“Inventory all customer Cisco ASA/FTD and Fortinet devices accessible from the internet today and prioritize patches for CVE-2026-20349 and the Fortinet auth bypasses — don't wait for your normal Tuesday patch window.”
Post-Incident Review: July 23 M365/Azure West US Outage Caused by Maintenance Automation Bug
Microsoft confirmed a maintenance automation bug mistakenly removed IP routes from more devices than intended on July 23, disrupting Azure and Microsoft 365 services for nearly five hours — affecting Outlook, Teams, SharePoint, OneDrive, Copilot, and more. SharePoint accounted for 78% of complaints and Downdetector peaked at over 2,400 reports. The PIR is publicly available; admins should review the incident (ID MO1437424) and track Microsoft's promised remediation milestones.
Read more →CRITICAL: Cisco ASA/FTD Zero-Day CVE-2026-20349 Actively Exploited — CISA KEV Deadline Passed August 14
Cisco confirmed active exploitation of CVE-2026-20349 (CVSS 8.6) in August 2026 — an unauthenticated remote attacker can send a crafted HTTP request to the Remote Access SSL VPN service of ASA or FTD devices, triggering a device reload and denial-of-service. CISA added it to the KEV catalog with a federal deadline of August 14, 2026; organisations still running vulnerable firmware should treat this as a same-week emergency. No workaround exists — upgrade to fixed ASA firmware trains or apply the FTD hotfix image immediately.
Read more →Gunra Ransomware Group Exploiting Fortinet Auth Bypass CVEs on FortiOS/FortiProxy — Joint US/South Korean Advisory
A joint advisory from US and South Korean agencies details the Gunra ransomware-as-a-service group actively exploiting Fortinet auth bypass flaws CVE-2024-55591 and CVE-2025-24472 to bypass MFA on FortiOS and FortiProxy devices and gain super-admin access. Affected organisations should immediately apply Fortinet patches, review admin account lists for unauthorised entries, and validate MFA configurations are not relying solely on FortiCloud SSO. Check FortiGuard PSIRT advisories for affected version lists.
Read more →CRN Australia Channel Awards 2026 Shortlist Announced — MSP, MSSP and Solution Provider Categories Expanded
CRN Australia has announced the finalists for the CRN Channel Awards Australia 2026, with MSP of the Year and Service Provider of the Year split into new headcount-based sub-categories due to a record number of applications. The awards honour MSPs, Solution Providers, and MSSPs, as well as ESG and IT project excellence, with a Lifetime Achievement Award to be announced on the night. Australian MSPs should review the shortlist for competitive intelligence on peer organisations and emerging service models gaining industry recognition.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.