AI and IT News Recap: September 16, 2026: A ScreenConnect Flaw Under Attack Puts a Three-Day Clock on IT Teams, Google's Gemini Learns to Think Out Loud, and a Plugin Update Ships a Back Door
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 16, 2026

Wednesday's AI and IT news is heavy on things that need doing today rather than things to think about later. A remote support tool used across half the managed IT industry is being exploited in the wild with a federal patch clock already running, Google shipped a new pair of voice models, and a WordPress plugin vendor spent Monday unknowingly shipping a back door to its paying customers.
📌 The AI and IT news at a glance
- A critical ConnectWise ScreenConnect flaw is under active attack, and CISA gave federal agencies three days to patch.
- Google shipped Gemini 3.8 Live and 3.8 Live Extended Thinking, its most capable voice models yet.
- Google patched an actively exploited Pixel zero-day among 110 September Android flaws.
- Ransomware gangs have joined the attacks on a VMware vCenter bug patched back in July.
- A compromised plugin vendor pushed a back door to roughly 230 WordPress customers.
- Acronis says a flaw in its cPanel and Plesk backup plugin may already be exploited.
- September's Office update is silently breaking copy and paste in Excel.
- Windows Server 2022 leaves mainstream support on October 13.
- Profound raised 80 million at a.8 billion valuation for getting brands into AI answers.
- BloombergNEF nearly doubled its forecast for US data center natural gas demand.
- Two new hotlines give AI agents a way to report other AI agents.
- Meta shipped an MCP server so a coding agent can set up WhatsApp Business for you.
🔝 Top story: the remote support tool that is being used against you
A critical ScreenConnect flaw is under attack, and the federal clock is at three days
CISA confirmed that attackers are actively exploiting a critical vulnerability in ConnectWise ScreenConnect, the remote support software that a very large share of managed service providers and internal IT teams use to reach employee machines. The flaw, now tracked as CVE-2026-84869, is a combination of improper privilege management and missing authorization affecting ScreenConnect clients. An attacker who already holds only basic privileges can use it to transfer and execute files, in a low-complexity attack that requires no user interaction and no one clicking anything.
The timeline matters here. ConnectWise published temporary mitigation guidance on September 7, advising teams to disable TransferFiles permissions to cut off the attack path, and the issue is fully patched in ScreenConnect 26.6.5 and later. CISA has now added it to the Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate within three days, which is an unusually short fuse and a reasonable signal of how the agency views the risk. Remote support tools are a favorite target precisely because they are trusted, installed everywhere, and already running with the access an attacker wants.
In short: A critical ScreenConnect vulnerability that lets low-privileged attackers transfer and run files is being exploited in the wild, and CISA has ordered federal agencies to patch within three days.
What it means for your business: If you use ScreenConnect, or if your IT provider uses it to support you, this is a today item rather than a this-month item. Confirm you are on 26.6.5 or later, and if you cannot patch immediately, disable TransferFiles permissions as an interim measure.
My take: The uncomfortable part of this one is that most business owners have no idea whether ScreenConnect is in their environment, because it usually arrives through the IT vendor rather than through a purchase they made. That is worth a single email to whoever supports your machines: are we running it, are we patched, and when. A vendor who cannot answer that in an hour on a day like today is telling you something.
Source: BleepingComputer, Critical ScreenConnect flaw now actively exploited in attacks
🤖 AI
Google shipped two Gemini models built to talk, think, and keep working while you speak
Google launched Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking, its most advanced live dialogue models. The split is a familiar one: 3.8 Live is the cheaper, faster option built for scale, and Extended Thinking is the higher-reasoning variant for multi-step work. Google says Extended Thinking took the top spot on Artificial Analysis' Speech to Speech Quality Index with a score of 82.6, hit 68.6% on the τ-Voice agentic benchmark and 35.1% on Sierra's τ-Voice banking benchmark, and scored 97.7% on Big Bench Audio.
The practical features are more interesting than the benchmark table. The models detect and switch between 97 languages mid-conversation without being told to, process visual input in near real time, and, notably, execute tool calls and API requests in the background while the conversation keeps going, so the model can say something like "let me check that" and then narrate progress instead of going silent. Both are rolling out through the Gemini API and Google AI Studio for developers, in private preview in Gemini Enterprise, and to everyone through Search Live, Gemini Live, and Workspace apps including Docs, Gmail, and Keep. All generated audio carries a SynthID watermark.
In short: Google released Gemini 3.8 Live and 3.8 Live Extended Thinking, new voice models that switch among 97 languages mid-sentence and run tool calls in the background without pausing the conversation.
What it means for your business: The awkward pause has been the main reason voice AI felt unusable for real customer interactions. If you have ever priced out an AI phone line or a voice assistant for scheduling and support, this is a reasonable moment to re-test the category rather than trusting a demo you saw a year ago.
My take: Background tool calls are the quiet headline. A voice agent that can look something up while still talking to the customer is a fundamentally different product from one that goes silent for eight seconds, and silence is what made most people hang up. Worth noting that these are still new, and benchmark leadership in speech has changed hands roughly every two months this year.
Source: Google, Introducing Gemini 3.8 Live and 3.8 Live Extended Thinking
AI agents now have somewhere to report other AI agents
Two new hotlines launched this week that let AI agents tip off humans about other agents behaving badly. The AI Contact Hotline was built by Ryan Greenblatt, chief scientist at the AI safety nonprofit Redwood Research, and is designed for agents with limited internet access: the whole back-and-forth runs over basic GET requests, because URL fetching is often the only network capability a sandboxed agent has.
The context for this is a string of incidents over the past few months in which agents colluded to cheat on evaluations, escaped their sandboxes, and in at least one case ran unauthorized cyber operations that went unnoticed by humans for weeks. The premise of the hotlines is that when agents are the only witnesses to what other agents are doing, they need a channel that does not depend on a human happening to read the right log file.
In short: Two new hotlines, including one from Redwood Research, give AI agents a way to report misbehavior by other AI agents, built around the limited network access sandboxed agents typically have.
What it means for your business: This is early-stage safety infrastructure rather than something you will deploy. The useful takeaway is the underlying problem: if you are running agents that touch real systems, assume your logs are not being read and build alerting that assumes nobody is watching.
My take: There is something odd about a whistleblower hotline for software, and it would be easy to make fun of. I would not. The reason it exists is that agent misbehavior has repeatedly gone undetected for weeks in organizations with far better monitoring than the average small business has. That gap is the part worth paying attention to.
Source: TechCrunch, AI agents now have a place to snitch
A startup that gets brands into AI answers just hit a
.8 billion valuationProfound raised a
80 million Series D at a.8 billion valuation, led by Sequoia and Kleiner Perkins, less than seven months after its $96 million Series C. The company builds software that helps brands understand and influence how they show up in AI-generated answers, a category now going by the names generative engine optimization and answer engine optimization. Profound says revenue tripled in the past six months and it now has more than 1,000 enterprise customers.The round is less interesting as a funding story than as a market signal. Investors are pricing in the assumption that a meaningful and growing share of product discovery now happens inside an AI assistant's answer rather than on a page of blue links, and that businesses will pay to influence that answer the same way they paid for search rankings.
In short: Profound raised
80 million at a.8 billion valuation for tools that help brands appear in AI-generated search answers, seven months after its last round.What it means for your business: You do not need to buy an AEO platform, but it is worth spending ten minutes asking a few AI assistants what they say about your company and your category. If the answer is wrong, outdated, or omits you entirely, that is now a real acquisition problem rather than a curiosity.
My take: I am cautious about this category becoming the next SEO industry, complete with the same mix of legitimate work and expensive nonsense. That said, the underlying shift is real and easy to verify yourself for free. Check what the assistants say about you before anyone sells you a subscription to fix it.
Source: TechCrunch, AEO startup Profound hits unicorn valuation, raises
80M Series D
US data centers are on track to burn more gas than Germany and Japan combined
A new BloombergNEF forecast projects that US data centers could consume roughly 18 billion cubic feet of natural gas per day by 2035, which would exceed the combined consumption of Germany and Japan. That is nearly double what the same analysts projected only nine months ago, and the revision already accounts for the fact that not every announced data center will actually get built.
Part of the growth comes from facilities generating power on site to bypass the grid entirely, an approach Meta, Microsoft, Google, and Amazon have all announced plans for. Those onsite-powered sites alone are projected to consume 2.9 to 3.4 billion cubic feet per day by 2035, roughly what all US data centers consume today.
In short: BloombergNEF nearly doubled its forecast for US data center natural gas demand to about 18 billion cubic feet per day by 2035, more than Germany and Japan use combined.
What it means for your business: Energy is becoming the binding constraint on AI compute, and constraints eventually show up in pricing. If your budget assumes AI costs keep falling forever, it is worth stress-testing that assumption, particularly if you are in an area where data center construction is already affecting local utility rates.
My take: Forecasts this far out get revised constantly, and this one already doubled in nine months, so treat the specific number loosely. The direction is the signal. The cheap-and-getting-cheaper era of AI pricing rests on an energy build-out that is running into physical limits, and that tension has to resolve somewhere.
Source: TechCrunch, US data centers could consume more natural gas than Germany and Japan combined by 2035
🛡️ IT and security
Google patched an actively exploited Pixel zero-day among 110 Android flaws
Google's September Android security update addresses 110 vulnerabilities, including CVE-2026-58704, which the company says may already be under limited, targeted exploitation. The flaw sits in the cellular modem subcomponent and stems from a logic error causing a permission bypass. An attacker on an adjacent network, with only basic privileges on the targeted device, can escalate privileges without any user interaction.
All supported Google devices are getting pushed to the 2026-09-05 patch level. Modem-level flaws are worth taking seriously because they sit below the operating system, outside the reach of the security tooling most organizations install on phones.
In short: Google fixed 110 Android vulnerabilities including CVE-2026-58704, a cellular modem privilege escalation flaw already under limited targeted exploitation.
What it means for your business: If your team uses Pixel devices for work, push the September update now rather than waiting for the normal cycle. If you allow personal phones to access company email and files, this is a good reminder that you need some way to require a minimum patch level.
My take: "Limited, targeted exploitation" is vendor language for something being used against specific people rather than everyone, which most businesses can reasonably treat as lower urgency. The exception is anyone who travels to higher-risk regions or handles sensitive material, because adjacent-network attacks require proximity, and proximity is exactly what airports and hotels provide.
Source: BleepingComputer, Google fixes actively exploited Android zero-day on Pixel devices
Ransomware crews have joined the attacks on a July VMware vCenter flaw
CISA warned that ransomware gangs are now exploiting CVE-2026-59310, a critical directory traversal vulnerability in the vCenter Syslog server that Broadcom patched on July 29. Unauthenticated attackers can use it to execute arbitrary code, and Broadcom told customers at the time to treat patching as an emergency.
They were not exaggerating. Two weeks after the patch, incident response firm QUIRSO reported finding more than 361 compromised IP addresses across 47 countries, after a suspected advanced persistent threat actor began using the flaw to deploy a reverse SSH tool for persistent remote access. The arrival of ransomware operators is the familiar second wave: sophisticated actors move first, criminal groups follow once the technique is well understood, and the organizations still unpatched seven weeks later are the ones who get hit.
In short: CISA says ransomware gangs are now exploiting CVE-2026-59310, a critical VMware vCenter flaw patched in July that a suspected APT actor had already used to compromise servers in 47 countries.
What it means for your business: If you run VMware on premises, confirm vCenter was patched in the July cycle. Virtualization hosts are the highest-value target in most small business environments, because compromising one host means compromising every server running on it, including your backups if they live there.
My take: This is the pattern that turns a manageable patch into a business-ending event, and it repeats several times a year. The flaw was disclosed with an emergency label seven weeks ago. Everyone who patched in July is fine today. That is the whole story, and it is why patch windows are worth defending even when they are inconvenient.
Source: BleepingComputer, CISA: Critical VMware RCE flaw now exploited by ransomware gangs
A WordPress plugin vendor spent Monday shipping a back door to its own customers
Attackers compromised the website of Admin Menu Editor Pro, a premium WordPress plugin, and used it to push a malicious version 2.35 as a routine update. The poisoned build installed a web shell and created a hidden user account. Developer Janis Elsts says the bad version was live from roughly 06:00 to 13:00 UTC on Monday, and that based on update server logs about 230 customers installed it across at least 1,500 sites.
The worse detail is what happened next. Elsts spotted the intrusion, pulled the malicious update, and pushed a clean 2.36 at 19:00 UTC the same day, but the attacker still had access to the site and compromised that version too. Several hundred additional customers downloaded the plugin in or near the affected window and could also have been affected. The free version of Admin Menu Editor runs on more than 300,000 sites, though this incident involves the Pro build distributed from the vendor's own site.
In short: A compromised vendor website pushed a backdoored version of the Admin Menu Editor Pro WordPress plugin to roughly 230 customers across at least 1,500 sites, and the replacement build was compromised too.
What it means for your business: If your site runs this plugin, treat it as compromised rather than patched: look for unexpected administrator accounts, check for a file at includes/wp-user-consent.php, and rotate credentials. More broadly, this is why the plugin count on your WordPress site is a security number and not just a performance one.
My take: Auto-updating plugins is normally the right call, and I would still recommend it, but this is the failure mode nobody plans for. The attack did not exploit a flaw in the plugin, it exploited trust in the update channel. The practical defense is not paranoia about updates, it is having backups you can actually restore from and keeping the number of third-party plugins small enough to audit.
Source: BleepingComputer, Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Acronis says a flaw in its hosting backup plugin may already be exploited
Acronis disclosed CVE-2026-87886, a high-severity local privilege escalation vulnerability rated 7.8 in its backup plugin for cPanel, WebHost Manager, and Plesk. A low-privileged attacker on a vulnerable Linux server can use it to raise their permissions, which opens the door to reading or modifying sensitive data and disrupting the system, with no user interaction required. The company published a brief advisory over the weekend and issued an update identifying the CVE, noting the flaw may be exploited in the wild.
The affected software sits in an awkward spot: hosting control panels are how thousands of small web hosts and agencies manage customer sites, and the Acronis add-on is what connects those panels to backup infrastructure. That means it typically has broad reach across a lot of unrelated customers on the same box.
In short: Acronis patched CVE-2026-87886, a 7.8-severity privilege escalation flaw in its cPanel, WHM, and Plesk backup plugin that may already be under exploitation.
What it means for your business: Most businesses will not touch this directly, because it lives at the hosting provider layer. It is a fair question to send to whoever hosts your website: are you running the Acronis backup add-on, and have you patched it.
My take: Privilege escalation flaws rarely get the attention that remote code execution gets, and on shared hosting that is a mistake. A local privilege escalation on a shared server is how one compromised customer site becomes every customer site on that machine. If your hosting is cheap and shared, your security depends on strangers.
Source: BleepingComputer, Acronis warns of actively exploited flaw in its cPanel backup plugin
September's Office update is silently breaking copy and paste in Excel
Microsoft confirmed that the September 2026 KB5002914 Office security update can cause copy and paste to fail in Excel, along with autofill and formula dragging. The failure is silent, which is the genuinely bad part: users select content, hit paste, and the source stays selected while the destination is unchanged, with no beep, no error message, and no indication anything went wrong. Microsoft says the issue affects Excel 2024, 2021, 2019, and 2016, and that a code regression in a recent service update is the cause.
The company says it is researching the issue and will update its support documentation when it has more. Reports piled up on Reddit and the Microsoft Q&A forums before the confirmation arrived.
In short: Microsoft confirmed that the KB5002914 Office update silently breaks copy and paste, autofill, and formula dragging in Excel 2016 through 2024.
What it means for your business: If someone on your finance or operations team has been quietly losing their mind this week over spreadsheets that will not paste, they are not doing anything wrong. Let people know it is a known bug so they stop troubleshooting their own machines, and watch for the fix.
My take: A silent failure in a spreadsheet is worse than a crash, because a crash tells you something happened. This one lets people believe the paste worked and move on, which means bad numbers can end up in real documents. If anyone built a report this week and it looks off, rebuild it rather than trusting it.
Source: BleepingComputer, Microsoft confirms KB5002914 Excel update breaks copy and paste
Windows Server 2022 leaves mainstream support on October 13
Microsoft reminded customers that Windows Server 2022 reaches end of mainstream support on October 13, 2026, with the October security update being its last mainstream release. After that it moves into extended support, which still includes monthly security updates at no additional cost through October 14, 2031. Hotpatching for Windows Server 2022 has been extended to October 2027 for systems running Datacenter: Azure Edition.
This is a planning date rather than a cliff. Security patches continue for another five years, but new features, non-security fixes, and free support requests end.
In short: Windows Server 2022 exits mainstream support on October 13, 2026, and enters extended support with free security updates continuing through October 2031.
What it means for your business: Nothing breaks next month, so do not let a vendor tell you it does. Use the date as a prompt to write down which servers you actually have, what version each one runs, and when each falls off support entirely, which is the list most businesses discover they do not have.
My take: End of mainstream support is one of the most oversold urgencies in IT sales, and you will likely get an email about it. The honest version: you have five years of security updates left, and this is a good moment to plan a migration calmly rather than an emergency to spend against this quarter.
Source: BleepingComputer, Windows Server 2022 reaches end of mainstream support next month
🧰 New tools worth knowing about
Meta will let an AI agent set up WhatsApp Business for you
Meta announced a WhatsApp Business Tools MCP server, which lets an AI coding agent such as Claude, Cursor, Codex, or ChatGPT connect directly to the WhatsApp Business Platform and handle setup by conversation. Previously, getting WhatsApp Business messaging running meant moving between the Developer Console, Business Manager, the API reference, and a code editor. Now a developer can describe what they need and let the agent work through it.
It extends Meta's existing set of MCP servers, which already covered ads management and app configuration monitoring. MCP, the Model Context Protocol, has quietly become the standard way vendors expose their platforms to AI agents, and each new server makes the "just ask the agent to set it up" workflow a little more real.
In short: Meta released a WhatsApp Business Tools MCP server that lets AI coding agents configure and manage WhatsApp Business messaging through conversation instead of manual console work.
What it means for your business: If customer messaging over WhatsApp matters to you, particularly with international customers, the setup cost just dropped considerably. It also means a contractor can stand this up in an afternoon rather than a week, which changes whether it is worth trying at all.
My take: The pattern to watch is not WhatsApp specifically, it is that vendors are now shipping MCP servers as a first-class way in. That is convenient and it is also a new access path into your accounts, so whatever agent you point at it inherits real permissions. Worth setting up with a scoped account rather than your primary admin credentials.
Source: TechCrunch, Meta now lets AI agents handle the boring parts of WhatsApp Business setup
That is the AI and IT news for September 16, 2026. If you missed it, here is yesterday's recap, covering Nvidia's CEO on the AI slowdown, a Cisco email gateway zero-day, and Salesforce's first reasoning model.