// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Tuesday, September 15, 2026

2 CRITICAL3 WARNING6 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Inventory and verify patch status on all Fortinet firewalls and FortiManager instances today — don't wait for the weekly cycle.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE1 item
WARNING☁️ M365/Azure

M365 / Teams / Outlook / Azure Outage Reports Resurface — September 14, 2026

DownDetector JP logged a spike in Microsoft 365, Teams, Outlook, Azure, and OneDrive outage reports on September 14, with reports rising around 4:08 PM JST (3:08 AM ET). It is unclear at time of writing whether this is a new platform-wide event or residual noise; check the Microsoft 365 Service Health dashboard for your tenant status. Workaround: fall back to mobile data or an alternative email client while investigating.

Read more →
🔐 SECURITY3 items
CRITICAL🔐 Security

Unpatched Defender PoC Released: Researcher Claims Incomplete Fix for CVE-2026-69414 (ShieldBreak)

Approximately two hours after September Patch Tuesday shipped, researcher 'MSNightmare' published a proof-of-concept claiming Microsoft's patch for the Defender ShieldBreak vulnerability (CVE-2026-69414) is incomplete, with a remaining attack path enabling SYSTEM-level file reads and potential full privilege escalation. Microsoft has not yet confirmed or denied the bypass. Workaround: enable additional Defender tamper-protection settings and monitor for MSRC guidance; treat affected endpoints as high-risk until clarified.

Read more →
WARNING🔐 Security

Skype for Business Server CVE-2026-66302: Critical RCE at CVSS 9.8 — LTSC 2021 Loses Support 13 October

September Patch Tuesday includes CVE-2026-66302, a critical remote code execution vulnerability in Skype for Business Server rated CVSS 9.8. Organisations still running the LTSC 2021 edition face a double risk: the vulnerability and an end-of-support deadline on 13 October 2026, after which no further patches will be issued. Workaround: apply the September Patch Tuesday update immediately and plan migration off LTSC 2021 before 13 October.

Read more →
WARNING🔐 Security

Windows DNS Server RCE CVE-2026-69730: CVSS 9.8 Critical — Eight Additional DNS Server RCEs Also Patched

September Patch Tuesday addresses CVE-2026-69730, a critical CVSS 9.8 Remote Code Execution vulnerability in Windows DNS Server, alongside eight additional DNS Server RCEs. Although not yet confirmed as actively exploited, network-reachable critical RCEs in DNS infrastructure represent a high-priority patching target for any organisation running Windows Server in a DNS role. Workaround: apply KB5122871; where possible, restrict DNS management interfaces to trusted subnets.

Read more →
🔥 NETWORKING1 item
CRITICAL🔥 Networking

CISA KEV: Fortinet FortiOS/FortiSwitchManager/FortiSASE CVE-2025-25249 — PivotC2 RAT Campaign Active

CISA added CVE-2025-25249 (CVSS 7.3, heap-buffer-overflow) to the KEV catalog on September 9, 2026, confirming exploitation in a campaign delivering the PivotC2 Node.js RAT with capabilities including interactive shells, tunnelling, and config harvesting. Over 3,000 IPs were targeted and 178 devices infected; a Russia-linked financially motivated actor is assessed responsible. Workaround: restrict CAPWAP/Security Fabric interfaces to trusted sources via local-in policy; permanent fix requires upgrading FortiOS/FortiSwitchManager to patched releases.

Read more →
🤖 AI/TOOLING1 item
INFO🤖 AI/Tooling

Guardz AI-Native MSP Security Platform: ITDR, EDR, Email & Cloud Protection in One Multi-Tenant Console

Guardz is gaining traction as an AI-native unified security platform purpose-built for MSPs, bundling identity threat detection and response (ITDR), SentinelOne-powered EDR, Check Point-powered email protection, cloud data protection, phishing simulations, dark web monitoring, and external footprint scanning in a single multi-tenant dashboard. The platform addresses the growing MSP challenge of alert fatigue across disparate security tools. Australian MSPs evaluating security stack consolidation should include it in their shortlist.

Read more →
Monday, September 14, 2026
Wednesday, September 16, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice