Live briefing · Updated Aug 13, 2026

Security Briefing: What's Attacking, What's Expiring

The threats and deadlines that actually affect a small or midsize business — in plain English, with what to do about each. Government advisories straight from CISA (the U.S. government's cyber-defense agency), the attack stories that matter, and the IT deadlines heading for your calendar. No fear-mongering, no email gate.

The IT Deadline Tracker

Dates when something your business relies on stops working, changes behavior, or becomes an obligation. Every date is verified against the primary source linked on the card — not against someone's blog post.

Sep 1, 2026 in 19 days

Microsoft 365: passkeys become the default sign-in

What happens: Users still enabled for text-message or voice codes are automatically enrolled for passkeys and start seeing registration prompts at sign-in. The prompts can be snoozed — for now.

Who it affects: Every business running Microsoft 365 where anyone still signs in with a texted code.

Do this: Inventory who still uses SMS or voice codes, choose each group's passkey method (Authenticator app, Windows Hello, or a hardware key), and tell your team before the prompts surprise them.

Source: Microsoft Learn · our migration guide →

Sep 11, 2026 in 29 days

CMMC: Phase 2 suspended — program review outcome expected

What happens: On July 13, 2026 the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones, ordering a 60-day program review. The November 10, 2026 third-party (C3PAO) assessment phase-in is off the calendar, and contracting officers are directed to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification before the next option period — Level 1 (Self) and Level 2 (Self) designations remain, and no waivers are granted during the review. What did NOT change: DFARS 252.204-7012 still requires NIST SP 800-171; DFARS 252.204-7019 and -7020 still require a current SPRS score and annual affirmation; Phase 1 self-assessments stay in force; and government-led DIBCAC assessments continue.

Who it affects: Defense suppliers, machine shops, and subcontractors handling federal contract information or CUI — at any tier.

Do this: Do not stand down. Keep your NIST 800-171 self-assessment and SPRS score current. An affirmation is a legal statement, and the Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over misrepresented cybersecurity compliance whether or not a certification deadline is pending. Watch for the review outcome around mid-September.

Source: Department of War — CMMC Phase II suspension memorandum · our full guide →

Oct 13, 2026 in 61 days

Windows 10: consumer Extended Security Updates end

What happens: The one-year consumer ESU bridge ends — enrolled Windows 10 PCs stop receiving security patches after this date. Business ESU continues only as an annually purchased subscription (available through October 2028).

Who it affects: Any office still running Windows 10 PCs — especially machines that used the free consumer ESU enrollment as a stopgap.

Do this: Replace or upgrade remaining Windows 10 machines to Windows 11, or budget the business ESU subscription for machines that genuinely cannot move yet. An unpatched PC on your network is everyone's problem.

Source: Microsoft

Feb 1, 2027 in 172 days

Microsoft 365: text-message and voice sign-in codes retired

What happens: Microsoft-provided SMS and voice delivery is fully retired from the sign-in system behind Microsoft 365 (Entra ID). Users whose only second factor is a texted code hit a blocking passkey-registration prompt — Microsoft's own wording: there is no opt-out, for any tenant. Organizations with a genuine regulatory need for texted codes will be able to buy them back through a third-party provider, at per-message cost — details in our guide.

Who it affects: Every Microsoft 365 organization, every industry, every size.

Do this: Finish moving every user to a passkey, Windows Hello, or a security key before this date. Check whether your password-reset process also depends on text messages — the retirement covers that too.

Source: Microsoft Learn · our printable checklist →

Recently passed deadlines — still biting the businesses that missed them
Oct 14, 2025passed

Windows 10 end of support (free updates ended)

Machines without an ESU subscription have received no security patches since.

If that's you: Treat those machines as unpatched and prioritize replacement.

Source: Microsoft

Oct 14, 2025passed

Exchange Server 2016/2019 and Office 2016/2019 end of support

On-premises Exchange 2016/2019 and perpetual Office 2016/2019 left support on October 14, 2025 — no more security fixes.

If that's you: Unsupported mail servers are a favorite ransomware entry point — migrate to Exchange Online or a supported platform.

Source: Microsoft Learn

Threat Watch

The stories below are curated and written by us — each with the part most reporting skips: what it means for a business your size, and what to do. The live list underneath comes straight from CISA.

Act now Aug 3, 2026

Actively exploited flaw in N-able N-central — and the first fix did not hold

N-able disclosed CVE-2026-18577 on August 2, 2026: an authentication bypass that grants administrative takeover of an N-central server. It exists because the earlier fix for CVE-2026-18556 was incomplete — attackers found another route to the same flaw. CISA added it to the Known Exploited Vulnerabilities catalog on August 3, 2026 and gave federal agencies three days to remediate, its strongest urgency signal. Every build through 2026.3.1 is affected; the fix is N-central 2026.3 HF1 (Hotfix 1). N-central is a platform many IT providers use to manage their clients’ systems, so a compromised server can mean attacker access to every business behind it.

What it means for you: This is a supply-chain risk: the question isn’t whether YOUR systems run this software — it’s whether your IT provider’s do. Ask one question today, and note that the obvious version of it is now the wrong one: “patched for CVE-2026-18556” is no longer a sufficient answer, because 2026.2 fixed that path and remained exploitable. The question to ask is: “Is our N-central instance on 2026.3 HF1 or later, and on what date was it applied?” A good provider answers with a version and a date. Silence is an answer too.

Reported by: N-able — N-central security update, August 2, 2026 · CISA — adds one Known Exploited Vulnerability to catalog (Aug 3, 2026) · NVD — CVE-2026-18577

Act now Aug 1, 2026

Hotel and guest Wi-Fi hijacked to steal Microsoft 365 logins

Microsoft Threat Intelligence is warning about a campaign it calls CaptiveCrunch, attributed to a Russian state-linked group. Attackers compromise the sign-in pages of hotel, conference, and other guest Wi-Fi networks (the "captive portal"), then redirect users to fake software-update prompts. The download installs malware that harvests browser cookies, passwords, and Microsoft 365 session tokens, and can capture keystrokes, screenshots, and audio. Active since at least May 2026, targeting travelers worldwide.

What it means for you: If your people travel — escrow officers at closings, partners at conferences, anyone working from a hotel — treat guest Wi-Fi as hostile by default. Use a phone hotspot or your company VPN. A Wi-Fi login page that offers you a software update is an attack, every time.

Reported by: Microsoft Threat Intelligence (via BleepingComputer)

Plan for it Jul 29, 2026

Reminder: Microsoft's clock is running on text-message sign-in codes

Microsoft's updated guidance re-confirms both dates on the tracker above: passkey prompts begin September 1, and texted sign-in codes end February 1, 2027.

What it means for you: The office that migrates in September does it calmly; the office that waits for February does it during a lockout. Read our guide →

Reported by: Microsoft Learn

Actively exploited right now — CISA's Known Exploited Vulnerabilities

Flaws confirmed to be under real-world attack — not theoretical. When your software appears here, patching stops being routine maintenance and becomes urgent. Newest 15 entries; full catalog at CISA.

Source: CISA Known Exploited Vulnerabilities catalog (U.S. government, public domain). Feed refreshed Aug 13, 2026.
AddedSoftwareWhat it isUsed in ransomware?
Aug 11, 2026 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. Unknown
Aug 11, 2026 Microsoft Windows Ancillary Function Driver for WinSock
CVE-2026-68820
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Unknown
Aug 11, 2026 Metabase Metabase
CVE-2026-72898
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Unknown
Aug 7, 2026 Progress LoadMaster
CVE-2026-8037
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Unknown
Aug 5, 2026 JetBrains TeamCity
CVE-2026-63077
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Unknown
Aug 4, 2026 N-able N-central
CVE-2026-18556
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Unknown
Aug 4, 2026 Apache Tomcat
CVE-2026-34486
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Unknown
Aug 4, 2026 IBM Langflow
CVE-2026-9198
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Unknown
Aug 3, 2026 N-able N-central
CVE-2026-18577
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. Unknown
Jul 29, 2026 Cisco Secure Firewall Management Center (FMC)
CVE-2026-20316
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. Unknown
Jul 27, 2026 Fortinet FortiOS
CVE-2025-68686
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. Unknown
Jul 27, 2026 Arista VeloCloud Orchestrator
CVE-2026-16812
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Unknown
Jul 22, 2026 Check Point SmartConsole
CVE-2026-16232
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Unknown
Jul 22, 2026 Microsoft SharePoint
CVE-2026-50522
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Unknown
Jul 21, 2026 WordPress Core
CVE-2026-60137
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Unknown

The full CISA catalog →

Latest CISA advisories

Industry headlines

What the security press is covering right now — each headline links straight to the original reporting. Their story, their site, their click.

How this briefing is sourced

Government data, republished as intended. The vulnerability and advisory lists come from CISA and NIST — U.S. government publications in the public domain (17 U.S.C. §105), published expressly for reuse. We reproduce them faithfully and link the originals.

News, in our own words. Curated stories are summaries we write ourselves from the underlying facts, always crediting and linking the original reporting. We never republish another outlet's text — their reporting deserves the click.

Facts are stated as of the date shown. Vulnerability and deadline entries reflect the linked source at the time we recorded it. Vendors' own advisories are the authoritative record, and a date that moves is the vendor's to move — if you are acting on something here, click through and confirm the current position first.

Headlines are links, nothing more. The industry-headlines list carries each outlet's title, date, and a link to their site — no excerpts, no copies. If a headline interests you, the click belongs to the people who reported it.

What this isn't. A briefing, not incident response. If something on this page is happening to you right now, don't read — call (949) 916-6444.

Want someone watching this for you?

Secure IT clients don't read threat feeds — our 24/7 security operations coverage does it for them. See where your business stands, with the owner.

Book a Free 30-Minute IT Assessment