Business IT News Roundup: August 12, 2026
Good morning. The last day gave us a nasty WordPress supply chain attack aimed squarely at small business sites, two more signs that AI is moving from experiment to line item, and, right on cue, the actual August Patch Tuesday we flagged on Monday. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A WordPress supply chain attack is quietly minting rogue admin accounts on small business sites. Attackers poisoned a promotional data feed used by several popular BdThemes plugins, including widely installed Elementor add-ons like Element Pack and Prime Slider, and used it to create hidden administrator accounts and drop web shells on affected sites. They never touched the plugin code in the official WordPress repository, so nothing looked out of place, and WordPress has since pulled the plugins while it investigates. If your company website runs on WordPress, this is a good week to have someone check your installed plugins and your list of admin users for anything unfamiliar, because a fake admin account is exactly the kind of thing that sits unnoticed until it is used against you. A website is easy to treat as set-and-forget, and that is precisely why it gets targeted. Read more at BleepingComputer ...