“Pull your SonicWall and Windows update inventory today, prioritize any Gen 6 appliances and unpatched systems, and get clients to confirm receipt of both zero-day and privilege-escalation advisories before they ask why their email is down.”
Microsoft 365 Outage Wave Continues: Five Major Incidents in Six Months
Microsoft has recorded five significant cloud outages in six months spanning Azure Front Door, Teams, Outlook, Copilot, and Exchange Online — the latest knocking services offline for over nine hours across North America with cascading impact into Australian tenants. The root cause of the most recent event was attributed to reduced capacity during infrastructure maintenance in a North American subset. Workaround: Enable failover to on-premises mail flow or backup MX where available; monitor the Azure Service Health dashboard for real-time status.
Read more →Skype for Business Server LTSC 2021 Reaches End of Support 13 October 2026
Microsoft's September 2026 Patch Tuesday highlighted that Skype for Business Server LTSC 2021 exits support on 13 October 2026, with the final patch cycle including CVE-2026-66302, a critical RCE rated CVSS 9.8. Organisations still running on-premises Skype for Business infrastructure have only days to migrate or accept unsupported risk. No workaround exists for end-of-support; migration to Teams Phone is the recommended path.
Read more →APT28 Exploiting Windows Zero-Days CVE-2026-21509 and CVE-2026-32202 in Targeted Email Campaigns
Proofpoint threat intelligence confirms APT28 exploited two Windows vulnerabilities — CVE-2026-21509 (Windows Shell security bypass) and CVE-2026-32202 (incomplete patch bypass for CVE-2026-21510) — within days of disclosure, using RTF attachments with embedded LNK files and WebDAV-hosted payloads. Both CVEs are now tracked in vendor telemetry across more than 5,000 network sensors. Workaround: Block WebDAV at the perimeter, disable auto-execution of LNK files, and deploy the latest Windows cumulative update immediately.
Read more →Windows Elevation of Privilege CVE-2026-68820 Actively Exploited in the Wild — August Patch Still Relevant
Microsoft confirmed CVE-2026-68820, a Windows Elevation of Privilege vulnerability, is under active exploitation in the wild, disclosed during the August 2026 Patch Tuesday cycle. Organisations that have not applied the August cumulative update remain exposed ahead of the October 13 patch cycle. Workaround: Apply the August 2026 cumulative update; audit privileged account usage and review local administrator scope across endpoints.
Read more →Exploitation Mean Time Now Negative Seven Days — Defenders Falling Further Behind
Mandiant's M-Trends 2026 report places the mean time to exploit at approximately negative seven days, meaning attackers are weaponising vulnerabilities on average a week before a vendor patch is available. Verizon's 2026 DBIR also found the median remediation time for critical vulnerabilities has risen to 43 days, with only 26% of CISA KEV entries fully remediated. MSPs should accelerate vulnerability triage SLAs and invest in exploit-prediction tooling such as EPSS scoring.
Read more →SonicWall Gen 6 Hardware Approaching End-of-Life — October 2026 Final Deadline
SonicWall Generation 6 appliances (including TZ 300, TZ 400, TZ 500, NSA series) are reaching their final end-of-life dates across April–October 2026, meaning no further security patches will be issued for these devices. MSPs running clients on Gen 6 hardware are now at maximum exposure with no vendor remediation path available. Action required: Accelerate hardware refresh conversations and migrate affected clients to Gen 7 or Gen 8 platforms before CVEs targeting these units go unpatched.
Read more →SonicWall SMA1000 SQL Injection CVE-2026-4112 Allows Privilege Escalation to Primary Admin
SonicWall patched CVE-2026-4112, a high-severity SQL injection flaw in its SMA1000 series firewalls, which allows an attacker with read-only administrator credentials to escalate to full primary admin rights. Three additional vulnerabilities in the same patch round allow SSL VPN credential enumeration and TOTP authentication bypass. Workaround: Apply SonicWall's patch immediately; restrict SMA1000 management access to trusted IP ranges only.
Read more →ConnectWise Sidekick Delivers 70+ AI-Assisted Actions Across PSA and Cyber Defence
ConnectWise's Sidekick AI layer now includes over 70 AI-assisted actions spanning ticket summarisation, sentiment analysis, response generation, and AI-powered PowerShell scripting, embedded across its PSA, RMM, and cybersecurity modules. The scripting capability allows technicians to generate, refine, and execute remediation scripts with AI assistance, reducing manual effort. This positions ConnectWise's ecosystem as a strong contender for MSPs looking to consolidate AI tooling within a single vendor stack.
Read more →MSP AI Summit Scheduled 14–16 October 2026 — Free Virtual Event Covering Secure AI Foundations
A free three-day virtual MSP AI Summit runs 14–16 October 2026, with twelve sessions across secure AI foundations, scaled service desk automation, and documentation workflows, plus three hands-on labs. Sessions are recorded, making it accessible for Australian MSPs across time zones. Registration is open now — a useful CPD opportunity for technical and management staff heading into the Q4 planning cycle.
Read more →CRN Channel Awards Australia 2026 Results: Otto IT, Interactive, and Orro Take Top MSP Gongs
CRN Australia's inaugural Channel Awards named Otto IT as MSP of the Year (0–49 employees), Interactive as MSP of the Year (100+ employees), and Orro as MSSP of the Year, with Kaseya winning both Vendor of the Year and Channel Leader of the Year. LogicMonitor took the new AI and Automation Vendor of the Year category, and First Focus won AI Initiative of the Year. The awards reflect a maturing Australian channel with strong competition across all size tiers.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.