“Pull a list of every client running Palo Alto GlobalProtect or Fortinet FortiGate and call them now — don't email — to confirm patch status or advise immediate segmentation if unpatched.”
Azure Front Door DNS Configuration Change Triggers Widespread M365 Service Disruption
Microsoft pushed an internal configuration update to Azure Front Door (AFD) that corrupted routing configurations, causing broad Azure and M365 service unavailability. Microsoft mitigated the incident by rolling back to a 'last known good' AFD configuration, with customer configuration changes temporarily blocked during recovery. Workaround: Avoid making AFD or Azure CDN configuration changes until Microsoft confirms the block has been lifted; check the Azure Status page.
Read more →West US Azure Network Maintenance Causes Multi-Hour Connectivity Outage for M365 Tenants
A device maintenance window at 14:44 UTC triggered abnormal routing behaviour in the West US Azure region, disrupting connectivity to Azure and M365 cloud services until 19:41 UTC. Engineers identified the root cause as routing anomalies linked to recent network maintenance activity and rolled back the changes to restore service. Workaround: For tenants in affected regions, failover to cached/offline access in Microsoft 365 apps; verify tenant region assignments in the Microsoft 365 Admin Center.
Read more →TP-Link Archer AX90 RCE via TDDPv2 Service — CVE-2026-84682 Disclosed 1 October 2026
CVE-2026-84682 discloses an OS command injection in the TDDPv2 service on TP-Link Archer AX90 V1, exploitable by an unauthenticated adjacent-network attacker to execute arbitrary commands as root during device boot. While no public PoC has been confirmed and it is not yet in the CISA KEV catalog, the attack surface includes any SMB or home-office network using this popular consumer router. Workaround: Disable remote management, isolate the device from untrusted network segments, and monitor for vendor firmware updates.
Read more →IBM Advisory: Palo Alto GlobalProtect Auth Bypass (CVE-2026-0257) & FortiBleed Under Active Broad Exploitation
As of June 2026, IBM X-Force documented broad exploitation campaigns against Palo Alto PAN-OS GlobalProtect (CVE-2026-0257) and a Fortinet SSL-VPN credential-harvesting campaign dubbed 'FortiBleed.' Attackers forge valid authentication cookies by extracting public keys from TLS certificates, bypassing credentials entirely on unpatched GlobalProtect portals. Workaround: Disable authentication override cookies where not required, apply PAN-OS patches, and audit FortiGate SSL-VPN logs for credential exposure indicators.
Read more →Shadow AI Data Leakage Emerging as Top Client Risk — MSPs Urged to Lead Policy Conversations
MSP executives report that employee use of unsanctioned AI tools (shadow AI) is creating significant risk of client IP exposure, with data inadvertently fed into tools like ChatGPT or public LLMs. MSPs that proactively establish AI usage policies and deploy sanctioned tools for clients are positioned to capture a significant advisory revenue opportunity. Consider pairing Microsoft Copilot or private LLM deployments with an AI acceptable-use policy as a billable client engagement.
Read more →MSP GLOBAL 2026 Conference: AI, Cybersecurity & Automation on Agenda — Barcelona, 21–22 October
MSP GLOBAL 2026 runs 21–22 October in Barcelona, with sessions focused on how AI, cybersecurity, and automation are reshaping MSP business models together rather than as separate initiatives. Registration is free for MSPs, MSSPs, resellers, and systems integrators while passes last. Australian MSPs unable to attend in person should monitor session recordings for actionable AI-and-security convergence strategies.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.