// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Monday, July 27, 2026

1 CRITICAL4 WARNING6 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Identify and patch Fortinet FortiSandbox systems immediately — this is CISA KEV, meaning active exploitation; create a priority list before end of shift.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE3 items
WARNING☁️ M365/Azure

Azure Maintenance Bug Wipes IP Routes, Knocking Out M365 for Nearly Five Hours

On July 23, 2026, a bug in Azure's automated network maintenance system incorrectly removed IP routes from more devices than intended in the West US region, severing the datacenter from Microsoft's global WAN. Teams, SharePoint, OneDrive, Copilot Chat, and a wide range of Azure services (AKS, Cosmos DB, Sentinel, VPN Gateway, and more) suffered connectivity failures and elevated latency. Microsoft rolled back the change and restored services by ~3:41 PM ET; a full Post Incident Review is expected by early August 2026. Workaround: None during the incident — customers with multi-region architecture in non-West-US regions were not affected.

Read more →
WARNING☁️ M365/Azure

Azure Outage Also Blocked Windows 11 Updates and WSUS Sync on July 23

The same July 23 Azure West US outage disrupted Windows Update and Microsoft Update services, preventing Windows 11 and Microsoft Store app updates from downloading. WSUS synchronisation was also affected, compounding problems for MSPs managing endpoint patching pipelines. Microsoft confirmed the issue was resolved after reverting the networking change, but the bug remained listed on the Windows Release Health page as of July 24.

Read more →
WARNING☁️ M365/Azure

Microsoft Defender Impacted During July 23 Outage: Threat Explorer, Advanced Hunting & Automated Remediation Failed

Alongside the broader M365 outage, Microsoft Defender experienced parallel degradation: Threat Explorer and Advanced Hunting queries failed, automated investigation/remediation workflows stopped, and customers experienced delays reaching Microsoft Defender Experts for assistance. Security teams relying on automated response playbooks were effectively blind during the incident window. No workaround; restore manual SOC triage procedures during future Azure West US incidents.

Read more →
🔥 NETWORKING2 items
CRITICAL🔥 Networking

Fortinet FortiSandbox OS Command Injection Flaws (CVE-2026-39808 / CVE-2026-25089) Added to CISA KEV

CISA added two unauthenticated OS command-injection vulnerabilities in Fortinet FortiSandbox's web interface — CVE-2026-39808 (affecting versions 4.4.0–4.4.8) and CVE-2026-25089 (affecting additional on-premises, cloud, and PaaS deployments) — to KEV on July 16. Both can lead to full appliance takeover via crafted web requests. Workaround: Upgrade to FortiSandbox 4.4.9 or later, or 5.0.6 or later; remove management interfaces from public internet exposure and rotate all credentials the appliance accessed.

Read more →
WARNING🔥 Networking

Palo Alto PAN-OS July 2026 Patch Wave: Updates Across 10.2, 11.1, 11.2, and 12.1 Branches

Palo Alto Networks released PAN-OS patch updates and hotfixes across multiple active branches (10.2, 11.1, 11.2, 12.1) as part of the July 2026 vendor patch cycle, addressing security vulnerabilities and stability issues. Customers should review applicable release notes before upgrading as changes vary per branch. MSPs managing Palo Alto firewalls should schedule upgrades this week, prioritising internet-facing GlobalProtect and management interfaces.

Read more →
📡 INDUSTRY1 item
INFO📡 Industry

Coro Promotes Deme Georgiou to VP Global MSP — Signals Continued Vendor Investment in AU MSP Channel

Cybersecurity vendor Coro has promoted Deme Georgiou to VP of Global MSP, a move highlighted on CRN Australia reflecting continued vendor-side investment in the MSP go-to-market channel. The appointment signals that multi-tenant security platform vendors are scaling their MSP-focused leadership as the AU channel grows. Australian MSPs evaluating consolidated security platforms should factor vendor MSP-channel commitment into procurement decisions.

Read more →
Friday, July 24, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice