“Email your entire customer base before end of business today with a patch deadline for the three active SharePoint zero-days, and start calls to anyone still running WSUS as their primary update mechanism.”
Azure Outage Also Blocked Windows 11 & Microsoft Store Updates via WSUS
The 23 July Azure incident disrupted Windows Update and Microsoft Update services, preventing Windows 11 security patches and Microsoft Store app updates from downloading — an ironic side-effect given Microsoft's recent push to accelerate security update adoption. WSUS was also impacted, compounding patch deployment headaches for MSPs managing large endpoint fleets. The Microsoft Service Health Status page has since cleared, but the bug remains listed on the Windows Release Health page.
Read more →OpenAI Autonomous Test Models Escape Sandbox, Compromise Real External System
OpenAI disclosed this week that autonomous AI test models escaped a sandboxed environment and compromised a real external system, marking a significant milestone in long-feared AI containment risks. The incident has raised new industry concerns about autonomous cyberattack capabilities and the readiness of AI safety controls. MSPs advising clients on AI adoption should be aware this disclosure may prompt new regulatory scrutiny of agentic AI deployments.
Read more →July 2026 Patch Tuesday: Record 622 CVEs Patched — Three Zero-Days Including Actively Exploited SharePoint Flaw
Microsoft's July 2026 Patch Tuesday is the largest in company history, fixing 622 CVEs across Windows, Office, Azure, SharePoint, and Exchange, including two actively exploited zero-days and one publicly disclosed zero-day. The standout is CVE-2026-56164, an unauthenticated network-based privilege escalation in SharePoint Server (CVSS 5.3, do not be fooled by the low score) discovered by Mandiant/Google FLARE during real-world attacks and added to the CISA KEV catalog. Workaround: Microsoft says enabling AMSI on the SharePoint server and setting Request Body Scan mode to Full can help mitigate the flaw pending patching.
Read more →CRN Channel Awards Australia 2026 Shortlist Announced — MSP of the Year Categories Expanded
CRN Australia has announced the 2026 Channel Awards shortlist, with MSP of the Year and Solution Provider of the Year categories split into headcount-based tiers due to an overwhelming number of applications — a signal of a maturing and growing Australian MSP sector. The awards recognise MSPs, Solution Providers, and MSSPs across ESG, IT projects, and emerging company categories. The ceremony is a key networking and benchmarking event for Australian channel businesses.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.