Your business faces real threats this week — and two of them have patch deadlines that can’t wait. Today on Nerds News, Albert Steed breaks down the CISA-flagged Adobe Acrobat Reader zero-day, a surge in ClickFix attacks targeting QuickBooks users, and the surprising truth about AI productivity in 2026.
Adobe Acrobat Reader Zero-Day: Patch It Today
CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week — and two of them are almost certainly running on machines in your office right now. The most urgent: CVE-2026-34621, a critical zero-day in Adobe Acrobat Reader that attackers have been exploiting since December 2025. CISA’s deadline for federal agencies to patch is April 27 — but for small businesses, the right deadline is today.
Adobe Reader is on virtually every business computer. If you’re an ACS managed services client, your machines are already in our patch queue — but only if your computer is turned on and connected to the internet. Patches can’t install on a machine that’s been powered off or disconnected all week. Leave your computers on overnight so our tools can do their job.
The second flaw affecting our clients is a SQL injection bug in Forescout, a network access control tool. If you’re running an older version, our team is already on it. The third notable flaw — a Microsoft Exchange Server vulnerability — doesn’t affect our clients because we’ve moved everyone off on-premises Exchange. This is exactly the kind of protection a managed services relationship is designed to provide: someone is watching so you don’t have to.
ClickFix Attacks Are Now Targeting QuickBooks Users
Tax season is prime time for cybercriminals — and in 2026, their favorite weapon is called ClickFix. It’s a social engineering technique where a fake error message or verification popup convinces you to copy and paste a command into your computer. That command silently installs a remote access tool, giving attackers full control of your system.
Microsoft’s security team has tracked ClickFix campaigns impersonating QuickBooks that reached over 29,000 users across 10,000 organizations. State-sponsored hacking groups are now calling ClickFix their primary initial access vector for 2026 — meaning it’s not a fringe attack, it’s the main playbook. On Macs, attackers are using fake “reclaim disk space” popups to deliver the same payload.
The fix is simple, but it requires training your instincts: do not react to unexpected popups. Legitimate software — including our tools — almost never asks you to copy and paste a command. If something pops up and you’re not sure, send us a ticket before you click anything. That two-minute pause could save you from a ransomware recovery that takes weeks.
The AI Productivity Paradox: More Tools, Less Focus?
Asana’s 2026 State of the Workplace report dropped this week with a finding that’s making headlines: employee focus efficiency has hit a three-year low, down 60%. Among workers who adopted multiple AI tools, those using three or more AI platforms saw a net productivity decline — with time spent on administrative tasks jumping as much as 346% and AI-monitoring fatigue up 12%.
Albert’s take: the data is real, but the interpretation misses something important. Right now, most businesses are in the setup phase — investing time building automations, learning workflows, and figuring out which tools actually fit their operations. That investment feels like lost productivity today. But the businesses doing that work now will have a compounding advantage in 12 months when those automations are humming and competitors are still doing things manually.
The practical lesson: don’t adopt AI tools randomly. Pick one or two that solve a real, specific problem in your business. Master those before adding more. Three half-implemented tools will hurt you; one well-integrated tool will help you. If you’re not sure where to start, that’s a conversation worth having with your IT partner.
Quick Hits: Privacy Laws, Teams Bots, Booking.com & AI Gains
20 US states now have data privacy laws — including Indiana, Kentucky, and Rhode Island, which activated their laws in January 2026. If your business collects customer data (and every business does), check with your attorney about which states’ laws apply to you. Requirements vary widely but generally include rules around data retention, third-party disclosures, and consumer rights.
Microsoft Teams bot detection is rolling out mid-May through June 2026. Meeting organizers will be able to see, approve, or remove external bots that join their calls — giving you more control over who (or what) is recording your conversations. If your team uses Teams for sensitive client calls, this is a useful new guardrail.
Booking.com disclosed a breach affecting 200,000+ customer records — names, emails, and phone numbers exposed via a ClickFix attack on partner hotel systems. If you use Booking.com for business travel, monitor that email address for phishing attempts and consider changing your password.
PwC’s 2026 AI study found that 74% of AI’s economic value is being captured by just 20% of organizations — those focused on business model reinvention, not just cost-cutting. The gap between AI haves and have-nots is widening fast. The good news for small businesses: you don’t need an enterprise budget to be in that top 20%. You need a clear use case and the willingness to implement it.
Key Takeaways
- Patch Adobe Acrobat Reader today — actively exploited, patch deadline is now
- Train your team on ClickFix — if a popup asks you to paste a command, it is an attack
- AI tools work best one at a time — master one before adding more
- Check your data privacy obligations — 20 states now have active privacy laws
- Leave computers on overnight — your managed patches cannot install on a powered-off machine
Nerds News airs live on Facebook several times per week. Subscribe on YouTube or find us on Spotify and Apple Podcasts to catch every episode.
Don’t let cyberthreats catch your business off guard. Schedule a free IT consultation with ACS — we’ll review your patch status, security posture, and AI readiness in one conversation.