Tonight’s technology news is a reminder that speed without control is just a faster way to create risk. CISA has added an actively exploited remote-management flaw to its urgent catalog, Britain is openly weighing stronger AI rules, Microsoft’s agent-based security platform entered public preview, and large organizations are placing fresh bets on AI chips and cloud consolidation. Here is The IT Guys’ source-backed 5 PM recap for Monday, August 3, 2026.
🎧 Listen to the recap
Locally synthesized narration by Jennifer Hudsen for The IT Guys.

Tonight in 60 seconds
CISA says CVE-2026-18577 is being exploited; N-able says every N-central instance below 2026.3.1 is affected.
The government says regulation remains an option if voluntary predeployment testing stops protecting the public.
Project Perception entered public preview with red-, blue-, and green-team security agents.
OLIX received government equity backing as it develops specialized inference hardware.
ArcelorMittal is expanding its Microsoft cloud stack around Azure, Fabric, Purview, and Foundry.
Apple says all 62 Leagues Cup matches will stream on Apple TV beginning August 4.
1. CISA flags an exploited N-able N-central authentication bypass
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3. The flaw affects N-able N-central, a remote monitoring and management platform used by managed service providers to administer many customer devices. CISA describes it as an authentication bypass that can lead to account takeover and says it resulted from an incomplete fix for the earlier CVE-2026-18556.
That is an especially uncomfortable product category for a security failure. A remote-management console is designed to reach many systems at once. If an attacker takes over the console, the same centralized access that makes support efficient can increase the blast radius.
CISA set an August 6 remediation due date for federal civilian agencies covered by its directive. That deadline is not a universal legal deadline for every private organization, but the catalog’s inclusion is a strong signal to prioritize the issue. CISA lists known ransomware-campaign use as unknown; do not translate “known exploited” into “confirmed ransomware” without additional evidence.
N-able also published investigation indicators. It recommends checking device users’ Documents folders for a file named svchost.exe, looking for a service named Cloudflared, and reviewing firewall logs for inbound connections from the IP addresses in its advisory. Those indicators are not a substitute for patching, and a clean search does not prove an environment was never accessed.
- Good: CISA and the vendor supplied a named CVE, a fixed build, an urgent timeline, and concrete investigation leads.
- Bad: The vulnerability bypasses authentication in a high-trust management platform, and the first patch was incomplete.
- Caution: Upgrade first, preserve relevant logs, then investigate. Do not delete suspicious files before collecting evidence or disconnect a management server in a way that destroys volatile data without an incident plan.
If a ransom note or lock screen is already present, use The IT Guys’ first-15-minutes ransomware checklist: isolate safely, preserve evidence, avoid improvising with attacker instructions, and bring in qualified help.
2. Britain says AI regulation remains an option if voluntary safeguards fall short
Britain’s AI Minister Kanishka Narayan told Reuters that the government would consider regulating advanced AI models if its current voluntary approach to predeployment testing no longer proved sufficient to protect the public.
For now, Britain has no single dedicated AI regulator. Existing authorities cover areas such as competition, human rights, health, and safety. The country’s AI Security Institute receives early access to frontier models under voluntary agreements with developers including OpenAI, Anthropic, and Google, allowing it to evaluate capabilities and risks before wider deployment.
The timing matters. Recent disclosures from major AI companies have made evaluation boundaries, agent autonomy, and real-world access more concrete public concerns. Britain’s approach sits between the United States’ generally lighter federal posture and the European Union’s more prescriptive AI Act.
- Good: Predeployment access can expose risky capabilities before they reach ordinary users, and an outcomes-focused review can adapt faster than a rigid checklist.
- Bad: A voluntary system depends on sustained cooperation, adequate technical access, and enough public transparency to establish trust.
- Uncertainty: There is no announced threshold for deciding voluntary safeguards have failed, and no proposed replacement structure yet.
For businesses: do not wait for a national AI law to establish basic governance. Keep an inventory of approved AI tools, define what data may be uploaded, require human review for consequential outputs, document third-party integrations, and maintain a way to revoke an agent’s credentials quickly.
3. Microsoft’s Project Perception enters public preview
Microsoft’s Project Perception entered public preview on August 3. The company describes it as an agent-based security system that continuously combines signals, context, models, and specialized agents to identify risk and move from investigation toward protection.
The design organizes work into three roles: red-team agents search for paths to compromise, blue-team agents investigate and prioritize meaningful risk, and green-team agents take corrective actions intended to strengthen the environment. Microsoft says humans remain in control while the system handles machine-speed correlation and repetitive work.
Microsoft also says its MAI-Cyber-1-Flash configuration achieved 96% on the CyberGym benchmark, 12 points above Mythos, while delivering nearly 50% cost savings compared with the current MDASH configuration. Those figures are useful release data, but they are vendor-reported benchmark and cost results—not a guarantee that a customer’s alerts will be 96% correct or that every deployment will cut costs in half.
- Good: Coordinated agents could reduce repetitive triage and help defenders connect identity, endpoint, cloud, data, and application signals.
- Bad: Automated remediation can magnify a bad decision; a mistaken isolation or access change can become an outage.
- Caution: “Public preview” means evaluate—not blindly standardize. Preview support terms, feature behavior, pricing, and data-handling details can change.
4. The UK backs OLIX in the race for specialized AI chips
The UK government’s Sovereign AI venture fund announced an equity investment in OLIX, a London-based startup with offices in Bristol that is developing specialized inference chips. The backing is part of a nine-figure fundraise announced July 30.
The government describes OLIX as one of Britain’s newest “unicorns,” meaning a private valuation above $1 billion, and says the company raised a $220 million Series A earlier in 2026. OLIX is the fifth startup to receive a Sovereign AI equity investment since the program launched.
OLIX’s pitch is to divide inference work among chips specialized for different parts of a model’s processing—more like a coordinated production line than one general-purpose processor doing everything. The intended outcome is lower cost, better performance, and lower energy use.
- Good: More hardware competition could reduce dependence on a small number of suppliers and encourage architectures tuned for real-world inference rather than only model training.
- Bad: Chip startups face long development cycles, expensive fabrication, software-ecosystem demands, and the brutal gap between a promising design and volume deployment.
- Caution: The energy and performance benefits are claims and objectives until reproducible third-party benchmarks and deployed systems exist.
Why small businesses should care: inference efficiency eventually influences the price and availability of AI features in cloud services, PCs, phones, cameras, and business software. The investment is not an immediate reason to delay a purchase, but it is another sign that the next AI competition is as much about power, cooling, memory, and silicon as it is about chatbots.
5. ArcelorMittal expands its Microsoft cloud partnership
ArcelorMittal said it is expanding its work with Microsoft under a “Cloud First, Data Centric” strategy that uses Azure as its primary cloud platform. Reuters reports that the steelmaker plans to integrate Microsoft Fabric, Purview, and Foundry to modernize systems, improve cybersecurity, and reduce reliance on legacy technology. Financial terms were not disclosed.
The product list shows the shape of many enterprise projects: Fabric for data and analytics, Purview for data governance and compliance, Foundry for building and managing AI applications, and Azure as the underlying cloud platform. Consolidation can reduce fragmented tooling, but it also increases the importance of identity design, service dependencies, and exit planning.
- Good: A coordinated data, governance, AI, and infrastructure stack can replace brittle point-to-point systems and improve visibility.
- Bad: A single-vendor concentration can turn one identity, billing, region, or policy failure into a broad operational problem.
- Unknown: The announcement provides no financial terms, migration schedule, measured security result, or return-on-investment figure.
6. Apple turns the Leagues Cup into a 62-match streaming test
Apple says all 62 Leagues Cup matches will stream live on Apple TV beginning August 4. The tournament includes 18 Major League Soccer clubs and 18 Liga MX clubs, with viewers in more than 100 countries and regions able to watch every match through Apple TV. Commentary will be available in English, Spanish, and French where offered.
This is consumer technology as much as sports news. Live events stress home Wi-Fi, streaming devices, account authentication, content-delivery networks, and support systems in ways that on-demand video does not.
- Good: One service carrying the complete tournament simplifies discovery, and Apple says there will be no need to hunt across multiple packages for individual matches.
- Bad: “Available in more than 100 countries” does not mean every viewer has the required subscription, device compatibility, bandwidth, or preferred commentary for every match.
- Tonight’s setup tip: update the Apple TV app and streaming device, sign in before kickoff, test one live stream, and use wired Ethernet or strong 5/6 GHz Wi-Fi when possible.
The IT Guys practical action list
- N-central operators: confirm the actual server build now. Move self-hosted systems to 2026.3.1.7 and preserve logs before aggressive cleanup.
- Review remote-management trust. Require multifactor authentication, restrict administrative source networks, remove stale technicians, separate tenant roles, and alert on new privileged accounts.
- Put AI tools on an inventory. Record owners, data access, credentials, integrations, output-review rules, and an emergency-disable path.
- Treat agentic security as a controlled pilot. Start read-only, require human approval for remediation, and test rollback.
- Test one restore before trusting a dashboard. Use our one-file restore checklist.
- Windows and Apple users: keep the month-ahead plan handy. Our August 2026 Windows and Apple update preview separates released fixes from previews and expected cadence.
FAQ
Does CISA’s catalog entry mean every N-central server was hacked?
No. It means CISA has evidence the vulnerability is being exploited in the wild. Exposure and compromise are different questions. Patch urgently, then investigate using vendor indicators, authentication records, firewall logs, administrative-account changes, and qualified incident-response procedures.
Is CVE-2026-18577 confirmed ransomware?
CISA lists known ransomware-campaign use as “unknown.” Do not make that leap without incident-specific evidence.
Did Britain announce a new AI law today?
No. The AI minister said regulation is an option if voluntary safeguards no longer protect the public. No bill, final rule, implementation date, or dedicated AI regulator was announced in the Reuters interview.
Can Microsoft Project Perception automatically fix security problems?
Microsoft describes green-team agents that can take corrective actions, but preview deployments should begin with narrow permissions and human approvals. The safe level of automation depends on the environment, the action, available rollback, and evidence quality.
Does OLIX already have independently proven faster and cheaper AI chips?
The government and company describe that as the design objective. Tonight’s public evidence establishes the investment, valuation claims, funding history, and proposed architecture—not independent production benchmarks.
Do I need a separate MLS package for the Leagues Cup?
Apple says Apple TV subscribers can watch all 62 matches. Check Apple’s current local offer, subscription status, supported device, and regional availability before kickoff rather than assuming an old sports package or trial still applies.
More from The IT Guys
Catch up on Sunday’s 5 PM technology recap, which covered AI evaluation boundary failures, Chrome’s AI-assisted security work, a Windows Insider certificate deadline, cloud-infrastructure spending, and Minnesota’s AI-image law.
Sources checked
- CISA — Known Exploited Vulnerabilities catalog JSON, version 2026.08.03
- N-able — N-central 2026.3 Hotfix 1 mitigation for CVE-2026-18577
- Reuters — Britain says it is open to AI regulation if voluntary safeguards fall short
- Microsoft — Rethinking security for the age of AI
- GOV.UK — Sovereign AI invests in UK startup reinventing AI chips
- Reuters — ArcelorMittal expands Microsoft partnership on cloud
- Apple — Leagues Cup kicks off August 4 on Apple TV
Reporting note: Sources were checked August 3, 2026, in America/New_York. Company and government claims are labeled; practical implications and cautions are The IT Guys’ analysis. Reuters pages were cited canonically and read through identifiable syndication where automated device checks blocked the direct page.
