Live briefing · Updated Aug 4, 2026

Security Briefing: What's Attacking, What's Expiring

The threats and deadlines that actually affect a small or midsize business — in plain English, with what to do about each. Government advisories straight from CISA (the U.S. government's cyber-defense agency), the attack stories that matter, and the IT deadlines heading for your calendar. No fear-mongering, no email gate.

The IT Deadline Tracker

Dates when something your business relies on stops working, changes behavior, or becomes an obligation. Every date is verified against the primary source linked on the card — not against someone's blog post.

Sep 1, 2026 in 28 days

Microsoft 365: passkeys become the default sign-in

What happens: Users still enabled for text-message or voice codes are automatically enrolled for passkeys and start seeing registration prompts at sign-in. The prompts can be snoozed — for now.

Who it affects: Every business running Microsoft 365 where anyone still signs in with a texted code.

Do this: Inventory who still uses SMS or voice codes, choose each group's passkey method (Authenticator app, Windows Hello, or a hardware key), and tell your team before the prompts surprise them.

Source: Microsoft Learn · our migration guide →

Oct 13, 2026 in 70 days

Windows 10: consumer Extended Security Updates end

What happens: The one-year consumer ESU bridge ends — enrolled Windows 10 PCs stop receiving security patches after this date. Business ESU continues only as an annually purchased subscription (available through October 2028).

Who it affects: Any office still running Windows 10 PCs — especially machines that used the free consumer ESU enrollment as a stopgap.

Do this: Replace or upgrade remaining Windows 10 machines to Windows 11, or budget the business ESU subscription for machines that genuinely cannot move yet. An unpatched PC on your network is everyone's problem.

Source: Microsoft

Nov 1, 2026 in 89 days

CMMC: third-party assessment requirements phase into new DoD contracts

What happens: The CMMC rule has been enforceable in DoD contracts since November 2025; from November 2026 the phase-in widens and third-party (C3PAO) assessment requirements begin appearing in more new solicitations. Primes are already asking subcontractors for SPRS scores ahead of the calendar.

Who it affects: Defense suppliers, machine shops, and subcontractors handling federal contract information or CUI — at any tier.

Do this: If defense work is any part of your revenue, get your NIST 800-171 self-assessment and SPRS score current now, and book assessor capacity early — C3PAO calendars are filling.

Source: 32 CFR Part 170 — the CMMC program rule (eCFR) · our full guide →

Feb 1, 2027 in 181 days

Microsoft 365: text-message and voice sign-in codes retired

What happens: Microsoft-provided SMS and voice delivery is fully retired from the sign-in system behind Microsoft 365 (Entra ID). Users whose only second factor is a texted code hit a blocking passkey-registration prompt — Microsoft's own wording: there is no opt-out, for any tenant. Organizations with a genuine regulatory need for texted codes will be able to buy them back through a third-party provider, at per-message cost — details in our guide.

Who it affects: Every Microsoft 365 organization, every industry, every size.

Do this: Finish moving every user to a passkey, Windows Hello, or a security key before this date. Check whether your password-reset process also depends on text messages — the retirement covers that too.

Source: Microsoft Learn · our printable checklist →

Recently passed deadlines — still biting the businesses that missed them
Oct 14, 2025passed

Windows 10 end of support (free updates ended)

Machines without an ESU subscription have received no security patches since.

If that's you: Treat those machines as unpatched and prioritize replacement.

Source: Microsoft

Oct 14, 2025passed

Exchange Server 2016/2019 and Office 2016/2019 end of support

On-premises Exchange 2016/2019 and perpetual Office 2016/2019 left support on October 14, 2025 — no more security fixes.

If that's you: Unsupported mail servers are a favorite ransomware entry point — migrate to Exchange Online or a supported platform.

Source: Microsoft Learn

Threat Watch

The stories below are curated and written by us — each with the part most reporting skips: what it means for a business your size, and what to do. The live list underneath comes straight from CISA.

Act now Aug 4, 2026

Actively exploited flaw in N-able N-central, a platform many IT providers use to manage client systems

CISA added CVE-2026-18556 — an authentication bypass in N-central — to its Known Exploited Vulnerabilities catalog, confirming attackers are using it in the wild. Federal agencies were given three days to remediate, CISA's strongest urgency signal. A compromised management platform can mean attacker access to every business it manages.

What it means for you: This is a supply-chain risk: the question isn't whether YOUR systems run this software — it's whether your IT provider's do. Any business whose provider manages them through N-central should ask one question today: 'When was our N-central instance patched for CVE-2026-18556?' A good provider answers with a date. Silence is an answer too.

Reported by: CISA Known Exploited Vulnerabilities Catalog

Act now Aug 1, 2026

Hotel and guest Wi-Fi hijacked to steal Microsoft 365 logins

Microsoft Threat Intelligence is warning about a campaign it calls CaptiveCrunch, attributed to a Russian state-linked group. Attackers compromise the sign-in pages of hotel, conference, and other guest Wi-Fi networks (the "captive portal"), then redirect users to fake software-update prompts. The download installs malware that harvests browser cookies, passwords, and Microsoft 365 session tokens, and can capture keystrokes, screenshots, and audio. Active since at least May 2026, targeting travelers worldwide.

What it means for you: If your people travel — escrow officers at closings, partners at conferences, anyone working from a hotel — treat guest Wi-Fi as hostile by default. Use a phone hotspot or your company VPN. A Wi-Fi login page that offers you a software update is an attack, every time.

Reported by: Microsoft Threat Intelligence (via BleepingComputer)

Plan for it Jul 29, 2026

Reminder: Microsoft's clock is running on text-message sign-in codes

Microsoft's updated guidance re-confirms both dates on the tracker above: passkey prompts begin September 1, and texted sign-in codes end February 1, 2027.

What it means for you: The office that migrates in September does it calmly; the office that waits for February does it during a lockout. Read our guide →

Reported by: Microsoft Learn

Actively exploited right now — CISA's Known Exploited Vulnerabilities

Flaws confirmed to be under real-world attack — not theoretical. When your software appears here, patching stops being routine maintenance and becomes urgent. Newest 15 entries; full catalog at CISA.

Source: CISA Known Exploited Vulnerabilities catalog (U.S. government, public domain). Feed refreshed Aug 4, 2026.
AddedSoftwareWhat it isUsed in ransomware?
Aug 4, 2026 N-able N-central
CVE-2026-18556
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Unknown
Aug 4, 2026 Apache Tomcat
CVE-2026-34486
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. Unknown
Aug 4, 2026 IBM Langflow
CVE-2026-9198
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Unknown
Aug 3, 2026 N-able N-central
CVE-2026-18577
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. Unknown
Jul 29, 2026 Cisco Secure Firewall Management Center (FMC)
CVE-2026-20316
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. Unknown
Jul 27, 2026 Fortinet FortiOS
CVE-2025-68686
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. Unknown
Jul 27, 2026 Arista VeloCloud Orchestrator
CVE-2026-16812
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Unknown
Jul 22, 2026 Check Point SmartConsole
CVE-2026-16232
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Unknown
Jul 22, 2026 Microsoft SharePoint
CVE-2026-50522
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Unknown
Jul 21, 2026 WordPress Core
CVE-2026-60137
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. Unknown
Jul 21, 2026 WordPress Core
CVE-2026-63030
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. Unknown
Jul 21, 2026 Langflow Langflow
CVE-2026-0770
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Unknown
Jul 21, 2026 DD-WRT DD-WRT
CVE-2021-27137
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Unknown
Jul 16, 2026 Microsoft SharePoint
CVE-2026-58644
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Unknown
Jul 16, 2026 Fortinet FortiSandbox
CVE-2026-25089
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Unknown

The full CISA catalog →

Latest CISA advisories

Industry headlines

What the security press is covering right now — each headline links straight to the original reporting. Their story, their site, their click.

How this briefing is sourced

Government data, republished as intended. The vulnerability and advisory lists come from CISA and NIST — U.S. government publications in the public domain (17 U.S.C. §105), published expressly for reuse. We reproduce them faithfully and link the originals.

News, in our own words. Curated stories are summaries we write ourselves from the underlying facts, always crediting and linking the original reporting. We never republish another outlet's text — their reporting deserves the click.

Headlines are links, nothing more. The industry-headlines list carries each outlet's title, date, and a link to their site — no excerpts, no copies. If a headline interests you, the click belongs to the people who reported it.

What this isn't. A briefing, not incident response. If something on this page is happening to you right now, don't read — call (949) 916-6444.

Want someone watching this for you?

Secure IT clients don't read threat feeds — our 24/7 security operations coverage does it for them. See where your business stands, with the owner.

Book a Free 30-Minute IT Assessment