The week in business IT & comms

Weekly Roundup · Week of 21 to 27 September 2026

The week in business IT & comms

Two dates set the week and neither of them is 31 January. Openreach confirmed on 24 September that lines still on the old phone network after the switch off may be moved to its last-resort EVAc service, which will now carry broadband where it can, at £35 a month wholesale before your provider adds anything. The same day ISPreview reported that Vodafone has told its wholesale partners that migration orders placed after 30 September cannot be guaranteed to complete before the old service is ceased. Elsewhere, Microsoft pulled an optional Office update that left some Office 2016 and 2019 machines unlicensed or without Office at all, and the Met made two arrests over a phishing kit that took over 12,000 Microsoft 365 inboxes without ever needing a password.

28 September 2026
  1. 01
    The Switch-Off

    Openreach confirms the safety net for lines that miss 31 January, and it now carries broadband

    Openreach said on 24 September that customers who have not moved to a digital service by 31 January 2027 may be transferred to EVAc, a limited last-resort phone service, and that where technically possible it will now keep linked broadband running on ADSL, FTTC and G.fast lines. It will cost communications providers £35 a month for WLR3 Basic and £38.60 for WLR Premium, cannot be ordered in advance, and capacity cannot be reserved. Openreach now puts the lines still on the old network at around 1.2 million, including around 350,000 business premises. The closure date is unchanged.

    Read the full story
  2. 02
    The Switch-Off

    Vodafone's wholesale partners have a cut-off of 30 September, not January

    ISPreview reported on 24 September that Vodafone, as a wholesale supplier to other providers, has brought its own legacy withdrawal forward to 1 October 2026, and that migration orders submitted after 30 September cannot be guaranteed to complete before the existing service is ceased. Vodafone told ISPreview the aim is to reduce the risk from ageing PSTN equipment that is harder to maintain and more prone to faults, and that formal service withdrawal and cease notifications begin in October, subject to contract terms and customer protections. It applies to Vodafone's wholesale partners, not its own consumer base.

    Read the full story
  3. 03
    Cyber Security

    Two arrests and 50 seized websites as Microsoft takes down a phishing service that skipped MFA on 12,000 inboxes

    Microsoft announced on 22 September that it had disrupted EvilTokens, a phishing-as-a-service platform launched in February and linked to more than 12,000 compromised inboxes across over 10,000 organisations. It used device code phishing, which gets a victim to type a code into Microsoft's real sign-in page and hands the attacker a working session without a password. Microsoft seized 50 websites and disabled more than 150 supporting domains, and the Metropolitan Police arrested two men, aged 32 and 38, on 11 September. The UK was among the countries with the most victims.

    Read the full story
  4. 04
    Microsoft & Cloud

    Microsoft pauses KB5002907 after it deactivated, and in some cases removed, Office 2016 and 2019

    Microsoft confirmed on 26 September that it has paused KB5002907, an optional update meant to bring Microsoft 365 Apps installations more than 90 days out of date back onto a current build. BleepingComputer reported that it also landed on bought-outright Office 2016 and 2019 installs, leaving them showing as an unlicensed product and in some cases removing Office entirely. Microsoft's support page now says reactivate with the original licence, or reinstall where the product was removed. Both versions left support on 14 October 2025.

    Read the full story
  5. 05
    Cyber Security

    Citrix confirms two NetScaler zero-days are being exploited, one of them in the default configuration

    Citrix published security bulletin CTX697096 on 27 September confirming that CVE-2026-88771 and CVE-2026-88772, both scored 9.5, are being exploited on unpatched NetScaler ADC and NetScaler Gateway appliances. The first affects every deployment, including the default configuration, and needs no authentication. BleepingComputer reported that administrators had been told by suppliers and national cyber agencies to shut appliances down before the patches existed. Fixed builds are 14.1-73.37 and 13.1-64.23, and the bulletin fixes six further flaws. BleepingComputer's advice for anyone who cannot patch at once is to reduce the appliance's exposure to the internet.

  6. 06
    Cyber Security

    Ransomware hit a 2026 high in August, and a new gang is threatening to destroy backups

    NCC Group's monthly threat report, published on 23 September, counted 1,073 ransomware attacks in August, a record for the year and up 12 per cent on July, with Europe taking 26 per cent of them. Its UK example was Manchester Airports Group, which suffered a customer data leak across car park, lounge, fast track and airport WiFi systems. Separately, Infosecurity Magazine reported on 24 September that a new group called n0n, first seen on 18 September, gets in with credentials stolen by infostealer malware and then threatens to encrypt or destroy backups and shadow copies unless it is paid.

  7. 07
    Telephony & VoIP

    Ofcom opens investigations into Vonage and Voxbone over phone numbers used for scams

    Ofcom said on 24 September it has opened separate investigations into Vonage Business Limited and Voxbone SA over concerns that numbers allocated to them are being misused, including to run scams. It expects providers to carry out know-your-customer checks on business customers before handing over numbers, to keep monitoring for misuse, and to act on reports. The investigations will test compliance with General Condition B1. ISPreview does not expect an outcome before late spring 2027.

What we’re watching

The date that matters most is 1 October. Openreach's July price schedule takes the WLR basic rental up by a further 40 per cent on that day, to double what it was at the start of the year, and Vodafone's wholesale withdrawal starts the same day, so anything still on a copper phone line costs more from 1 October and, with some providers, can no longer be guaranteed a migration slot. Microsoft says further guidance on KB5002907 will come through its usual channels; if there is Office 2016 or 2019 in the building, find the licence details before you need them. Citrix customers should be on the fixed NetScaler builds by now; for anyone who cannot patch yet, BleepingComputer's advice is to cut the appliance's exposure to the internet. Ofcom also published its first look at AI in telecoms customer service on 25 September: 8 per cent of online adults have used an AI tool to deal with their phone or broadband provider, and Ofcom's stated expectation is that customers are always told when they are talking to AI and never blocked from reaching a person. And if your website runs on WordPress with the Elementor plugin, versions 4.3.0 and 4.3.1 carry a flaw that lets one clicked link create an admin account; 4.3.2 fixes it.

#WEARECOBALT

Got a question this raises?

If anything here makes you wonder where your business stands, ask us. We'll give you a straight answer for your setup, with no obligation.