
Weekly Roundup · Week of 31 August to 6 September 2026
The week in business IT & comms
Three of this week's stories are about things that happen without anyone in your business deciding anything. Microsoft raises the minimum patch level for Exchange servers sending mail into Microsoft 365, and mail from anything older starts getting throttled and then blocked. A phishing platform keeps producing new pages a month after the FBI seized its servers, and the pages ask for your multi-factor code while an operator watches. And in the Lords, a bill that will put managed IT providers on a 24 hour incident reporting clock moved a step further, with almost no coverage of the part that reaches ordinary customers.
- 01Microsoft & Cloud
Microsoft starts blocking mail from out-of-date Exchange servers
From the second week of September, Exchange Server 2016 and 2019 machines that send mail to Exchange Online over an inbound connector of the OnPremises type have to be patched to at least the final public update, released in October 2025. Microsoft announced it on 2 September and said the update level was released almost a year ago and all organisations should have updated to it. Older servers get throttled, then blocked.
Read the full story - 02Cyber Security
A phishing kit that intercepts MFA codes is still running a month after an FBI-led takedown
Group-IB published research on 3 September into the Outsider phishing kit, a phishing-as-a-service platform whose adversary-in-the-middle features let operators serve SMS, email, PIN or app-based MFA challenges live. Researchers counted more than 100,000 phishing pages across 54 or more countries between December 2025 and May 2026, and more than 700 new pages in the month after Google's civil lawsuit and the FBI-coordinated Operation Ghost Hook.
Read the full story - 03Compliance & Data
Peers lose the AI argument over the Cyber Security and Resilience Bill
In Lords Grand Committee on Tuesday 1 September, cyber security minister Baroness Lloyd of Effra rejected amendments that would have brought AI vendors into the scope of the Cyber Security and Resilience (Network and Information Systems) Bill, pointing instead to the AI Security Institute and a voluntary code of practice. The bill still extends the regime to managed service providers, data centre operators and designated critical suppliers.
Read the full story - 04Telephony & VoIP
Gamma's board backs a £1.079bn cash offer from Epiris
On 1 September the business comms and IT provider Gamma Communications said its board and Bradbury Bidco Limited, a vehicle formed by funds managed or advised by the private equity firm Epiris, had reached agreement on the terms of a recommended cash offer. It values Gamma's share capital at about £1,015 million, with an implied enterprise value of about £1,079 million, and is expected to complete during the first half of 2027.
- 05Connectivity & Broadband
Broadband provider iTalk files notice to appoint an administrator
ISPreview reported on 3 September that iTalk Affiliate Telecommunications had filed a notice to appoint an administrator on 28 August, after months of customer complaints about outages and support. Telecom Acquisitions Group, whose CEO Nigel Barnett said suppliers had given assurances that no service should be affected in the short term, has begun talks with the administrators. Andrew Pear and Richard Keley of Moorfields Advisory were appointed on 4 September.
- 06Cyber Security
A group calling itself FulcrumSec claims the Manchester Airports Group breach
Infosecurity Magazine reported on 2 September that FulcrumSec had claimed responsibility for the breach MAG confirmed on 27 August, saying it took 549GB of data covering 8.7 million customer profiles, 108,000 vehicle registration plates and 191,000 future bookings. It said it obtained admin keys for a customer engagement platform from JavaScript on the airports' own websites. MAG has not updated its original statement and the claims remain unverified.
- 07Cyber Security
SonicWall says two chained zero-days in its SMA1000 remote access boxes are under active attack
CVE-2026-83548 is a pre-authentication server-side request forgery flaw carrying a CVSS v3 score of 10.0, and CVE-2026-83549 is a post-authentication command injection issue rated 7.8. They affect SMA 6210, 7210 and 8200v appliances. Hotfixes are out and there are no workarounds. NHS England's National CSOC said it assesses future exploitation of the flaws as almost certain.
What we’re watching
The Exchange change lands this week, so if anyone in your business still runs a server on site, the next few days are when you find out. The Gamma sale is not settled either: the Sunday Times reported on 6 September that the Dutch private equity firm Waterland plans to table a larger bid, which would involve selling two of Gamma's SME divisions to Giacom. Grand Committee scrutiny of the Cyber Security and Resilience Bill resumes, with peers signalling that the AI question will come back at a later stage. On the network side, Openreach has extended the pilot of its EAD 2.0 and Cablelink Service Connect products to 30 November, with pilot order deadlines of 12 October and 2 November, and a commercial launch still expected in December. In the background the analogue phone network still switches off on 31 January 2027, with no fallback service for business lines.
#WEARECOBALT
Got a question this raises?
If anything here makes you wonder where your business stands, ask us. We'll give you a straight answer for your setup, with no obligation.