IT News Roundup: Record Microsoft Patches, SonicWall VPN Attacks, and AI Security Tools
Welcome back to another week in IT — and what a week it’s been. If you’ve been busy getting on with actual work, here’s everything that matters, in plain English, no jargon required.
Microsoft Just Patched a Staggering 570 Security Flaws
Let’s start with the big one. Microsoft’s latest Patch Tuesday update fixed a jaw-dropping 570 security vulnerabilities across Windows and its wider software catalogue. To put that in perspective, last month’s update was already considered record-breaking — this one is nearly triple the size of that.
What’s driving the surge? Microsoft says artificial intelligence is helping its researchers find vulnerabilities far faster than before. That’s genuinely good news for the long term, but in the short term it means an awful lot of patching to do.
If you’re running a Windows PC or laptop — and the vast majority of UK home users and small businesses are — you’ll want to make sure your machine has picked up the latest updates as soon as possible. Go to Settings > Windows Update and hit “Check for updates” if it hasn’t run automatically. Don’t put it off.
What this means for you: Unpatched Windows machines are a hacker’s favourite target, so getting this update installed promptly is one of the most important things you can do for your security this week.
SonicWall VPN Devices Were Attacked Before Anyone Knew They Were Vulnerable
This one’s a little more technical, but it’s worth knowing about if your small business uses a VPN appliance to let staff connect remotely. Researchers have confirmed that a previously unknown threat actor — dubbed UTA0533 — was actively exploiting serious flaws in SonicWall’s SMA 1000 series VPN devices before the vulnerabilities were even publicly disclosed. These are so-called “zero-day” attacks, meaning the attackers knew about the weaknesses before the manufacturer did.
The attacks, which began as far back as late June, could give an intruder root-level access to affected devices — essentially handing them the keys to the kingdom.
If your business uses SonicWall SMA 1000 hardware, check with your IT supplier or support contact immediately to confirm you’re running the latest patched firmware. For smaller operations using software-based VPN solutions — consumer-grade services like NordVPN or Surfshark are a world away from enterprise appliances like these, and don’t carry the same risks — but this is a good reminder that any VPN setup needs to be kept up to date.
What this means for you: If you manage a SonicWall VPN appliance, treat this as urgent — patch now and check your access logs for anything suspicious.
Capital One Releases a Free AI Tool That Hunts for Code Vulnerabilities
On a more positive note, Capital One has open-sourced an internal security tool called VulnHunter, now freely available on GitHub. The tool uses agentic AI to scan source code, work out how an attacker might exploit any weaknesses it finds, and suggest fixes — all before the software is ever released to users.
It’s aimed squarely at developers rather than everyday users, but it’s a significant moment for the security world. Making this kind of sophisticated analysis freely available means smaller development teams and independent software creators can now benefit from the sort of security testing that was previously only accessible to large enterprises with deep pockets.
If you run a small business that builds or customises software in-house, this is well worth keeping an eye on.
What this means for you: Free, high-quality security tooling becoming available to smaller teams is great news — better-tested software means fewer vulnerabilities reaching the products you use every day.
Dodgy Supply Chain Attack Targets Ruby Developers
Finally, a quieter but important story for anyone who works with software development. Researchers uncovered an attack campaign called SleeperGem, in which malicious packages were published to RubyGems — a popular repository of code libraries used by developers working in the Ruby programming language. The fake packages were designed to look legitimate and, once installed, could deliver harmful payloads to a developer’s machine.
This is a reminder that even the tools developers use to build software can be tampered with. If your small business relies on developers or freelancers, it’s worth asking whether they follow safe dependency management practices.
What this means for you: Software supply chain attacks are on the rise — encourage any developers you work with to verify packages carefully before adding them to a project.
That’s your week in IT. Between a record-breaking Microsoft patch drop, active VPN exploits in the wild, and some genuinely exciting developments in AI-assisted security, it’s been a full-on seven days in the tech world. Stay patched, stay cautious, and we’ll see you next week.