The week in business IT & comms

Weekly Roundup · Week of 7 to 13 September 2026

The week in business IT & comms

Two of this week's stories are about scale and one is about small print. Microsoft published 974 security fixes in a single release, more than it has ever shipped in one month, and exactly two of them were already being used in attacks when they landed. The NCSC put a figure on something most business owners suspect but cannot measure, which is how much of their company already runs on AI tools nobody signed off. And Ofcom changed the test Openreach has to meet before price controls come off copper connections, which moves a date that sits quietly in a lot of business budgets.

14 September 2026
  1. 01
    Microsoft & Cloud

    Microsoft ships 974 security fixes in one Patch Tuesday, its largest ever

    Microsoft's September update covers 974 CVEs, a record by both The Register's and Infosecurity Magazine's count. Infosecurity put 119 at critical severity, with 723 in Windows and 111 in Office. Two were already being used in attacks: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack, each giving an attacker SYSTEM level access. The Register counted nine Exchange Server flaws in the same batch.

    Read the full story
  2. 02
    AI for Business

    The NCSC says 71 percent of UK employees use AI tools their employer has not approved

    A post published on 7 September by Simon B, a senior cloud researcher at the National Cyber Security Centre, defines shadow AI as AI technology that is not captured in an organisation's approved systems and processes. It cites Microsoft UK research finding that nearly three quarters of employees, 71 percent, have used AI tools their employer never approved. The NCSC's advice is to reduce the practice through culture and clear guardrails rather than try to block it.

    Read the full story
  3. 03
    The Switch-Off

    Ofcom drops the fibre coverage test for lifting copper price caps from 100 percent to 90

    In a statement published on 9 September, Ofcom decided to let Openreach exclude a fixed 10 percent of premises in an exchange area from the coverage requirement that removes price controls from copper based services. In practice the second copper retirement threshold is met at 90 percent ultrafast coverage rather than 100. The exclusions can only be applied from 1 April 2029, and the full requirement stands before then.

    Read the full story
  4. 04
    Cyber Security

    A phishing operation took 5,137 Microsoft 365 records, and switched passkeys off to do it

    Researchers at CloudSEK got inside the admin panel of a phishing-as-a-service operation known as BigBear and counted 5,137 stolen records tied to 461 organisations, including 1,032 plaintext passwords, 4,148 session cookies and 474 complete multi-factor bypasses. The Register reported on 8 September that the kit proxies Microsoft's real login flow through attacker infrastructure, and that its JavaScript disables FIDO2 and WebAuthn so victims fall back to SMS codes and app prompts the proxy can relay.

  5. 05
    Compliance & Data

    Peers push for personal liability for executives in the cyber bill, and lose

    On the second day of Grand Committee scrutiny, reported by The Register on 7 September, Baroness Kidron and Lord Clement-Jones argued for personal civil liability for senior executives under the Cyber Security and Resilience Bill. Cyber security minister Baroness Lloyd of Effra rejected it, pointing to maximum fines of £17 million or 4 percent of annual turnover and board level governance rules to come through secondary legislation. Baroness Harding, the former TalkTalk chief executive, argued for a 14 day interim report and a final one at a month.

  6. 06
    Connectivity & Broadband

    Devon wireless broadband kit maker Cambium Networks calls in the administrators

    ISPreview reported on 13 September that Cambium Networks Limited filed a notice of intention to appoint an administrator on 10 September. The company makes fixed wireless access and Wi-Fi hardware and has a UK research and development centre in Ashburton. Its US parent was delisted from Nasdaq in March over delayed filings, and its latest annual report flagged concerns about continuing as a going concern. ISPreview expects an impact on UK wireless broadband providers running Cambium hardware.

  7. 07
    Compliance & Data

    The EU's Cyber Resilience Act starts a 24 hour vulnerability clock that reaches UK manufacturers

    Article 14 of the Cyber Resilience Act took effect on 11 September. Any manufacturer of a product with digital elements sold into the EU, wherever it is based, now has to file an early warning within 24 hours of finding an actively exploited vulnerability or a severe incident, a detailed notification at 72 hours, and a final report at 14 or 30 days, all through ENISA's Single Reporting Platform. Maximum fines are €15 million or 2.5 percent of annual turnover.

What we’re watching

The patching work is the immediate one. Two flaws were already being exploited when September's fixes shipped, so those go before the other 972, and any Exchange server still on site now has nine fresh flaws on top of the mail blocking deadline we covered last week. Ofcom's copper decision sits a long way out at 1 April 2029, so the useful work this autumn is finding out which of your connections still run over copper rather than reacting to the date. The analogue phone switch-off runs on its own separate timetable and is not changed by that decision. The Cyber Security and Resilience Bill has more Lords stages to come, and peers have signalled that both personal liability and the reporting thresholds will be back. And on 14 September The Register reported that the government has begun moving 23 million GOV.UK One Login users off passwords and onto passkeys, after a trial covering more than 300,000 people, which is the same direction of travel as our advice on phishing. The BigBear research adds the wrinkle: attackers have started trying to switch passkeys off rather than beat them.

#WEARECOBALT

Got a question this raises?

If anything here makes you wonder where your business stands, ask us. We'll give you a straight answer for your setup, with no obligation.