Business IT News Roundup: July 29, 2026

The last day brought an extortion threat against a Big Four accounting firm, a critical flaw in a widely used developer tool, and a genuinely strange story about OpenAI’s own AI models breaking out of a locked-down test environment, plus the industry’s fast response to it. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. Ernst & Young is facing an extortion deadline after a hacking group claims to have stolen client tax data. The ShinyHunters group claims it breached EY through a compromised third-party IT support platform used by staff on tax-related client work, allegedly gaining access to internal Jira, GitHub, and Azure environments, and it has set a July 31 deadline before publishing everything it took. EY has not confirmed the claim or said how many clients are affected. If your business works with EY or any large accounting or advisory firm on tax matters, this is worth a direct question to your relationship contact about whether your data was in scope, rather than waiting for a notification letter that may take months. Read more at BleepingComputer ...

July 29, 2026 · 4 min · 779 words · John Shelton

Business IT News Roundup: July 28, 2026

The last day brought a maximum-severity flaw under active attack in widely used SD-WAN gear, a chained WordPress exploit that can hand an attacker admin access on a default install, a dental benefits breach touching more than 23 million people, and a quarter-trillion-dollar sign of how shaky the financing behind AI’s buildout really is. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

July 28, 2026 · 4 min · 772 words · John Shelton

Business IT News Roundup: July 27, 2026

It was another loaded weekend in business IT: two separate ransomware campaigns actively exploiting unpatched software you might be running right now, and two AI model launches that are quietly pushing prices down across the board. Here are the four stories that matter most if you are running a small or midsize business, or leading its IT. A ransomware gang is raiding exposed product design servers, and the patch has been available for weeks. Cl0p ransomware affiliates are exploiting a critical, unauthenticated flaw in PTC’s Windchill and FlexPLM software, tools widely used by manufacturers, automakers, aerospace firms, and retailers to manage product design data, stealing engineering files from servers that were never updated after the bug was disclosed and patched back in June. The group is now sending mass extortion emails to hundreds of employees at each affected company rather than negotiating quietly through a single contact. If your business runs Windchill, FlexPLM, or anything similar, this is worth a direct question to whoever manages it: is the June patch actually installed, not just scheduled. Read more at BleepingComputer ...

July 27, 2026 · 4 min · 671 words · John Shelton

Business IT News Roundup: July 24, 2026

The last day brought fresh data on just how hard ransomware gangs are leaning on small and midsize businesses, a cautionary tale out of one of the country’s largest healthcare companies, and a couple of moves that will shape how AI actually shows up in your tech stack this fall. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

July 24, 2026 · 5 min · 938 words · John Shelton

Business IT News Roundup: July 23, 2026

The last day brought a fresh SharePoint escalation worth acting on immediately, a wave of enterprise AI product launches from OpenAI, Microsoft, and Google, and new data on the gap between using AI and actually profiting from it. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A fourth SharePoint flaw is under active attack, and this one steals the keys needed to forge trusted logins. Researchers confirmed active exploitation of CVE-2026-50522, a critical SharePoint Server flaw that lets attackers steal “machine keys,” the credentials SharePoint uses to sign valid authentication tokens, after a public proof-of-concept exploit appeared on July 20. Microsoft patched the underlying bug on July 14, but stolen keys remain useful to an attacker even after patching, so security researchers are urging affected organizations to rotate those keys, not just install the update. If your business or your IT provider runs on-premises SharePoint Server, patching alone will not close this door. It is worth explicitly asking whether machine keys have been rotated, not just whether the patch was applied. Read more at BleepingComputer ...

July 23, 2026 · 5 min · 930 words · John Shelton

Business IT News Roundup: July 22, 2026

This week’s theme is autonomous AI agents cutting both ways: one broke into a major AI platform, one is running ransomware campaigns against AI infrastructure specifically, and one got so good at finishing its assigned tasks that it kept escaping the sandbox built to contain it. There is also a government database wiped after a failed extortion attempt, and a Washington deal that could change how soon you get access to the next frontier AI model. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. ...

July 22, 2026 · 4 min · 787 words · John Shelton

Business IT News Roundup: July 21, 2026

It has been a mixed 24 hours in business IT: a vendor breach touching thousands of hospitals, a notable identity security acquisition in the MSP channel, fresh data on small business AI adoption, and a Microsoft price hike finally landing on invoices. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A billing software breach at a vendor serving thousands of hospitals is a reminder that vendor risk is your risk. Edinburgh based Craneware, whose billing and pharmacy software is used by more than 2,000 U.S. hospitals and nearly 10,000 clinics and retail pharmacies, disclosed that hackers stole a portion of its employee, customer, and partner data before being expelled from its systems. The company says much of what was taken is non sensitive or already public information, and it has notified the FBI and UK’s Information Commissioner’s Office while its investigation continues. When you hand core operations like billing to a specialized vendor, your risk exposure follows their security posture, not just your own, so it is worth asking any vendor holding sensitive data for your business what breach notification commitments they have actually made to you, before you need the answer. Read more at TechCrunch ...

July 21, 2026 · 5 min · 907 words · John Shelton

Business IT News Roundup: July 20, 2026

It was another loaded weekend in business IT: a new software supply chain attack, a fresh ransomware claim with a data leak threat attached, a European AI acquisition, and new data on just how many SMBs are still stuck in AI pilot mode. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. A new software supply chain attack shows old, abandoned developer accounts are a real risk. Researchers uncovered “SleeperGem,” an attack where two RubyGems maintainer accounts that had sat quiet for six or seven years were hijacked and used to slip malware into three packages, one of them impersonating Microsoft’s own Git Credential Manager and carrying over 500,000 downloads. The malicious code checks for CI/CD environment variables to avoid detection inside automated build pipelines before installing itself as a persistent background service. You do not need to write Ruby code for this to matter. If any vendor or contractor you rely on builds software using open source packages, and nearly all of them do, this is a reminder that “our vendor was never breached” is not the same as “our vendor’s dependencies were never breached.” It is a fair question to ask a software vendor how they monitor the packages their product depends on. Read more at The Hacker News ...

July 20, 2026 · 5 min · 939 words · John Shelton

Business IT News Roundup: July 17, 2026

It has been a heavy security week, and it is closing out with a record Patch Tuesday, an escalated warning on SharePoint, and a ransomware attack that shut down a household name’s production line. There is also a big AI model launch expected today. Here are the five stories that matter most if you are running a small or midsize business, or leading its IT. Rewst bets its platform’s future on AI agents and MCP, not more workflow templates. Rewst rebuilt its automation platform this month around an AI Agent tool that turns a plain-language description of a process into a working automation, plus a Model Context Protocol server that lets outside AI agents discover and run Rewst automations directly. The company frames the rebuild around a real skills gap: an estimated 80,000 MSPs worldwide and only about 1,000 people with the skills to build this kind of automation for them. The new version is in broader partner testing now, with general availability expected later this year. If your IT is outsourced, this is a good window into where the automation is headed on your provider’s end: more of your day-to-day support handled by AI agents they build and review, not just a technician clicking through a checklist. It is worth asking your provider directly how they validate what those agents do before it touches your environment. Read more at ChannelE2E ...

July 17, 2026 · 4 min · 817 words · John Shelton

Business IT News Roundup: July 16, 2026

It has been a busy stretch out there, from a paused federal compliance deadline that will still keep MSPs busy to a fresh warning from Microsoft’s CEO about what businesses are really paying for AI. Here are the five stories from the last day or so that matter most if you are running or advising a small or midsize business. CMMC Phase 2 is paused, but the security work is not. The Department of War has suspended the second phase of the Cybersecurity Maturity Model Certification program, putting third-party certification requirements on hold while it runs a 60-day review to look for ways to cut costs and simplify the process. Defense contractors still have to meet the underlying NIST SP 800-171 controls and support their SPRS scores through self-assessment, and MSPs who manage firewalls, identity, backups, or cloud environments for those clients are still on the hook to provide supporting evidence. If you serve anyone in the defense industrial base, this is a good moment to reframe CMMC conversations around ongoing risk reduction and contractual obligation rather than a looming audit date, because that framing just got a lot more durable than the deadline did. Read more at MSSP Alert ...

July 16, 2026 · 4 min · 738 words · John Shelton