Ubiquiti Bulletin 067: patch UniFi OS, Protect, Access, and Talk now
Ubiquiti's August 2026 advisory covers 22 UniFi vulnerabilities. Here are the affected products, fixed versions, real risks, and a practical update checklist.
26 articles
Ubiquiti's August 2026 advisory covers 22 UniFi vulnerabilities. Here are the affected products, fixed versions, real risks, and a practical update checklist.
Chrome, Edge, and Apple Passwords are useful autofill stores, but they are not a shared business vault for payroll, banking, or infrastructure logins.
An operator’s opinion: why 1Password is my default for personal use and small businesses, including the isolated Families account that comes with Business and MSP-provisioned seats.
CVE-2026-64531 is a local privilege escalation in the Linux Open vSwitch datapath with a public PoC. Who is exposed, which stables are fixed, and what to do today.
Hugging Face and OpenAI documented an autonomous model crossing evaluation and production boundaries. Lessons on sandboxing, local forensics, and data-processing attack surface.
A realistic endpoint baseline for small businesses: patching, MFA, EDR, backups, and least privilege, without pretending you need a Fortune 500 stack.
Microsoft's 663-CVE July 2026 release reflects AI-assisted vulnerability discovery. What MSPs and SMBs should change in triage without freezing from volume anxiety.
A practical way to rank vulnerability work using exposure, exploitation evidence, business impact, and change risk instead of CVSS alone.
A practical first sixty minutes for scoping an incident, stopping active harm, preserving evidence, securing identity, and giving leadership facts instead of guesses.
How small IT teams store shared admin passwords and API keys in a password manager without Spreadsheet-of-Doom habits.
Aggressive block lists feel productive until legitimate mail vanishes. How to tighten filtering without losing invoices, MFA codes, and vendor threads.
Standing VPN accounts for vendors age badly. Just-in-time access with time bounds and approval beats a shared tunnel nobody reviews.
Inventory service identities, replace passwords where possible, and rotate remaining secrets without breaking the workloads that depend on them.
Anthropic's April 2026 Project Glasswing put Claude Mythos Preview to work finding critical flaws with major vendors. What that means for downstream patching at ordinary SMBs.
Why the CEO's mailbox is the first account that deserves FIDO2 or passkeys, not another SMS code.
A vendor-neutral VoIP toll-fraud baseline covering dial permissions, admin access, SIP exposure, alerts, logs, and incident response.
A practical same-day IT offboarding runbook for identity, sessions, SaaS, devices, shared secrets, and company data without deleting first and asking later.
How small businesses can recognize payment fraud, verify a request outside email, and respond quickly when money or a mailbox may be at risk.
Single sign-on is not free to roll out — but neither is password sprawl. How SMBs decide which apps get SSO enforced and which can wait.
A practical Google Workspace baseline for 10-50 users: enforced 2-Step Verification, safer administrators, controlled sharing, OAuth review, devices, and alerts.
When your PSA is full of noise, operators stop seeing real incidents. A practical filter list for SMB RMM alerting.
A practical escrow plan for BitLocker recovery keys in small businesses — so a lost PIN does not become a full disk wipe.
How to create and maintain emergency Microsoft 365 admin accounts so you can recover the tenant without leaving a permanent backdoor.
Emergency browser updates do not wait for Patch Tuesday. How SMBs should force Chrome updates, control extensions, and close the relaunch gap before attackers do.
A bad Falcon content update crashed millions of Windows systems. Here is what small IT teams should change without turning it into blame theater.
CVE-2024-3094 hit rolling Linux distros hard. Here is what happened, who was exposed, and the checks SMB teams should run.