Airtable's owner just bought Miro

The news: Bending Spoons agreed on 10 September to buy Miro for $1.355 billion in cash. That is six weeks after it closed a $1.285 billion purchase of Airtable.

Why it matters: Two tools your teams bought separately now share one owner, and that owner's record is layoffs followed by repricing. It cut roughly 75% of WeTransfer's staff, and this month Vimeo began moving customers onto costlier tiers unasked. The deal closes in the fourth quarter, so today's contract terms are the ones you keep.

What to do: Pull your Miro and Airtable agreements this morning and check who can re-tier or reprice you mid-term.

From the people who send this

CXO Brief is published by DoGood. More than seventy enterprise vendors are currently paying for 30-minute briefings with IT and security leaders on AI governance, third-party risk, identity, observability and infrastructure. You choose which vendors to meet, if any. Every completed briefing pays you $150 to $200, as a premium gift card, cash, or a donation to a charity you pick if your employer restricts gifts. Membership is free and by invitation.

Or reply to this email with the word "briefing" and Ryan will set you up personally.

Three separate crews were already in the firewall console

On 9 September Cisco Talos confirmed active attacks on a CVSS 10.0 auth bypass in Secure Firewall Management Center. Cisco patched CVE-2026-20079 back in early March. Talos found three distinct intrusion clusters, one planting a Sandworm-linked Cyclops Blink variant and one delivering Qilin ransomware. Two of them took credentials or managed-device configs, so the blast radius is every firewall FMC controls. Hotfixes are already out and a wider hardening release ships this week.

GitLab shipped a 10.0 and the scanners showed up overnight

GitLab has patched CVE-2026-85706, a path traversal in the repository commits API rated CVSS 10.0. watchTowr logged in-the-wild probes, not confirmed breaches, from 06:00 UTC on 11 September. It only needs one thing: a public project on the instance. An unauthenticated attacker then reads logs and config files holding credentials and CI/CD secrets. Patch to 19.3.2, 19.2.6 or 19.1.8, then grep for POST requests to the commits endpoint carrying a file.Path parameter.

Watch This

Salesforce previewed its Trusted Enterprise AI Harness on 10 September, a week before Dreamforce. It repackages tools Salesforce already sells, and it ships to all customers only next year. ServiceNow, AWS and Genesys ship the same idea, so your agent control plane will be whoever already holds your identity data.

The CXO Brief is published by DoGood, the network where enterprise IT leaders are paid for 30-minute vendor briefings.

Know a CIO who needs this? Forward it and they can subscribe here.

Run IT or security at a $100M+ company? Claim your invite.