// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Thursday, July 23, 2026

2 CRITICAL1 WARNING4 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Immediately inventory all SonicWall SMA appliances across your client base and prioritize patching CVE-2026-15409/15410 today — these are being exploited in the wild, not just disclosed.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE1 item
INFO☁️ M365/Azure

Microsoft 365 Suffers Near-10-Hour Outage in January 2026 — Entra ID Authentication Root Cause

A major Microsoft 365 outage earlier in 2026 knocked out Outlook, Defender, and Purview for North American users for nearly 10 hours, with 15,000 reports at peak on Downdetector. All affected services shared a dependency on Azure AD/Entra ID authentication, pointing to the identity layer as the core failure point. MSPs should ensure out-of-band monitoring (not relying on M365/Azure-hosted alerts) and maintain documented failover communication plans.

Read more →
🔐 SECURITY1 item
CRITICAL🔐 Security

July 2026 Patch Tuesday: Record 622 CVEs Patched — Two Zero-Days Actively Exploited in the Wild

Microsoft's July 2026 Patch Tuesday is the largest in company history, fixing 622 CVEs including two actively exploited zero-days (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server) and one publicly disclosed BitLocker bypass (CVE-2026-50661). Both actively exploited CVEs have been added to CISA's KEV catalog. Microsoft attributes the record volume partly to a new AI-powered vulnerability discovery system (MDASH) scanning the Windows codebase.

Read more →
🔥 NETWORKING1 item
CRITICAL🔥 Networking

SonicWall SMA1000 Zero-Days (CVE-2026-15409 / CVE-2026-15410) Exploited Weeks Before Disclosure

Attackers were installing custom malware on SonicWall SMA1000 appliances via CVE-2026-15409 and CVE-2026-15410 weeks before SonicWall disclosed the flaws or CISA added them to the KEV catalog — a classic pre-disclosure exploitation pattern. MSPs managing SonicWall SMA1000 devices should treat any unpatched unit as potentially compromised and apply the latest firmware immediately. Check for persistence indicators and unusual outbound connections even on patched devices.

Read more →
📡 INDUSTRY1 item
WARNING📡 Industry

SMB1001:2026 Standard Updated — Australian MSPs Urged to Review Changes

The SMB1001:2026 cybersecurity standard has been updated, with Australian MSPs advised to review what changed and how it affects compliance obligations for SMB clients, particularly in Perth and other key markets. The update sits alongside ongoing ACSC Essential Eight alignment requirements and the broader ASD framework. MSPs serving SMB clients in regulated sectors should assess whether client environments meet the revised SMB1001:2026 controls.

Read more →
Wednesday, July 22, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice