In 30 seconds
- If your firewall or VPN is internet facing and still using old, shared, or leaked credentials, you are not "at risk", you are already on someone's shopping list.
- The edge is the new front door. Attackers are not breaking in through Hollywood hacks, they are logging in with what organisations forgot to rotate.
- Microsoft's latest patch wave is a reminder that "we will do it next month" is not a plan when zero-days are in play.
Why it matters
This week's theme is simple: the stuff you rely on to keep people out is now being used to let people in.
FortiBleed is not interesting because it is clever. It is interesting because it is mundane. Credentials tied to Fortinet devices were exposed at scale, and CISA is explicitly telling organisations to harden devices because attackers are already using what is out there. For regulated businesses, that is the nightmare scenario. Not a breach that starts with a phishing email, but a breach that starts with remote access you assumed was "fine" because it has always been there.
If you are a financial services firm, a law firm, a government body, or a medical practice, your edge devices sit in the worst possible place. They are internet facing, they often have privileged access behind them, and they tend to be owned by "IT" rather than "security". That gap in ownership is where incidents start. The practical takeaway is not "buy a new firewall". It is to treat edge access like a regulated control. Lock down management access, rotate credentials, enforce MFA, and make sure you can prove who logged in and when.
Now connect that to the Microsoft patch cycle. Patch Tuesday stories can feel like background noise, until they are not. When multiple zero-days are fixed in one month, it is a signal that attackers have working paths into common business environments. In the Channel Islands, most organisations run Microsoft heavily. That means patching is not an IT hygiene task, it is a business continuity control. The organisations that do well are the ones that can patch quickly without drama, because they have a repeatable process, clear ownership, and a short list of systems that always get done first.
Practical advice for this week:
- Treat all internet facing remote access as "assume hostile". Reduce exposure, restrict by IP where you can, and monitor logins like you mean it.
- Stop relying on "we changed the password once". Rotate credentials on a schedule, and rotate immediately after any credible exposure.
- Run patching like a business process. Triage first, patch the high risk systems first, then mop up.
Questions to ask your team this week
- 1.Which of our firewalls, VPNs, and remote access portals are internet facing, and who is accountable for hardening and monitoring them?
- 2.When did we last rotate admin and service credentials on edge devices, and do we enforce MFA for all administrative access?
- 3.Can we prove, from logs, every successful admin login to our edge devices over the last 30 days?
- 4.What is our "48-hour plan" for deploying urgent Microsoft security updates to servers and endpoints, without breaking critical services?
One thing to do this week
Run a 30-minute "edge access lockdown" session: list every internet facing firewall and VPN, confirm management access is not exposed to the internet, rotate all admin credentials, and enforce MFA for admin logins.
Sources
- CISA, "CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure" (18 June 2026):
https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure - Fortinet PSIRT, "Analysis of Reported Credential Compromise of FortiGate Devices":
https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices - UK NCSC, "Advice following global targeting of Fortinet firewalls and VPN gateways":
https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways - BleepingComputer, "Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws":
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/ - Microsoft MSRC, "Security Update Guide, 2026-Jun release notes":
https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun

