← All briefings

Your IT provider's tools are under attack, and it's a patch week

Week of 17 to 23 August 2026

A busy week: the tool many IT providers use to manage client computers came under active attack in Australia; Windows, macOS and on-premises SharePoint all carried flaws criminals were already using; hosted Zimbra email needed patching; and a genuine National Anti-Scam Centre email arrived trailing its own follow-up scam.

  1. 1

    Ask your IT provider one question this week

    Any business whose IT is managed by an external provider or MSP (managed service provider).

    Many IT providers manage their clients' computers with a tool called N-able N-central, remote monitoring and management (RMM) software. The Australian Cyber Security Centre has issued a high alert: attackers are actively exploiting it in Australia, using two flaws that let them in without a password. A fix has existed since early August, but it only protects you if your provider has installed it.

    Do this

    Email whoever manages your IT: "Do you use N-able N-central to manage our systems, and is it patched to the August hotfix?" A good provider answers same-day.

    Essential Eight: Patch applicationsISM: Managed services and outsourcing

    Sources: ACSC high alert ↗ · N-able security update ↗CVE-2026-18556 · CVE-2026-18577 · CWE-288

  2. 2

    Approve this month's Windows and Mac updates: don't defer

    Everyone: any business running Windows PCs or Macs.

    Two operating system flaws joined the actively-exploited list this week. On Windows, a flaw in a built-in networking component (CVE-2026-33824) is rated more likely to be exploited than 99% of known vulnerabilities. On Mac, a flaw lets software bypass a security check (CVE-2026-65400). Both are fixed by the current updates. The risk is in postponing them.

    Do this

    Install the August updates on every Windows computer and update your Macs this week. If updates are managed for you, ask for confirmation they have been applied.

    Essential Eight: Patch operating systemsISM: System patching

    Sources: CISA KEV: Windows IKE flaw ↗ · CISA KEV: macOS flaw ↗ · Apple security releases ↗CVE-2026-33824 · CVE-2026-65400 · CWE-415 · CWE-287

  3. 3

    Run your own SharePoint server? Patch it. Use Microsoft 365? Ignore this one

    Only businesses running their own on-premises SharePoint server (uncommon for small business, worth checking for mid-sized ones).

    A weak-authentication flaw in Microsoft SharePoint (CVE-2026-55040) is being actively exploited. It affects only SharePoint servers a business runs itself. If your documents live in Microsoft 365, this one is Microsoft's problem, not yours, and you can skip to the next item.

    Do this

    If you run SharePoint on your own server, apply Microsoft's fix now; if you're not sure whether you do, ask your IT contact that exact question.

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: SharePoint flaw ↗CVE-2026-55040 · CWE-1390

  4. 4

    Email hosted on Zimbra? Ask your host about the patch

    Businesses whose email is hosted by a smaller provider or ISP rather than Microsoft 365 or Google Workspace.

    Zimbra Collaboration Suite, email software some hosting providers use to run business mailboxes, has a flaw (CVE-2026-73570) that lets attackers run commands on the mail server, and it is being actively exploited. Most small businesses on Microsoft 365 or Google Workspace are not affected; those on provider-hosted email might be without knowing it.

    Do this

    If your email address is hosted by a local provider, ask them: "Is our mail on Zimbra, and is it patched for CVE-2026-73570?"

    Essential Eight: Patch applicationsISM: Email security

    Sources: CISA KEV: Zimbra flaw ↗CVE-2026-73570 · CWE-78

  5. 5

    An email from the National Anti-Scam Centre? It's real, but watch the follow-up

    Anyone who has put money into cryptocurrency platforms, including business owners contacted at work addresses.

    The National Anti-Scam Centre has emailed more than 10,000 Australians whose details surfaced in a UK police investigation into a crypto investment scam operation. Two things to know: the email itself is genuine and asks for nothing, and anyone who then calls offering to recover lost money for a fee is running the follow-up scam. Authorities never charge to recover funds.

    Do this

    If you receive the notification, read it and follow its guidance directly, and treat any later call or email offering paid "fund recovery" as a scam.

    Essential Eight: Multi-factor authenticationISM: Cyber security awareness training

    Sources: Scamwatch announcement ↗

Beyond this week's news

Reading about threats is step one. Knowing where you stand is step two.

See whether the security products you already pay for cover the basics (free, in about three minutes), or get a fixed-price, plain-English review of your whole setup.

Prefer LinkedIn? Follow TERESEC: the briefing lands there every Monday.

Latest ISM release: ISM September 2026: What Changed and What to Check →What the ISM is and how we assess it →