“Audit all M365/Azure tenants for Defender version compliance today and push emergency patches to any client running pre-current versions before end of business.”
Unpatched Microsoft Defender 'ShieldBreak' Bypass PoC Released Hours After Patch Tuesday
Approximately two hours after Microsoft's September 8 Patch Tuesday release, researcher MSNightmare published a proof-of-concept targeting Microsoft Defender, claiming the patch for CVE-2026-69414 (ShieldBreak) was incomplete and that an alternate attack path enabling SYSTEM-level file reads remains open. Microsoft has not yet issued a supplemental fix. As a workaround, organisations should apply additional Defender configuration hardening and monitor for unusual SYSTEM-level file access.
Read more →Windows Biometric Service: 64 EoP CVEs Patched — Systemic Authentication Subsystem Weakness
September Patch Tuesday addressed 64 separate elevation-of-privilege vulnerabilities in the Windows Biometric Service (fingerprint and facial recognition), suggesting a systemic architecture weakness rather than isolated bugs. SQL Server received 61 CVE fixes and Windows DHCP Server 50 — all infrastructure-critical services often exposed internally. Ensure Windows Update is current across all server and endpoint fleets.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.