Datacap - We Solve Payment Problems
Home Security

Security and compliance news for ISVs: August 2026

From a major supply chain breach to new PCI guidance, here's what's shaping risk for software leaders right now.

security-revenue-growth

If you’re running an ISV, security news moves fast enough that it’s easy to miss something that actually affects your business. Here’s a roundup of what’s happened over the past two months, along with what it means for you as you build and support software for your customers.

A massive AI supply chain attack hit thousands of organizations

In March 2026, a threat actor group compromised the open-source LiteLLM framework, and researchers only fully understood the scope of the damage this August. CloudSEK now calls it the largest AI infrastructure supply chain breach of the year, with the malicious packages affecting roughly 434,000 CI/CD pipelines and potentially exposing credentials for AWS, Google Cloud, Azure, SSH keys, and Kubernetes tokens across more than 2,500 organizations. The packages were only live for about 40 minutes, but that’s plenty of time for automated pipelines to pull them in. The FBI issued a follow-up advisory in July warning that stolen credentials from this incident are still being weaponized months later. If your development pipeline pulls open source AI dependencies automatically, this is a good moment to review how you pin versions and verify package integrity before anything reaches a build server.

AI-generated code still fails security checks nearly half the time

Veracode’s 2026 GenAI Code Security Report, released in early August, found that AI coding tools pass security tests only 56 percent of the time, a number that’s barely moved in a year despite huge gains in how fast these tools write functional code. Roughly 44 percent of AI-generated code tasks introduced a known, exploitable vulnerability when developers didn’t specifically prompt for secure output. For ISVs leaning on AI assistants to speed up development (and most are at this point), this is a reminder that fast and working isn’t the same as safe. Build a security review step into your pipeline specifically for AI-assisted code, and don’t assume a clean compile means a clean bill of health.

An RMM vulnerability is a direct hit on the MSP channel

CISA added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog this month. N-central is a remote monitoring and management platform widely used by MSPs, and this particular flaw stems from an incomplete patch for an earlier vulnerability, which is its own lesson about verifying that fixes actually close the gap they’re meant to close. If your software integrates with RMM platforms, or if you sell through MSP partners who rely on this class of tool, it’s worth checking in on their patch status directly rather than assuming it’s handled.

PCI DSS enters its next planning cycle

Every future-dated requirement in PCI DSS 4.0.1 became mandatory back in March 2025, so if your payment-adjacent software hasn’t been assessed against the full standard yet, there’s no more grace period to lean on. What’s new is that the PCI Security Standards Council ran a request for comments this summer (closing July 20) on where the next version of the standard should go, specifically around AI and emerging technology. There’s no release date yet for what comes next, but ISVs building payment pages, e-commerce checkout flows, or POS integrations should expect the standard to keep tightening around script integrity and third party monitoring, not loosening.

Breach costs keep climbing, and third parties are a growing share of the problem

IBM’s 2026 breach cost report puts the global average cost of a data breach at just under five million dollars, with the US average north of eleven million. Third parties were involved in nearly half of all breaches studied, a sharp jump from the prior year. If you’re an ISV, you are frequently the third party in someone else’s breach story. That’s worth internalizing when you’re prioritizing your own security roadmap, since a lapse on your end doesn’t just cost you, it costs every customer whose data flows through your platform.

State privacy law enforcement is heating up, not new laws

No new comprehensive state privacy laws passed this year, but Indiana, Kentucky, and Rhode Island joined the list of states with active laws back in January, bringing the total to twenty. Several states, including Connecticut and Arkansas, added tighter rules this summer around data belonging to minors. The bigger shift is enforcement: state attorneys general are now the primary drivers of privacy accountability in the US, and several cure periods that used to give companies time to fix violations before facing penalties have expired or are expiring this year. If your customer base spans multiple states, this is a good time to confirm your data handling practices hold up against the strictest applicable law rather than the most convenient one.


Mike Monocello

Mike Monocello is the co-founder of DevPro Journal and Managed Services Journal, and a training and content specialist at BlueStar US. Previously, Monocello was a member of the RSPA board of directors, the editor-in-chief of Business Solutions magazine, and a former VAR and ISV.

×