Welcome to the first issue of The Ridge.

Every other Tuesday, this newsletter does one job: it reads the security news so you don't have to, and tells you what actually applies to a business your size. Sometimes the answer will be "nothing." When it is, we'll say so. That's the whole point.

This week, though, there's real news.

The Big Story: Patch Tuesday, minus the panic

On Tuesday, Microsoft shipped fixes for roughly 400 vulnerabilities. (You'll see different totals in different headlines — 398, 415, 421 — because vendors count differently. The exact number doesn't matter. What's in it does.)

Three of them were "zero-days," meaning the flaw was known before the fix existed. Only one of those is confirmed being used in real attacks: a bug in a core Windows networking driver (CVE-2026-68820, for those keeping score) that lets an attacker who's already on a machine promote themselves to full SYSTEM control.

Read that carefully: already on a machine. This bug doesn't let anyone in. It makes a break-in worse. Attackers love these because they turn a small foothold — one phished employee, one bad download — into total control of the computer.

What this means for you: every Windows PC in your office has this driver. The fix is in this month's Windows Update.

What to do: nothing exotic. Make sure Windows Update runs and machines actually reboot. If your computers update automatically (most do), your action item is: don't postpone the restart this week. That's it. No new product to buy, no consultant to call.

Patch This (if it applies to you)

The scarier-sounding bugs this month live in Windows Server roles — the software behind features like DHCP, DNS, and network-boot deployment. One scored 9.8 out of 10.

Here's the honest filter: if your office doesn't run its own Windows Server, none of these apply to you. Your internet router handles DHCP. Your email lives in Microsoft 365 or Google. You're done reading this section.

If you do have a Windows Server in a closet — some offices still run one for files or an old line-of-business app — this is the month to patch it promptly, not eventually. Those network services are exactly the kind of thing that can be attacked without anyone clicking anything. If nobody at your company knows whether you have one, that's worth finding out. (That question is free. Reply and ask.)

Also this week: Adobe patched 51 flaws across its products, including ColdFusion and Commerce. If your business website runs on Adobe Commerce (Magento), forward this to whoever maintains it today.

We'd Tell You If You Needed Us

You don't, this week.

Everything above is handled by patches you already pay for, applied by the auto-update you already have. The gap between businesses that get hurt and businesses that don't is rarely fancy tools — it's whether the updates actually got installed and the machines actually got rebooted.

So here's your entire security to-do list for the week:

  1. Let Windows Update run. Reboot when asked.

  2. If you have a Windows Server on-site, patch it this week — or find out whether you have one.

  3. Using Adobe Commerce for your store? Ping your web person.

That's the list. If someone tries to sell you something because "Microsoft just patched 400 vulnerabilities," you now know what those 400 actually mean for a business your size: about three action items, all free.

See you in two weeks. If something bad enough happens before then, you'll hear from us sooner — that's the deal.

Forwarded this?
Subscribe here — practical security for small businesses, every other Tuesday.