{
  "slug": "2026-08-17",
  "date": "2026-08-17",
  "updated": "2026-08-21",
  "title": "Your IT provider's tools are under attack — and it's a patch week",
  "intro": "A busy week: the tool many IT providers use to manage client computers came under active attack in Australia; Windows, macOS and on-premises SharePoint all carried flaws criminals were already using; hosted Zimbra email needed patching; and a genuine National Anti-Scam Centre email arrived trailing its own follow-up scam.",
  "quietWeek": false,
  "items": [
    {
      "id": "n-able-n-central",
      "rank": 1,
      "published": "2026-08-19",
      "title": "Ask your IT provider one question this week",
      "summary": "Many IT providers manage their clients' computers with a tool called N-able N-central — remote monitoring and management (RMM) software. The Australian Cyber Security Centre has issued a high alert: attackers are actively exploiting it in Australia, using two flaws that let them in without a password. A fix has existed since early August, but it only protects you if your provider has installed it.",
      "whoItAffects": "Any business whose IT is managed by an external provider or MSP (managed service provider).",
      "action": "Email whoever manages your IT: \"Do you use N-able N-central to manage our systems, and is it patched to the August hotfix?\" A good provider answers same-day.",
      "prevention": {
        "e8": "Patch applications",
        "ism": "Managed services and outsourcing"
      },
      "sourceKind": "acsc",
      "cves": [
        "CVE-2026-18556",
        "CVE-2026-18577"
      ],
      "links": [
        {
          "label": "ACSC high alert",
          "url": "https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-remote-monitoring-and-management-platform-within-australia"
        },
        {
          "label": "N-able security update",
          "url": "https://www.n-able.com/blog/n-central-security-update-august-10-2026"
        }
      ],
      "cwes": [
        "CWE-288"
      ]
    },
    {
      "id": "windows-macos-updates",
      "rank": 2,
      "published": "2026-08-18",
      "title": "Approve this month's Windows and Mac updates — don't defer",
      "summary": "Two operating system flaws joined the actively-exploited list this week. On Windows, a flaw in a built-in networking component (CVE-2026-33824) is rated more likely to be exploited than 99% of known vulnerabilities. On Mac, a flaw lets software bypass a security check (CVE-2026-65400). Both are fixed by the current updates — the risk is in postponing them.",
      "whoItAffects": "Everyone — any business running Windows PCs or Macs.",
      "action": "Install the August updates on every Windows computer and update your Macs this week. If updates are managed for you, ask for confirmation they have been applied.",
      "prevention": {
        "e8": "Patch operating systems",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": [
        "CVE-2026-33824",
        "CVE-2026-65400"
      ],
      "links": [
        {
          "label": "CISA KEV: Windows IKE flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-33824"
        },
        {
          "label": "CISA KEV: macOS flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-65400"
        },
        {
          "label": "Apple security releases",
          "url": "https://support.apple.com/en-au/100100"
        }
      ],
      "cwes": [
        "CWE-415",
        "CWE-287"
      ]
    },
    {
      "id": "sharepoint-on-prem",
      "rank": 3,
      "published": "2026-08-18",
      "title": "Run your own SharePoint server? Patch it. Use Microsoft 365? Ignore this one",
      "summary": "A weak-authentication flaw in Microsoft SharePoint (CVE-2026-55040) is being actively exploited. It affects only SharePoint servers a business runs itself — if your documents live in Microsoft 365, this one is Microsoft's problem, not yours, and you can skip to the next item.",
      "whoItAffects": "Only businesses running their own on-premises SharePoint server — uncommon for small business, worth checking for mid-sized ones.",
      "action": "If you run SharePoint on your own server, apply Microsoft's fix now; if you're not sure whether you do, ask your IT contact that exact question.",
      "prevention": {
        "e8": "Patch applications",
        "ism": "System patching"
      },
      "sourceKind": "kev",
      "cves": [
        "CVE-2026-55040"
      ],
      "links": [
        {
          "label": "CISA KEV: SharePoint flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-55040"
        }
      ],
      "cwes": [
        "CWE-1390"
      ]
    },
    {
      "id": "zimbra-hosted-email",
      "rank": 4,
      "published": "2026-08-21",
      "title": "Email hosted on Zimbra? Ask your host about the patch",
      "summary": "Zimbra Collaboration Suite — email software some hosting providers use to run business mailboxes — has a flaw (CVE-2026-73570) that lets attackers run commands on the mail server, and it is being actively exploited. Most small businesses on Microsoft 365 or Google Workspace are not affected; those on provider-hosted email might be without knowing it.",
      "whoItAffects": "Businesses whose email is hosted by a smaller provider or ISP rather than Microsoft 365 or Google Workspace.",
      "action": "If your email address is hosted by a local provider, ask them: \"Is our mail on Zimbra, and is it patched for CVE-2026-73570?\"",
      "prevention": {
        "e8": "Patch applications",
        "ism": "Email security"
      },
      "sourceKind": "kev",
      "cves": [
        "CVE-2026-73570"
      ],
      "links": [
        {
          "label": "CISA KEV: Zimbra flaw",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-73570"
        }
      ],
      "cwes": [
        "CWE-78"
      ]
    },
    {
      "id": "nasc-crypto-scam-contact",
      "rank": 5,
      "published": "2026-08-17",
      "title": "An email from the National Anti-Scam Centre? It's real — but watch the follow-up",
      "summary": "The National Anti-Scam Centre has emailed more than 10,000 Australians whose details surfaced in a UK police investigation into a crypto investment scam operation. Two things to know: the email itself is genuine and asks for nothing — and anyone who then calls offering to recover lost money for a fee is running the follow-up scam. Authorities never charge to recover funds.",
      "whoItAffects": "Anyone who has put money into cryptocurrency platforms — including business owners contacted at work addresses.",
      "action": "If you receive the notification, read it and follow its guidance directly — and treat any later call or email offering paid \"fund recovery\" as a scam.",
      "prevention": {
        "e8": "Multi-factor authentication",
        "ism": "Cyber security awareness training"
      },
      "sourceKind": "scamwatch",
      "links": [
        {
          "label": "Scamwatch announcement",
          "url": "https://www.scamwatch.gov.au/about-us/news-and-alerts/nasc-contacts-australians-following-international-cryptocurrency-scam-investigation"
        }
      ]
    }
  ]
}
