// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Tuesday, September 8, 2026

2 CRITICAL2 WARNING4 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Force-deploy Chrome 152.0.7977.82/.83 to all managed endpoints today — treat it like ransomware response, not routine patching.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE2 items
WARNING☁️ M365/Azure

Microsoft 365 Multi-Day Auth Outage (EX1464935) Resolved — Post-Incident Review Pending

A failure in a core Microsoft Entra ID authentication configuration caused cascading outages across Exchange Online, Teams, SharePoint, OneDrive, Copilot, Purview, Defender XDR, and Universal Print beginning 31 August 2026. Microsoft confirmed the outage was largely resolved by 1 September 2026, though some infrastructure recovery continued into 2 September. No workaround was available during the incident; affected users should check the M365 Admin Centre for any residual issues and await the formal Post Incident Review.

Read more →
WARNING☁️ M365/Azure

September 2026 Patch Tuesday Live: 9 Critical CVEs Across Azure, Office, and Dynamics — No Active Exploits Today

Microsoft's September 2026 Patch Tuesday (released 8 September 2026 — today) fixes 181 listed entries, of which 9 are genuine Microsoft product CVEs all rated Critical, spanning Azure, Microsoft Office, and Microsoft Dynamics. No CVEs were publicly disclosed or actively exploited at ship time, but 'Exploit Wednesday' reverse-engineering by threat actors typically begins within 24 hours. MSPs should prioritise kernel, networking, and authentication patches and verify deployment state on all endpoints rather than relying on 'deployment succeeded' status.

Read more →
🔐 SECURITY1 item
CRITICAL🔐 Security

Chrome CVE-2026-85046 Exploited in the Wild — Update to 152.0.7977.82/.83 Immediately

Google confirmed CVE-2026-85046 is being actively exploited in the wild and shipped a fix in Chrome 152.0.7977.82/.83, which addresses 12 CVEs in total. The September 2026 Patch Tuesday forecast from Ivanti flags this as requiring immediate attention for enterprise environments. MSPs should push the Chrome update via RMM or GPO as a priority and verify the browser version on all managed endpoints.

Read more →
📡 INDUSTRY1 item
CRITICAL📡 Industry

ACSC Confirms Active Exploitation of N-able N-central Auth Bypass CVEs in Australia — Patch to Hotfix 2 Now

The Australian Cyber Security Centre (ACSC) has issued an alert naming CVE-2026-18556 and CVE-2026-18577, both authentication bypass vulnerabilities scored 8.2 (High) affecting all current versions of N-able N-central including 2026.3. The ACSC has observed active exploitation within Australia — this is not a theoretical advisory. N-able released patches on 1 August and Hotfix 2 on 6 August; organisations must upgrade to Hotfix 2 and run N-able's published indicators-of-compromise detection scripts immediately, as patching closes the door but does not evict attackers already present.

Read more →
Monday, September 7, 2026
Wednesday, September 9, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice