This Week in IT: Microsoft Goes Solo on AI, VPN Zero-Day Attacks, and the AI Phishing Flood

⚠️ Some links on this site are affiliate links. If you buy through them, we earn a small commission at no extra cost to you. This never influences our reviews.

Welcome back to the itpick weekly news roundup — your no-nonsense digest of the tech stories that actually matter if you’re running a small business or just trying to keep your home setup safe and sane. It’s been a busy week. Let’s get into it.

Microsoft Steps Out of OpenAI’s Shadow

For the past few years, Microsoft’s entire AI story has basically been “what OpenAI is doing, but inside Office.” That’s changing. Microsoft AI chief Mustafa Suleyman made it clear this week that the company is now charting its own course towards artificial intelligence — including the long-term pursuit of so-called superintelligence — rather than simply riding on OpenAI’s coat-tails.

At Microsoft’s Build 2026 conference, the company also doubled down on AI agents — software that doesn’t just answer questions, but actually takes actions on your behalf, like booking meetings, pulling data from multiple systems, or managing workflows. The message was that these agents are moving from experiments into real, everyday business use.

For regular users, this is most visible in Microsoft Copilot, which is being woven deeper into Windows, Teams, and Microsoft 365. If you’re a small business using any Microsoft tools, expect AI to become a much bigger part of your daily workflow over the coming months — whether you opt in consciously or not. Tools like Notion are also pushing hard in this space, so it’s worth keeping an eye on how AI assistants are evolving across the productivity landscape.

What this means for you: AI is moving from novelty to infrastructure — it’s worth starting to think about how your business might actually use (or misuse) these tools before they’re switched on by default.

Critical VPN Flaw Exploited by Ransomware Gang

This one’s important. Check Point — a well-known cybersecurity firm — disclosed a serious vulnerability in its own Remote Access VPN and Mobile Access products this week. The flaw was already being actively exploited in the wild before a patch was available, meaning attackers got there first. The attacks have been linked to the Qilin ransomware group, which has been making a name for itself hitting organisations across various sectors.

Zero-day exploits — where attackers take advantage of a flaw before the software maker can fix it — are particularly nasty because there’s no warning and no patch to apply until the vendor catches up. In this case, Check Point has now released security updates, so if you or your business uses their VPN products, patching immediately is the priority.

This is also a good reminder that VPN software itself needs to be kept updated, not just the devices connecting through it. If you’re using a consumer VPN service like NordVPN or Surfshark rather than self-managed VPN infrastructure, your provider handles security updates on their end — but it’s still worth checking that your VPN app is running the latest version.

What this means for you: If you use Check Point’s VPN products, update them right now. And make sure whatever VPN solution you rely on — business or personal — is set to update automatically where possible.

AI Is Flooding Your Inbox with Better Phishing Emails

Phishing attacks have always relied on volume — send enough dodgy emails and someone will eventually click. The problem now is that AI has made it dramatically easier to produce convincing, well-written, personalised phishing messages at scale. Security teams are reporting that the sheer number of suspicious emails is overwhelming their ability to review them — which is, of course, exactly what attackers are counting on.

Whereas a phishing email once might have been spotted by its clunky grammar or obvious template feel, AI-generated lures are polished and tailored. They can mimic the tone of a genuine supplier, reference real details, and adapt to specific targets. For small businesses without a dedicated security team, that’s a significant threat.

Good habits remain your first line of defence: use a password manager like NordPass so that even a successful phishing attempt can’t compromise multiple accounts, enable two-factor authentication everywhere, and treat any unexpected email asking you to click or log in with genuine suspicion.

What this means for you: AI-powered phishing is no longer just a big-business problem — stay sharp, and make sure your team knows that even well-written, professional-looking emails can be fake.


That’s Your Week in IT

Microsoft is staking out its own AI future, ransomware gangs are jumping on unpatched VPN flaws before businesses have a chance to react, and phishing emails are getting harder to spot by the day. It’s a lot — but staying informed and keeping your software updated goes a long way. We’ll be back next week with more of the same. Stay safe out there.


Further Reading

Microsoft AI VPN ransomware phishing cybersecurity Copilot