
Microsoft shipped 999 security fixes on September's Patch Tuesday, the most it has ever released in a single day, and two of the flaws were already being used in real attacks before the patches existed. Most of the coverage reads like a parts list. Here is what the release means for a professional-services firm with a few dozen Windows machines, a Microsoft 365 tenant, and no dedicated patching team.
Volume is the obvious part: 974 of the 999 fixes are in Microsoft's own products, and 723 of those are in Windows. Rapid7, which tracks every cycle, says there is no reason to expect a return to the smaller monthly batches of past years. The less obvious part is the shape of the two flaws already being exploited. Both are local privilege escalation bugs, CVE-2026-85880 in a Windows kernel component and CVE-2026-81963 in the Windows Update Stack. Neither lets an attacker in from the internet. Both let an attacker who is already on a machine as an ordinary user become SYSTEM, which is the step that turns one phished mailbox into control of the network.
That matters because the way small firms actually get breached is a staff member running something they should not have, or a stolen session, not a movie-style remote exploit. A bug that upgrades a foothold is worth more to an attacker than a flashy one that creates it.
Two wrinkles change the to-do list. CVE-2026-85880 has no patch for Windows 11 or Windows Server 2025, so the fix only applies to older builds, and you need an inventory to know which machines those are. Separately, a browser flaw Google patched in Chrome on September 3 was already being exploited, and while Microsoft pushed the fix to Edge on September 2, it has not published an advisory, so nothing in your normal update reports will tell you whether a given Edge install has it.
Four places, in rough order of how often we see them matter.
Staff laptops and desktops. This is where the two exploited bugs live. Any machine where a low-privilege foothold is plausible, which is every machine that receives email, is in scope. Terminal servers, jump boxes, and any workstation that runs a remote-management agent go first.
Remote access. If you publish Remote Desktop Services or a Remote Desktop Gateway so contractors or remote staff can reach the office, this month's Remote Desktop flaw is rated 9.8 and flagged by Microsoft as exploitation more likely. That single item can justify pulling the patch ahead of your usual schedule.
Exchange, if it is still on your premises. Four Exchange fixes this month, including a spoofing flaw rated 9.3 and a privilege escalation at 9.1. Mail server compromise typically produces exactly the outcomes your insurer and your regulator ask about: mailbox access, invoice fraud through internal-looking senders, and notification obligations once message content is confirmed exposed. Exchange 2016 and 2019 also lose support on October 14, 2026, with no paid extension offered, as do Office 2021 and Windows Server 2012 and 2012 R2. Anything in those categories stops receiving fixes for problems like these next month.
Identity. The highest scores in the release are in Microsoft's cloud identity services, including two rated a maximum 10.0, plus a flaw in the Microsoft Authenticator app rated 8.6. The service-side ones are Microsoft's to fix. The Authenticator one sits directly in the multi-factor path most firms rely on, and it is on your phones, not Microsoft's servers.
You do not have to patch 999 things this week. You have to make a documented decision about a short list.
Where a machine cannot be patched this cycle, remove standard users from the local administrators group and limit which accounts can log on to management hosts. That does not fix the flaw, but it shortens what an attacker can reach after escalating.
One more point for the firms that answer to an auditor. HIPAA, PCI DSS, and CMMC obligations commonly define a patch window for critical vulnerabilities, and a release this large makes the triage decision itself the evidence an assessor may ask to see. Write down what you patched first, what you deferred, and why. That record can be worth as much as the patches.
The full breakdown, including the CVE-by-CVE sequencing and detection guidance for your IT team, is in our Threat Intelligence Center write-up. If you are not sure which of the four exposure groups above applies to your firm, a security assessment answers that in an afternoon.
A malware family called TWINLOOT routes its command-and-control through Microsoft's own cloud — SharePoint, Teams, and the Graph API — so the domain blocklists and web filters built to catch an intrusion never see it, and it leaves no trace in your Microsoft 365 sign-in logs. Here's what that means for a professional-services firm, and the one question worth putting to your IT team.
Read more: When Your Own Microsoft 365 Becomes the Attacker's Channel

Blog • August 11, 2026
N-able's 2026 State of the SOC Report, built on data from the Adlumin SOC platform, lands on one finding every firm running endpoint protection should stop and consider: 50% of the attacks observed in 2025 bypassed endpoint controls entirely.
If your security strategy starts and ends with antivirus or EDR, that number means half of last year's attacks would have been invisible to you.
Key Insight
Half of 2025's attacks bypassed endpoint controls entirely — they moved through the network, perimeter, and identity layers that endpoint tools don't watch. — N-able 2026 State of the SOC Report
Here's why. Endpoint tools watch the endpoint — malware execution, suspicious processes, credential theft from memory. They're good at it. But a large share of modern attacks never runs anything on an endpoint until the very end. Network reconnaissance, lateral movement between systems, firewall and VPN exploitation, offline password cracking, identity attacks in the cloud — none of it generates an endpoint alert. By the time something does, the attacker has usually been inside for hours.
The Adlumin data puts numbers on it. Across 2025, the network and perimeter layers caught 137,187 threats that endpoint-only monitoring would have missed. Many weren't minor — they were the opening stages of attacks that would have become full breaches without visibility at those layers.
The same report explains why response speed matters as much as visibility. When a VPN login from an unusual location, internal SMB scanning, and a PowerShell execution show up separately, each looks ambiguous on its own. Correlated across layers, they read as an active compromise.
We watched a version of this play out in one of our own managed environments last Thanksgiving. A client traveled out of state for the holiday, logged in to get some work done, and was immediately flagged for signing in outside their normal area. SentinelOne on the laptop saw nothing wrong — because nothing on the laptop was wrong. The signal only existed in the layers around it. Adlumin correlated the sign-in with what our managed SonicWall appliance was seeing, and the SOAR weighed the context: a company laptop, a clean authentication, the VPN's two-factor prompt answered correctly. No aggravating circumstances, so it stopped at notifying me. Other cases have gone the other way — clients who left the country without telling us were automatically isolated from the network, applications, and resources until we confirmed it was really them. Same detection either way; the response matched the risk.
This is what the Capstone Threat Intelligence Center tracks: daily analysis of active threats — credential campaigns, perimeter exploits, the techniques showing up most often in professional services — and what each one means for the firms we manage.
Brian Sammons has managed IT environments for Ohio professional service firms since 2004. Capstone Technologies Group provides managed security services including firewall management, endpoint protection, backup, and 24/7 threat monitoring for medical practices, law firms, and accounting firms across the Dayton, Columbus, Cincinnati, and Springfield markets.
Questions about what your current tools can and can't see? Schedule 15 minutes and I'll walk you through it.
Announcement • June 01, 2026
Brian here. We've started publishing daily threat intelligence analysis at the Capstone Threat Intelligence Center.
The Threat Intelligence Center tracks active threats targeting the types of environments we manage — credential theft campaigns against Microsoft 365, malware delivery methods, phishing techniques, vulnerability disclosures, and the attack patterns that show up most often in professional services firms.
We monitor threat feeds throughout the day, score articles by relevance and severity, and publish analysis with context on what each threat means for managed environments. When a credential theft campaign targets Office 365 users — like the Storm-2755 attack we tracked last week that manipulates search results to redirect employee paychecks — the analysis publishes the same day.
Articles post to the Threat Intelligence Center daily and distribute across our social channels. The highest-priority threats get featured on LinkedIn each morning.
Starting this week, I'm also publishing a weekly summary on the blog — the two or three threats from the prior week that matter most for Ohio professional service firms, with context on what we're seeing and what it means for your environment. The first one is up now: SonicWall's 2026 Report Confirms What We See Every Week.
Windows 10 support ends October 14, 2025—just two weeks away. Microsoft recently announced extended security updates offering free and affordable options for the first time. With over 400 million Windows 10 PCs still in use and millions unable to upgrade due to strict hardware requirements, understanding your options is critical. Here's everything you need to know to protect your business systems and make informed decisions before the deadline.
Read more: Windows 10 End of Life: Your Free Security Bridge Explained
Page 1 of 3