Microsoft Just Shipped Its Biggest Patch Ever — and Two Holes Are Already Being Attacked

Filed under: Cybersecurity · Patching · July 2026

What happened

On July 14, 2026, Microsoft released its monthly “Patch Tuesday” update — the largest in the company’s history, fixing a record 570 security flaws. Two of them are already being used in real attacks: a privilege-escalation bug in Active Directory Federation Services (CVE-2026-56155) and one in SharePoint Server (CVE-2026-50661 — a BitLocker bypass — was publicly disclosed but not yet exploited). More important for most small offices, the same update quietly fixes several “critical” flaws in Excel, Word, and PowerPoint that could let a booby-trapped document run malicious code the moment it’s opened, plus critical Windows bugs in DHCP and graphics.

Why it matters to your business

Every Phoenix small business runs Windows and Office, so this update touches essentially every PC in your office. The scary-sounding zero-days are in server products (AD FS and SharePoint) that most small firms don’t run on their own hardware — but the very same July patch closes the Office and Windows holes on your everyday laptops and desktops. A single un-patched machine where someone opens an emailed spreadsheet can be all an attacker needs to get a foothold, then move to your files, QuickBooks, and email.

What to do this week

Install the July updates on every computer now: Start → Settings → Windows Update → Check for updates, then reboot when prompted (the fixes don’t fully apply until you restart). Update Office too — in any Office app go to File → Account → Update Options → Update Now. If any machine is still on Windows 10, know that it stopped getting free security updates in October 2025 — those PCs should be upgraded to Windows 11 or replaced, because they will not receive these fixes. Turn on automatic updates so you’re not doing this by hand each month (Settings → Windows Update → Advanced options). If you happen to run SharePoint Server or AD FS on-premises, patch those immediately or call us — those are the ones already under active attack.

The bigger picture

A record-breaking patch is a reminder that the number of flaws keeps climbing, and attackers move within days of each release to hit whoever hasn’t updated yet. Staying patched on a schedule is the cheapest, highest-return security work you’ll ever do — far cheaper than cleaning up after the one machine everyone forgot. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Confident every computer in your office actually installed this month’s updates? Book a free consult → https://micro1tech.com/contact/

Still Running Your Own SharePoint Server? A Ransomware Gang Is Hunting for It

Filed under: Cybersecurity · Ransomware · July 2026

What happened

A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities list on July 1 with a July 4 patch deadline for federal agencies — about as urgent as those deadlines get. The bug lets attackers run their own code on the server remotely, and at least one group exploiting it, Storm-2603, follows up by deploying Warlock ransomware. Important: this affects on-premises SharePoint Server only — SharePoint Online, the version included with Microsoft 365, is not affected.

Why it matters to your business

Plenty of small businesses had a SharePoint server installed years ago for file sharing and haven’t touched it since — which is exactly the profile this gang targets. An old server sitting in a closet, reachable from the internet, missing patches: that’s not a file server anymore, it’s a ransomware entry point. If you’re fully on Microsoft 365, you can relax on this one. If you’re not sure which you have, that uncertainty is itself the finding.

What to do this week

Ask one question: “Do we run SharePoint on our own server?” If yes, apply Microsoft’s latest SharePoint Server security update now — not at the next maintenance window — and check whether the server actually needs to be reachable from the internet at all. If the server is old enough that it no longer gets updates, it’s time to plan a migration to SharePoint Online, where Microsoft does the patching for you.

The bigger picture

Ransomware gangs don’t break in through your newest system — they scan for the oldest thing you forgot you owned. Once files are encrypted, options shrink fast; the only reliable recovery is never letting them in. Why the Only True Recovery from Ransomware Is Prevention

Do you know every server your business still runs — and who’s patching them? Book a free consult → https://micro1tech.com/contact/

If Your Office Network Runs on Ubiquiti UniFi Gear, Patch It Now

Filed under: Cybersecurity · Network Security · July 2026

What happened Hackers are actively exploiting three maximum-severity flaws in Ubiquiti’s UniFi OS — the software running popular small-business network gear like the Dream Machine, Cloud Gateways, and Cloud Keys (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). All three scored a perfect 10 out of 10: an attacker who can reach the device doesn’t need a password to take it over completely. CISA added them to its Known Exploited Vulnerabilities list on June 23 and gave federal agencies just three days to patch — its most urgent deadline.

Why it matters to your business UniFi is everywhere in small offices — it’s affordable, capable gear, and plenty of Phoenix businesses run their whole network on it. The catch: the box that controls your Wi-Fi and internet is exactly what you don’t want an attacker owning. From there they can watch traffic, redirect it, and reach every computer behind it — and network equipment rarely gets updated after installation, because nobody’s reminded to.

What to do this week Log into your UniFi console and check the firmware version under Settings → System (or Updates). Dream Machines, Cloud Gateways, Cloud Keys, and similar hardware need UniFi OS 5.1.12 or later; a standalone UniFi OS Server install needs version 5.0.8 or later. While you’re in there, turn on automatic firmware updates and make sure the management interface isn’t exposed to the open internet. Not sure what brand your network runs on? That’s worth finding out today.

The bigger picture Firewalls and routers only protect you while they’re current — a network device with a known, actively exploited hole is an open door, not a defense. Someone needs to own the job of keeping them patched. → [Proactive vs. Reactive IT Management]

Do you know who last updated your office router — or when? Book a free consult → https://micro1tech.com/contact/