
Updated for 5 PM Eastern on July 20, 2026. Today's recap is useful for small businesses, home offices, and anyone who maintains a website or Windows fleet: attackers are moving on recently patched WordPress bugs, a critical ServiceNow AI Platform flaw is being reported as exploited, a healthcare billing vendor disclosed stolen data, Microsoft has an out-of-band Dell Windows fix, and OpenAI published new AI-safety research.
Quick Take
- Bad news: WordPress sites that missed last week's critical fixes are already being targeted.
- Bad news: ServiceNow customers should check emergency guidance for CVE-2026-6875 because exploitation is being reported.
- Bad news: Craneware says hackers stole a significant volume of customer data from a healthcare billing software environment.
- Good news: Microsoft's KB5121767 out-of-band update is meant to fix a limited Dell Windows 11 update problem tied to Intel IPF drivers.
- Good news: OpenAI's GPT-Red research is another sign that AI vendors are investing in robustness and safety testing, not only new features.
1. WordPress Sites Need A Real Patch Check
TechCrunch reported today that hackers are exploiting recently patched critical WordPress bugs, with security firms warning that vulnerable websites are being taken over in the wild. The affected version ranges reported by TechCrunch are WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1. WordPress enabled forced updates where possible, which is the right move for a bug class this serious, but forced updates are not a guarantee that every business website is safe.
Small business websites often have friction that breaks normal patch flow: managed hosting with delayed updates, old PHP versions, custom code, abandoned themes, security plugins that block background updates, staging sites that were never cleaned up, or owners who do not know who currently maintains the site. A patched WordPress core also does not automatically mean every plugin, theme, upload tool, form builder, or page builder is healthy.
What Customers Should Do
- Log in and verify the exact WordPress version, not just whether the dashboard says updates are available.
- Update plugins and themes, then remove anything inactive or abandoned.
- Check for new admin accounts, unfamiliar plugins, strange files in upload directories, and unexpected redirects.
- Make sure backups are stored outside the hosting account so a website compromise cannot erase the recovery path.
- If the website takes payments, collects medical or legal information, or receives customer forms, review recent submissions and server logs.
The local-business takeaway: a website is part of your IT environment. If attackers compromise it, they can damage reputation, steal leads, inject malware, abuse email reputation, or pivot into accounts that reuse passwords. Website patching belongs on the same checklist as Windows updates and backup checks.
2. ServiceNow AI Platform Exploitation Raises The Stakes For Workflow Systems
BleepingComputer's security feed reported today that attackers have begun exploiting a critical ServiceNow AI Platform vulnerability, tracked as CVE-2026-6875, according to threat intelligence company Defused. ServiceNow environments can hold support tickets, asset records, internal workflow data, approvals, automation hooks, and integrations into identity and business systems. That makes emergency patching important even for companies that do not think of ServiceNow as a public-facing product.
For smaller organizations, the lesson is broader than ServiceNow. Any SaaS workflow platform that touches tickets, devices, user accounts, approvals, or customer records should have an owner, an update path, and a short emergency-contact route. If nobody knows who owns the platform, patching slows down exactly when speed matters most.
- Confirm whether your organization uses ServiceNow, including vendor-managed or parent-company instances.
- Check vendor advisories and administrative notices for the CVE-2026-6875 fix path.
- Review integrations and API tokens tied to workflow automation.
- Watch for unexpected admin changes, new integrations, unusual ticket exports, and abnormal login patterns.
- Use conditional access and MFA for administrator roles wherever the platform supports it.
3. Craneware Breach Is A Reminder That Vendor Risk Is Real Risk
TechCrunch reported that healthcare billing software maker Craneware disclosed a cyberattack in which hackers stole a "significant volume" of customer data, plus a percentage of employee and partner records. Craneware's software is used by thousands of U.S. clinics, hospitals, and pharmacies. TechCrunch also noted that Craneware acquired Florida-based pharmacy software maker Sentry in 2021, which the company said had collected 147 million patient records over two decades.
The most important point for customers is that vendor breaches can expose data even when your own computers were never directly hacked. Billing, payroll, HR, document management, payment processing, appointment reminders, marketing tools, and help desk platforms can all hold sensitive business or customer information. A vendor security failure can still become your notification, compliance, customer-service, or fraud-prevention problem.
Questions To Ask After A Vendor Incident
- What exact data fields were stored with the vendor?
- Were passwords, API keys, tokens, billing records, medical data, or identity documents involved?
- Does the vendor have logs showing which customer records were accessed or exfiltrated?
- Do any connected credentials need to be rotated?
- Who is responsible for customer notices, insurance notices, legal review, and fraud-monitoring decisions?
The local-business takeaway: keep a simple vendor inventory. It does not have to be fancy. A spreadsheet with vendor name, login owner, data stored, renewal contact, MFA status, and emergency support contact is enough to save hours during a breach response.
4. Microsoft KB5121767 Is Good News For Affected Dell Windows 11 PCs
Microsoft's July 18 support note for KB5121767 says the out-of-band Windows 11 update addresses an issue affecting a limited number of devices with an Intel Innovation Platform Framework driver. Microsoft says the issue could cause changes in performance, power consumption, or system behavior after recent Windows updates. The earlier July 14 KB5101650 notes say the update had been temporarily unavailable for a limited number of Dell devices using Intel IPF drivers because of an incompatibility between the update and an Intel component.
This is a good example of why update management needs nuance. The correct answer is not "install every update instantly on every computer" or "avoid updates forever." The practical answer is staged patching: install security fixes on a test group first when possible, watch known-issue notes, pause only the machines that are actually affected, and then resume patching once a fix is available.
- If you have a Dell Windows 11 24H2 or 25H2 device that was blocked from the July update, check Windows Update for KB5121767.
- Do not manually force the OOB update onto unrelated systems just because the KB number is new.
- For business fleets, document which models had the issue and when the corrected update was applied.
- For home users, plug the laptop in, let Windows Update complete, and restart when prompted.
5. OpenAI's GPT-Red Research Is A Useful AI Safety Signal
OpenAI's news page lists GPT-Red: Unlocking Self-Improvement for Robustness Safety as recent safety research. This is not a product feature that home users need to turn on today. It matters because AI tools are moving into support desks, coding workflows, document review, sales operations, and family devices. Better robustness testing is one piece of making those tools less brittle.
For customers, the practical rule is still simple: use AI for drafts, summaries, troubleshooting help, and research support, but keep a human review step around account access, payments, legal decisions, healthcare decisions, security changes, and anything that could expose private data. A safer model does not remove the need for good workflow design.
Good And Bad News Summary
Good News
- Microsoft has a targeted out-of-band fix for affected Dell systems.
- WordPress forced updates where possible, reducing risk for many ordinary sites.
- AI safety research continues to mature around robustness and red-team methods.
Bad News
- Attackers are moving quickly against WordPress sites that missed critical fixes.
- Enterprise workflow platforms remain attractive targets because they hold operational data.
- Vendor breaches can expose sensitive records even when the customer's own computers are clean.
The IT Guys Checklist For Tonight
- Check your WordPress version, plugins, themes, and admin-user list.
- Confirm whether ServiceNow is in use and whether CVE-2026-6875 guidance applies.
- Review critical vendors that hold customer, healthcare, billing, payroll, or identity data.
- Install KB5121767 only where Microsoft or Windows Update offers it for affected Dell systems.
- Make sure backup copies are separated from the systems they protect.
- When using AI tools, keep secrets out of prompts and keep a human approval step for risky actions.
Sources
- TechCrunch: Hackers are exploiting recently patched WordPress bugs
- WordPress News
- BleepingComputer: Critical ServiceNow AI Platform flaw now exploited
- TechCrunch: Hackers stole data from Craneware
- Microsoft Support: KB5121767 out-of-band update
- Microsoft Support: KB5101650 release notes and Dell IPF issue
- BleepingComputer: Windows KB5121767 OOB update fixes Dell shutdowns
- OpenAI News: GPT-Red safety research
Need help checking a WordPress site, Windows update issue, vendor exposure, or backup plan? Contact The IT Guys and we can help sort out what actually applies to your setup.