Patch Tuesday & AI Security
Welcome to your weekly IT news roundup from itpick.co.uk — the quick, no-nonsense version of what happened in tech this week, and what it actually means for you.
Microsoft Just Dropped a Monster Security Update
This week Microsoft pushed out patches for a staggering 398 security vulnerabilities across Windows and its wider software ecosystem. To put that in perspective, a typical Patch Tuesday covers somewhere between 60 and 120 issues — so nearly 400 is a big one, even by Microsoft’s standards.
One of the vulnerabilities was already being actively exploited in the wild before the patch arrived, meaning real attackers were already using it against real people. Two others had been publicly disclosed before fixes were available, which gives anyone with bad intentions a head start.
If you’re running Windows at home or in your small business, the message is simple: update now, not later. Go to Settings > Windows Update and make sure everything is installed. If you’re the sort of person who clicks “remind me later” on update prompts, this is the week to break that habit.
It’s also worth thinking about your passwords while you’re doing a bit of digital housekeeping — a password manager like NordPass makes it easy to check whether any of your logins have been caught up in known data breaches.
What this means for you: Run Windows Update today — one of these 398 flaws was already being used against people before Microsoft even had a fix ready.
Australian Police Arrest Members of a Supply Chain Hacking Gang
Police in Australia have arrested two men, aged 21 and 23, suspected of being part of a cybercrime group called TeamPCP. The group is accused of running what authorities are calling the longest sustained software supply chain attack campaign ever recorded.
The basic idea behind a supply chain attack is nasty: instead of targeting you directly, criminals hide malicious code inside legitimate open-source software that developers download and use to build apps. If that infected code ends up in a tool you use — something you’d never think to question — your data can be stolen without you doing anything obviously wrong.
This particular group is alleged to have stolen from thousands of victims globally using this method. The arrests in Western Australia are a real win for law enforcement, but they’re also a reminder that the software you rely on every day has a long, complicated chain of contributors behind it.
For small business owners who use any kind of software — and that’s all of you — it reinforces why keeping software updated and sticking to reputable, well-maintained tools matters. It’s also worth having decent security software in your corner; Mac users in particular should look at something like Intego to catch threats that slip through.
What this means for you: Even trusted software can be tampered with at the source — keep everything updated and only install tools from reputable publishers.
AI Agents Are Getting Powerful. The Security Hasn’t Caught Up.
A handful of stories this week from the enterprise world converged on the same uncomfortable truth: AI agents — software that can make decisions and take actions on your behalf, rather than just answering questions — are being rolled out faster than the security frameworks around them are being built.
Researchers highlighted three distinct risk layers: agents being impersonated or granted too much access, agents drifting from their intended behaviour and accidentally leaking data, and a particularly unpleasant attack called memory poisoning, where bad inputs corrupt what an agent “remembers” and cause it to behave dangerously later on.
This might sound like an enterprise-only problem, but tools like AI writing assistants, smart scheduling apps, and productivity platforms — think Notion’s AI features or Grammarly’s suggestions — are steadily moving in this direction. The more autonomously an AI tool acts on your behalf, the more important it becomes to understand what permissions you’ve granted it.
What this means for you: Before connecting any AI tool to your email, documents, or calendar, take five minutes to check exactly what access you’re giving it.
That’s Your Week in IT
A bumper Patch Tuesday, an international cybercrime bust, and a growing conversation about whether AI tools are moving faster than the security controls around them — it’s been a busy week. The common thread, as ever, is that staying on top of updates and being thoughtful about the tools and permissions you use goes a long way. We’ll be back next week with more.