May 2026 News & Updates
CTC News
- New pricing starting in June 2026 – We will be implementing a slight price increase on 1 June 2026. Additional information will be posted to our Policies and Procedures page here.
- Updates to the MyIT Program – The MyIT Program provides enterprise level compliance-ready IT support for small to medium business clients without the enterprise level pricing and with no term agreements, so no lock-in. If you don’t find value in the program, you can cancel at any time. We’re updating the MyIT Program level names to better reflect the value each tier provides. Going forward:
- MyIT Essentials (formerly Bronze) — Core protection for businesses that need the fundamentals: patching, backups, monitoring, and a team to call when things break.
- MyIT Professional (formerly Silver) — Our most popular plan. For businesses that can’t afford to wait: real-time alerting, priority support queue, and faster response when minutes matter.
- MyIT Enterprise (formerly Gold) — Maximum protection with included on-site support hours and dedicated account management.
- If you’re currently on a MyIT plan, your service and pricing aren’t changing—just the name. Details on all MyIT Programs are available here. Questions? Let us know.
Industry News
- Critical Windows Update: Stuxnet-level USB Vulnerability Patched Microsoft’s May 2026 Patch Tuesday includes fixes for over 100 vulnerabilities, including a particularly nasty Windows USB driver flaw that could let an attacker take complete control of a machine just by plugging in a malicious USB device. No clicks required. This is being actively exploited in the wild—if you haven’t patched yet, now’s the time.
- NVD Database Backlog Hits 20,000+ Vulnerabilities Remember that NIST triage change we mentioned last month? It’s worse than expected. The National Vulnerability Database now has a 20,000+ CVE backlog, meaning many vulnerabilities are going unanalyzed for months. What this means: You can’t wait for “official” severity ratings anymore. The bad guys aren’t waiting. If you don’t have a systematic patching process that treats any unpatched system as a risk, you’re flying blind.
- Zero-Day Surge: Vulnerability Exploitation Attacks Up 40% Security researchers report that zero-day attacks have increased 40% year-over-year. What’s a zero-day? It’s a vulnerability attackers know about before the vendor has a patch—and they’re using them to hit businesses before defenses can catch up. The only reliable defense: layered security, proactive monitoring, and a team that watches your systems 24/7.
- Upcoming End of Life for Windows Server 2016 – We’re officially under two years before the Windows Server 2016 End of Life (EOL), currently scheduled for 25 January 2027. This may seem like a long way off but, in most cases, the upgrade from Windows Server 2016 will require not only additional software licenses but also Client Access Licenses (CALs) and hardware and extensive planning to transition older systems off of the current Windows Server 2016 platform.
Updates
Microsoft released patches for between 120 and 137 vulnerabilities in their May 2026 Patch Tuesday release (depending on who you ask, several totals are being reported), including 16 vulnerabilities that are considered critical and at least one zero day (the USB flaw noted previously).
Microsoft releases regular updates the second Tuesday of each month, often referred to as ‘Patch Tuesday’. These updates are categorized as Low, Moderate, Important or Critical. Details on the categories are available here. The updates can include any supported Microsoft product from Windows to Office to Internet Explorer and server products like Exchange and SQL Server. If you have one or more of these products installed, especially if the update is listed as Important or Critical, it’s important that the updates are installed.
Additional details on this month’s Microsoft updates are available from SANS Internet Storm Center, Krebs on Security, Bleeping Computer, and CrowdStrike.
Adobe released 10 security bulletins this month, ranging from Important to Critical and impacting Premier, Media Encoder, After Effects, Commerce, Connect, Illustrator, Substance 3d Designer, Painter and Sampler, Content Credentials SDK.
Like Microsoft, Adobe now releases updates to their products on the second Tuesday of each month. Adobe will also release ‘out of band’ updates if necessary to address critical vulnerabilities in their products. Adobe products include Adobe Reader (for viewing PDF files), Adobe Flash Player (often used to watch videos, for interactive content like games, etc.), Adobe Shockwave and the Adobe Creative Suite (Photoshop, Illustrator, Acrobat, Lightroom, etc.).
Additional details are available from Adobe Here including links to download the update(s) and instructions for installation.
Need IT Support for your Home or Business? We’d love to help!
Are you a small to medium sized business looking to leverage technology and enable your business and workforce to work smarter and more efficiently? Do you already have computers, servers, firewalls, VPNs or other technology that you’re not taking full advantage of? Are you looking for an IT Service Provider who understands small to medium sized businesses needs and the challenges that we face that can work with you to grow your business rather than just sell you time?
Cyber Tech Cafe is an IT Service Company with a focus on helping small to medium business get the most out of their technology investment. As a small business ourselves, we understand the challenges you face and have designed our service offerings to help you get the most out of your technology dollar. We offer on-call, as needed support if you just need a quick fix or extra set of hands right now. We also offer maintenance plans that we call “MyIT” that are designed to address the most common concerns (patch management, disaster recovery / backup, log review, etc.) that are based on the number of workstations and servers that you have and have no term contract. We believe that, if you find value in what we’re doing, you’ll find a way to keep us around without a contract saying that you have to.
If you have questions about the MyIT plans or have an IT need that you need addressed right now, let us know. We look forward to the opportunity to earn your business.
Article Submitted by Nathan J. Underwood, CEH
