your size. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A breach in a popular AI tool leaked the cloud keys of thousands of companies. Researchers published a 153GB trove of credentials stolen through a supply chain attack on LiteLLM, a widely used open-source tool that sits between companies and the AI models they call, with data tied to more than 2,400 corporate domains including big names like Cisco, Samsung, and Nvidia. The stolen material was not just passwords but the deeper stuff: cloud access keys, code repository tokens, and the secrets that run automated build systems, all harvested after attackers slipped malicious code into a software update back in March. The uncomfortable lesson for any business is that the AI tools your team or your vendors bolt on can quietly become the crack that exposes everything behind them, so it is worth asking what AI software touches your systems and what credentials it can see. New tools deserve the same scrutiny you would give any vendor with a key to the building. Read more at Help Net Security ...

August 13, 2026 · 5 min · 936 words · John Shelton