Patch your SharePoint and Fortinet gear now
# Patch your SharePoint and Fortinet gear now
Stop reading the headlines about who is stealing what from which election database for five minutes. I don't care if it's a nation-state or a teenager in a basement; the result is the same. Your data is gone because someone left a door unlocked. While the pundits are arguing over attribution and geopolitical chess, the actual attackers are just walking through the front gate using a handful of keys that CISA has been screaming about for a week.
Look at the current KEV list. We have two Fortinet FortiSandbox flaws—CVE-2026-25089 and CVE-2026-39808—and a SharePoint vulnerability (CVE-2026-58644) that are all being exploited in the wild. For the SharePoint mess, the federal patch deadline is July 19. That's not a suggestion. That's a countdown.
If you haven't patched your SharePoint farm or your Fortinet boxes, don't tell me your "security posture" is strong. Your posture is "sitting duck."
I’ve seen this movie before. Back during the NotPetya disaster, people spent weeks talking about the "sophistication" of the attack. It wasn't sophisticated. It was a combination of a stolen update mechanism and a couple of old-school exploits that worked because people thought they were too small to be targeted. NotPetya didn't care about your company size; it cared about your lack of segmentation. It turned global shipping and logistics into a parking lot in a matter of hours.
Whenever I see the word "sophisticated" in a post-breach press release, I assume the company is lying to its shareholders to cover up the fact that they missed a critical patch for six months. There is nothing sophisticated about an OS command injection. It's a basic failure of input validation. It's the digital equivalent of leaving the keys in the ignition with the engine running and a sign on the dashboard that says "Please Steal This Car."
The real danger here isn't just the immediate breach. It's the second-order effect. Think about your Managed Service Providers (MSPs). If your MSP is managing your Fortinet gear across fifty different clients and they haven't patched their own management plane, one hole doesn't just compromise one company. It gives the attacker a skeleton key to every single one of those fifty networks. You aren't just trusting your own team; you're trusting the lowest common denominator of your vendor's patching schedule.
Some of you will argue that you have a WAF or an EDR that should catch this. That's a dangerous bet. A WAF is a speed bump, not a wall. Once an attacker has a working exploit for an OS command injection, they aren't knocking on the door; they're already inside the house, and they're changing the locks.
***
**MAILBAG**
**Gary from Des Moines: "I keep seeing news about 'sophisticated' state-sponsored actors. As a small shop owner, do I need to buy expensive AI-driven tools to defend against that kind of thing?"**
Gary, listen to me. You don't need a magic AI box. Most of the people who get hit by "state-sponsored" actors didn't get hit by a laser-guided missile; they got hit because they didn't change a default password or they're running a version of Windows from 2014. The attackers don't start with the fancy tools; they start with the easy ones. Keep your software updated, use MFA on everything that allows it, and keep your backups offline. If you do those three things, you're already harder to hit than half the Fortune 500.
**Sarah from Chicago: "The Windows LegacyHive zero-day is worrying me. I can't patch everything instantly. If I see an admin account acting weird, what's the first move?"**
Isolation. I don't care if it's the CEO's account or the Lead Admin's. If the telemetry looks wrong, you kill the session and disable the account immediately. You can apologize for the downtime later; you can't apologize for a total domain collapse. If LegacyHive is giving out admin privileges, your only real move is to shrink the blast radius. Cut the connection, dump the logs, and then figure out how they got in. Don't try to "watch and learn" while they're in the system. By the time you've learned something, they've already encrypted your backups.
**Marcus from Atlanta: "AssuranceAmerica just leaked driver's license numbers for nearly 7 million people. I'm a client. What actually happens to my data now?"**
It's on a forum or a private Telegram channel. It's probably already been scraped by a dozen different groups. Your driver's license number is a static identifier—you can't exactly change it like a password. This is where the "cost on a Tuesday" comes in. For you, it means your identity is now a commodity. You should be looking at freezing your credit and monitoring your accounts for the next few years. For AssuranceAmerica, it means a massive legal bill and a reputation that's currently in the shredder.
***
We're seeing a lot of noise this week. Over 380 data breach stories and north of 230 vulnerability reports. It's easy to get paralyzed by the volume. But the volume is a distraction.
The only thing that matters is the distance between the disclosure of a flaw and the moment you hit "update." If that window is more than 72 hours, you're gambling with the company's life.
I wonder how many of you are currently relying on a "legacy" system that you're too afraid to patch because you think it'll break the app. You're choosing a slow death over a quick surgery. Just remember: the attackers are more than happy to break your app for you.
◼