Live briefing · Updated Sep 5, 2026

Security Briefing: What's Expiring, What's Attacking

The threats and deadlines that actually affect a small or midsize business — in plain English, with what to do about each. Government advisories straight from CISA (the U.S. government's cyber-defense agency), the attack stories that matter, and the IT deadlines heading for your calendar. No fear-mongering, no email gate.

The IT Deadline Tracker

Dates when something your business relies on stops working, changes behavior, or becomes an obligation. Every date is verified against the primary source linked on the card — not against someone's blog post.

Sep 1, 2026 passed

Microsoft 365: passkeys become the default sign-in

What happens: Users still enabled for text-message or voice codes are automatically enrolled for passkeys and start seeing registration prompts at sign-in. The prompts can be snoozed — for now.

Who it affects: Every business running Microsoft 365 where anyone still signs in with a texted code.

Do this: Inventory who still uses SMS or voice codes, choose each group's passkey method (Authenticator app, Windows Hello, or a hardware key), and tell your team before the prompts surprise them.

Source: Microsoft Learn · our migration guide →

Sep 11, 2026 in 5 days

CMMC: Phase 2 suspended — program review outcome expected

What happens: On July 13, 2026 the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones, ordering a 60-day program review. The November 10, 2026 third-party (C3PAO) assessment phase-in is off the calendar, and contracting officers are directed to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification before the next option period — Level 1 (Self) and Level 2 (Self) designations remain, and no waivers are granted during the review. What did NOT change: DFARS 252.204-7012 still requires NIST SP 800-171; DFARS 252.204-7019 and -7020 still require a current SPRS score and annual affirmation; Phase 1 self-assessments stay in force; and government-led DIBCAC assessments continue.

Who it affects: Defense suppliers, machine shops, and subcontractors handling federal contract information or CUI — at any tier.

Do this: Do not stand down. Keep your NIST 800-171 self-assessment and SPRS score current. An affirmation is a legal statement, and the Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over misrepresented cybersecurity compliance whether or not a certification deadline is pending. Watch for the review outcome around mid-September.

Source: Department of War — CMMC Phase II suspension memorandum · our full guide →

Oct 13, 2026 in 37 days

Windows 10: consumer Extended Security Updates end

What happens: The one-year consumer ESU bridge ends — enrolled Windows 10 PCs stop receiving security patches after this date. Business ESU continues only as an annually purchased subscription (available through October 2028).

Who it affects: Any office still running Windows 10 PCs — especially machines that used the free consumer ESU enrollment as a stopgap.

Do this: Replace or upgrade remaining Windows 10 machines to Windows 11, or budget the business ESU subscription for machines that genuinely cannot move yet. An unpatched PC on your network is everyone's problem.

Source: Microsoft

Feb 1, 2027 in 148 days

Microsoft 365: text-message and voice sign-in codes retired

What happens: Microsoft-provided SMS and voice delivery is fully retired from the sign-in system behind Microsoft 365 (Entra ID). Users whose only second factor is a texted code hit a blocking passkey-registration prompt — Microsoft's own wording: there is no opt-out, for any tenant. Organizations with a genuine regulatory need for texted codes will be able to buy them back through a third-party provider, at per-message cost — details in our guide.

Who it affects: Every Microsoft 365 organization, every industry, every size.

Do this: Finish moving every user to a passkey, Windows Hello, or a security key before this date. Check whether your password-reset process also depends on text messages — the retirement covers that too.

Source: Microsoft Learn · our printable checklist →

Deadlines already passed — still biting the businesses that missed them
Oct 14, 2025passed

Windows 10 end of support (free updates ended)

Machines without an ESU subscription have received no security patches since.

If that's you: Treat those machines as unpatched and prioritize replacement.

Source: Microsoft

Oct 14, 2025passed

Exchange Server 2016/2019 and Office 2016/2019 end of support

On-premises Exchange 2016/2019 and perpetual Office 2016/2019 left support on October 14, 2025 — no more security fixes.

If that's you: Unsupported mail servers are a favorite ransomware entry point — migrate to Exchange Online or a supported platform.

Source: Microsoft Learn

Threat Watch

The stories below are curated and written by us — each with the part most reporting skips: what it means for a business your size, and what to do. The live list underneath comes straight from CISA.

Plan for it Aug 26, 2026

Microsoft switches passkeys on for your staff automatically on September 1 — and the opt-out expires in February

Microsoft has now spelled out the mechanics of a change most businesses have not prepared for. In its own words: “Starting September 1, 2026, passkeys become the default authentication experience and will be automatically enabled for users enabled for SMS or voice.” That happens inside your tenant without an administrator doing anything — anyone currently set up for texted or voice codes has passkeys switched on for them in the Authentication Methods Policy. September is not the hard part. A temporary opt-out exists for the window between September 1 and February 1, 2027. After that the tone changes: Microsoft states that from February 1, 2027, users whose only available MFA method is SMS or voice “will be required to register a passkey during sign-in to continue accessing their account,” that the prompt will be blocking, and — verbatim — “There is no opt out from this February 1 behavior. It will be enforced for all tenants.”

What it means for you: Two different problems, five months apart. September’s is confusion: your people start seeing passkey prompts nobody warned them about, and an unexpected security prompt is exactly what a well-built phishing page imitates. Send a short note before September 1 saying the prompt is genuine, what it looks like and who to ask — that one email prevents most of the calls and most of the risk. February’s is an outage. Anyone whose only second factor is a texted code will be stopped at sign-in until they enrolll a passkey, and there is no administrative switch to defer it. The work itself is not hard: find every account still relying on SMS or voice as its only method and move it to a passkey or an authenticator app. Done this fall it is routine housekeeping. Done on February 2 it is a lockout, in business hours, with no way to buy time. Read our guide →

Reported by: Microsoft Entra documentation · Microsoft Security Blog

Act now Aug 12, 2026

A SharePoint patch sat available for a month. A proof-of-concept turned it into an attack in one day.

CVE-2026-55040 is an authentication bypass in Microsoft SharePoint — Microsoft describes it as a weak authentication issue that lets an attacker bypass a security feature over a network, exposing files and allowing data to be modified. Microsoft scores it CVSS 9.1. Microsoft shipped the fix in its July 2026 Patch Tuesday. Rapid7 published proof-of-concept exploit code on August 11, 2026, and threat-intelligence firm Defused reported real attacks on August 12 — the next day. It is the fifth SharePoint flaw exploited in the wild this summer, after CVE-2026-50522, CVE-2026-58644, CVE-2026-56164 and CVE-2026-45659.

What it means for you: The fix existed for a month before anyone was attacked with it. That gap is the whole story, and it is not a Microsoft problem — it is a patching-cadence problem. Public exploit code compresses your safe window from weeks to hours, so the question is not whether your team would eventually have applied the July updates, it is whether they were applied before August 11. If you run SharePoint Server on-premises, confirm the July 2026 cumulative update is actually installed, not merely downloaded. SharePoint Online is Microsoft's to patch.

Reported by: Microsoft Security Response Center — CVE-2026-55040 · SecurityWeek · The Hacker News

Act now Aug 11, 2026

Adobe ships a Priority 1 ColdFusion fix — including a CVSS 10.0 command injection

Adobe security bulletin APSB26-90, dated August 11, 2026 and rated Priority 1, patches sixteen ColdFusion vulnerabilities. The most severe, CVE-2026-48362, is an OS command injection scoring CVSS 10.0 and leading to arbitrary code execution; CVE-2026-48273 (eval injection, 9.9) is close behind. Affected: ColdFusion 2025 through 2025.0.11 and ColdFusion 2023 through 2023.0.22. Fixed in 2025.0.12 and 2023.0.23.

What it means for you: ColdFusion is the kind of platform that is easy to forget you are running — it is usually underneath one old line-of-business application nobody has touched in years, and it is frequently reachable from the internet. That combination is why a CVSS 10.0 here is an emergency rather than a maintenance item: command injection on an internet-facing server is a full compromise with no credentials required. If you do not know whether you run ColdFusion, that is the finding, not the answer — an accurate application inventory is the first thing any of this depends on.

Reported by: Adobe Security Bulletin APSB26-90 · The Hacker News

Act now Aug 3, 2026

Actively exploited flaw in N-able N-central — and the first fix did not hold

N-able disclosed CVE-2026-18577 on August 2, 2026: an authentication bypass that grants administrative takeover of an N-central server. It exists because the earlier fix for CVE-2026-18556 was incomplete — attackers found another route to the same flaw. CISA added it to the Known Exploited Vulnerabilities catalog on August 3, 2026 and gave federal agencies three days to remediate, its strongest urgency signal. Every build through 2026.3.1 is affected; the fix is N-central 2026.3 HF1 (Hotfix 1). N-central is a platform many IT providers use to manage their clients’ systems, so a compromised server can mean attacker access to every business behind it.

What it means for you: This is a supply-chain risk: the question isn’t whether YOUR systems run this software — it’s whether your IT provider’s do. Ask one question today, and note that the obvious version of it is now the wrong one: “patched for CVE-2026-18556” is no longer a sufficient answer, because 2026.2 fixed that path and remained exploitable. The question to ask is: “Is our N-central instance on 2026.3 HF1 or later, and on what date was it applied?” A good provider answers with a version and a date. Silence is an answer too.

Reported by: N-able — N-central security update, August 2, 2026 · CISA — adds one Known Exploited Vulnerability to catalog (Aug 3, 2026) · NVD — CVE-2026-18577

Act now Aug 1, 2026

Hotel and guest Wi-Fi hijacked to steal Microsoft 365 logins

Microsoft Threat Intelligence is warning about a campaign it calls CaptiveCrunch, attributed to a Russian state-linked group. Attackers compromise the sign-in pages of hotel, conference, and other guest Wi-Fi networks (the "captive portal"), then redirect users to fake software-update prompts. The download installs malware that harvests browser cookies, passwords, and Microsoft 365 session tokens, and can capture keystrokes, screenshots, and audio. Active since at least May 2026, targeting travelers worldwide.

What it means for you: If your people travel — escrow officers at closings, partners at conferences, anyone working from a hotel — treat guest Wi-Fi as hostile by default. Use a phone hotspot or your company VPN. A Wi-Fi login page that offers you a software update is an attack, every time.

Reported by: Microsoft Security Blog — Microsoft Threat Intelligence · Microsoft Threat Intelligence (via BleepingComputer)

Plan for it Jul 29, 2026

Reminder: Microsoft's clock is running on text-message sign-in codes

Microsoft's updated guidance re-confirms both dates on the tracker above: passkey prompts begin September 1, and texted sign-in codes end February 1, 2027.

What it means for you: The office that migrates in September does it calmly; the office that waits for February does it during a lockout. Read our guide →

Reported by: Microsoft Learn

Actively exploited right now — CISA's Known Exploited Vulnerabilities

Flaws confirmed to be under real-world attack — not theoretical. When your software appears here, patching stops being routine maintenance and becomes urgent. Newest 15 entries; full catalog at CISA.

Source: CISA Known Exploited Vulnerabilities catalog (U.S. government, public domain). Feed refreshed Sep 6, 2026.
AddedSoftwareWhat it isUsed in ransomware?
Sep 2, 2026 SonicWall SMA1000 Appliances
CVE-2026-83548
Firewalls and remote access — check with whoever manages yours
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. None reported
Sep 2, 2026 SonicWall SMA1000 Appliances
CVE-2026-83549
Firewalls and remote access — check with whoever manages yours
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. None reported

Also added in this period, in systems far less common in small-business environments — Google Chromium V8, BerriAI LiteLLM, Kludex Starlette, Kestra OSS, JFrog Artifactory, Sangoma Switchvox, PaperCut NG/MF, PaperCut NG/MF, ownCloud, Linux Kernel, JFrog Artifactory, Ajax.NET Professional, Red Hat Libuser. Listed for completeness; if you don't run them, there is nothing here for you to do.

“None reported” means CISA has no record of this flaw being used in a ransomware campaign — it is not an all-clear, and it can change as investigations catch up.

The full CISA catalog →

Latest CISA advisories

Industry headlines

What the security press is covering right now — each headline links straight to the original reporting. Their story, their site, their click.

How this briefing is sourced

Government data, republished as intended. The vulnerability and advisory lists come from CISA and NIST — U.S. government publications in the public domain (17 U.S.C. §105), published expressly for reuse. We reproduce them faithfully and link the originals.

News, in our own words. Curated stories are summaries we write ourselves from the underlying facts, always crediting and linking the original reporting. We never republish another outlet's text — their reporting deserves the click.

Facts are stated as of the date shown. Vulnerability and deadline entries reflect the linked source at the time we recorded it. Vendors' own advisories are the authoritative record, and a date that moves is the vendor's to move — if you are acting on something here, click through and confirm the current position first.

Headlines are links, nothing more. The industry-headlines list carries each outlet's title, date, and a link to their site — no excerpts, no copies. If a headline interests you, the click belongs to the people who reported it.

What this isn't. A briefing, not incident response. If something on this page is happening to you right now, don't read — call (949) 916-6444.

Want someone watching this for you?

Secure IT clients don't read threat feeds — our 24/7 security operations coverage does it for them. See where your business stands, with the owner.

Book a Free 30-Minute IT Assessment