“Audit all client environments for Oracle PeopleSoft installations and current patch levels within 24 hours—this breach is live and active exploitation is documented.”
Azure Two-Outage Streak: Gateway & OpenAI Services Hit 18 Regions in 40 Hours
Between September 29 and October 1, 2026, Azure logged two separate outages affecting gateway services across 18 regions, with Azure OpenAI customers in Sweden Central facing failed API calls for nearly six hours. The root cause was a faulty infrastructure OS servicing rollout that Microsoft halted after connectivity failures surfaced; some management-plane errors persisted even after raw connectivity was restored. Workaround: route critical workloads to unaffected regions and monitor the Azure Service Health dashboard for region-specific status.
Read more →Microsoft Patch Tuesday October 2026: Exchange Server EoP Fix — Light Month, No Zero-Days
Microsoft's October 2026 Patch Tuesday released 4 KB updates fixing a single CVE: CVE-2026-96940, a Microsoft Exchange Server Elevation of Privilege vulnerability rated CVSS 8.8. No CVEs were rated Critical, none are listed as actively exploited, and none appear in the CISA KEV catalog as of publication. Admins should still deploy promptly given the high CVSS score and Exchange Server's typical exposure profile.
Read more →ShinyHunters Exploit Unpatched Oracle PeopleSoft CVE-2026-35273 in FBI Contractor Breach
The ShinyHunters threat group exploited an unpatched Oracle PeopleSoft Environment Management Hub endpoint (CVE-2026-35273) to breach an FBI contractor's job portal, with the FBI removing an Accenture contractor on or before October 6, 2026. Attackers used URL-encoding to bypass WAF protections — a known ShinyHunters technique. Organisations running Oracle PeopleSoft should verify patch status for CVE-2026-35273 immediately.
Read more →CISA KEV: 324 Microsoft Patch Updates Now Closing Actively Exploited Vulnerabilities
Senserva's tracker (updated 2 October 2026) flags 324 Microsoft security updates that close vulnerabilities currently under active attack per the CISA KEV catalog, out of 1,092 total tracked updates. With October Patch Tuesday covering only one CVE, unpatched prior-month flaws remain the dominant risk surface. Admins should cross-reference their deployed KB articles against the CISA KEV list to identify gaps.
Read more →SonicWall SMA1000 High-Severity SQL Injection (CVE-2026-4112) Patched – Admin Privilege Escalation Risk
SonicWall patched four vulnerabilities in its SMA1000 series, including CVE-2026-4112, a high-severity SQL injection flaw that allows attackers with read-only admin privileges to escalate to primary admin rights. Three additional flaws could enable VPN credential enumeration or TOTP bypass. SonicWall reports no confirmed in-the-wild exploitation, but urges immediate firmware updates via psirt.sonicwall.com.
Read more →AusAlert Cell Broadcast Emergency System Launched October 1, 2026 — MSP Compliance Awareness
Australia's new AusAlert cell broadcast emergency warning system, replacing the SMS-based Emergency Alert, launched on October 1, 2026 under the National Emergency Management Agency. MSPs supporting clients in emergency services, local government, or critical infrastructure sectors should be aware of integration and compliance obligations the new system may introduce. Review NEMA guidance at ausalert.gov.au for technical specifications relevant to client environments.
Read more →Hosted Network Named CRN Channel Awards Australia 2026 Finalist – Vendor and Leader Categories
Australian wholesale cloud and connectivity provider Hosted Network was shortlisted as Vendor of the Year finalist (alongside Kaseya and Twilio) and CEO Ben Town as a Channel Leader of the Year finalist at the inaugural CRN Channel Awards Australia 2026. The awards covered 31 categories specifically designed for the Australian channel — its first dedicated local program. Hosted Network also picked up a finalist spot at the ARN Innovation Awards 2026 in the Cloud category.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.