“Identify and patch Fortinet FortiSandbox systems immediately — this is CISA KEV, meaning active exploitation; create a priority list before end of shift.”
Azure Maintenance Bug Wipes IP Routes, Knocking Out M365 for Nearly Five Hours
On July 23, 2026, a bug in Azure's automated network maintenance system incorrectly removed IP routes from more devices than intended in the West US region, severing the datacenter from Microsoft's global WAN. Teams, SharePoint, OneDrive, Copilot Chat, and a wide range of Azure services (AKS, Cosmos DB, Sentinel, VPN Gateway, and more) suffered connectivity failures and elevated latency. Microsoft rolled back the change and restored services by ~3:41 PM ET; a full Post Incident Review is expected by early August 2026. Workaround: None during the incident — customers with multi-region architecture in non-West-US regions were not affected.
Read more →Azure Outage Also Blocked Windows 11 Updates and WSUS Sync on July 23
The same July 23 Azure West US outage disrupted Windows Update and Microsoft Update services, preventing Windows 11 and Microsoft Store app updates from downloading. WSUS synchronisation was also affected, compounding problems for MSPs managing endpoint patching pipelines. Microsoft confirmed the issue was resolved after reverting the networking change, but the bug remained listed on the Windows Release Health page as of July 24.
Read more →Microsoft Defender Impacted During July 23 Outage: Threat Explorer, Advanced Hunting & Automated Remediation Failed
Alongside the broader M365 outage, Microsoft Defender experienced parallel degradation: Threat Explorer and Advanced Hunting queries failed, automated investigation/remediation workflows stopped, and customers experienced delays reaching Microsoft Defender Experts for assistance. Security teams relying on automated response playbooks were effectively blind during the incident window. No workaround; restore manual SOC triage procedures during future Azure West US incidents.
Read more →Fortinet FortiSandbox OS Command Injection Flaws (CVE-2026-39808 / CVE-2026-25089) Added to CISA KEV
CISA added two unauthenticated OS command-injection vulnerabilities in Fortinet FortiSandbox's web interface — CVE-2026-39808 (affecting versions 4.4.0–4.4.8) and CVE-2026-25089 (affecting additional on-premises, cloud, and PaaS deployments) — to KEV on July 16. Both can lead to full appliance takeover via crafted web requests. Workaround: Upgrade to FortiSandbox 4.4.9 or later, or 5.0.6 or later; remove management interfaces from public internet exposure and rotate all credentials the appliance accessed.
Read more →Palo Alto PAN-OS July 2026 Patch Wave: Updates Across 10.2, 11.1, 11.2, and 12.1 Branches
Palo Alto Networks released PAN-OS patch updates and hotfixes across multiple active branches (10.2, 11.1, 11.2, 12.1) as part of the July 2026 vendor patch cycle, addressing security vulnerabilities and stability issues. Customers should review applicable release notes before upgrading as changes vary per branch. MSPs managing Palo Alto firewalls should schedule upgrades this week, prioritising internet-facing GlobalProtect and management interfaces.
Read more →Coro Promotes Deme Georgiou to VP Global MSP — Signals Continued Vendor Investment in AU MSP Channel
Cybersecurity vendor Coro has promoted Deme Georgiou to VP of Global MSP, a move highlighted on CRN Australia reflecting continued vendor-side investment in the MSP go-to-market channel. The appointment signals that multi-tenant security platform vendors are scaling their MSP-focused leadership as the AU channel grows. Australian MSPs evaluating consolidated security platforms should factor vendor MSP-channel commitment into procurement decisions.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.