Happy Thursday, nerds — good to be back in the chair, broadcasting from the new South Union Street office here in Traverse City; we’ve got three stories worth your attention today: a credential-harvesting campaign that quietly cracked 75,000 Fortinet firewalls across 194 countries, a ransomware report that should make every manufacturer in your industry group uncomfortable, and a Microsoft 365 update that’s actually worth knowing about before you renew another standalone AI subscription.
Let’s get into it.
Or watch on YouTube.
FortiBleed: 75,000 Firewalls, 194 Countries, and Not a Single New Vulnerability
The campaign has a name now — FortiBleed — and the number that should stop you mid-sip is 75,000. That’s how many internet-facing FortiGate firewalls had their administrator credentials harvested. Not guessed. Harvested. Quietly, methodically, starting back in June.
What makes this one sting is how it was done. The attackers didn’t find some brilliant zero-day. They chained together already-disclosed Fortinet flaws — vulnerabilities that had patches available, that had been in the security bulletins, that your IT provider should have been applying. This is the part that frustrates me every single time I see this pattern: the breach wasn’t inevitable. It was optional.
With valid admin credentials in hand, an attacker can log into your firewall remotely, change your security rules, open ports, and essentially redecorate your network perimeter however they like. You’d have no idea. The firewall would still be sitting there in the rack looking perfectly normal.
Some context on why this matters beyond the headline number: Fortinet has been one of the most popular firewall and VPN platforms for small to mid-size businesses for over a decade. The reason is straightforward — enterprise-grade features at a price point that doesn’t require an enterprise budget. We deploy FortiGate for our high-security clients. It’s a good product. Which is exactly why this is bad. When the premier option gets hit like this, it’s a signal about the whole category, not just one vendor.
Alert readers will also want to know that Fortinet has been actively phasing out SSL VPNs — the simpler but less secure VPN type — in favor of IPsec VPNs, which are considerably more secure and considerably more annoying to set up. We’ve been migrating clients through that transition. It’s the right call, even when it’s a headache.
So what do you actually do right now? A few things. First: your FortiGate’s admin management console should never be accessible to the open internet. If it is, that’s the first thing to fix. Second: rotate your admin passwords. Third, and this is the one people skip — log into your admin panel and audit the list of administrator accounts. If there’s an account in there you don’t recognize, you have a remediation problem on your hands, not just a security concern. Fourth: if you’re an ACS managed client, our managed firewalls are only accessible through our own private VPN — you have to get into our network to get to the firewall at all. That layer matters.
If you have a FortiGate and you’re not sure whether it’s exposed, that’s a five-minute check. Worth making the call.
1,140 Manufacturers Hit by Ransomware in One Quarter — Without Touching a Single Machine
Cybersecurity firm Dragos released their Q2 2026 industrial ransomware report, and the headline number is 1,140 ransomware incidents at industrial and manufacturing organizations. That’s roughly twelve attacks every day. Manufacturers absorbed the worst of it — 747 of those incidents landed on the shop floor sector.
The sub-headline is the part worth sitting with: “without touching a single machine.” What that means is the attackers aren’t hacking into your CNC controllers or your programmable logic systems. They don’t need to. They go after the office IT — your ERP system, your file shares, your order processing. They encrypt it, or they steal it and threaten to publish it, and suddenly you can’t process orders, you can’t ship product, and you’re getting a ransom demand in your inbox.
For years, the assumption in manufacturing has been that air-gapping the shop floor — keeping the production machines off the internet — was sufficient protection. And look, air-gapping the machines is correct. You should absolutely do that. But it was never the whole answer. The back office was always the softer target, and that’s where the money is for the attackers anyway.
There’s also the USB problem, which I think about more than most people want to hear about. A machine operator brings a drive from home, plugs it into the workstation connected to that CNC, and if that workstation is sitting on your main company network instead of an isolated segment — you’ve got a very bad afternoon ahead of you. Network segmentation isn’t glamorous. It doesn’t show up on a sales brochure. But it’s the difference between an incident that stays contained and one that takes down the whole operation.
And if you’re a manufacturer doing any kind of Department of Defense contract work, the stakes are higher still. Data theft from that environment isn’t just an operational problem — it’s a compliance and contractual problem that follows you for a long time.
The checklist here is short but not negotiable: make sure your production machines are on an isolated network segment, not your main company network. Make sure you have tested, offline, immutable backups — and tested is doing real work in that sentence, because a backup you’ve never restored from is just a hope, not a plan. And make sure whoever is handling your IT can actually describe your layered defense to you in plain language. If they can’t explain it, it probably doesn’t exist.
Microsoft 365 Just Gave Every Business Subscriber Copilot Notebooks — Here’s What That Actually Means
Microsoft rolled out a significant August 2026 update to Microsoft 365, and the part that affects you immediately is this: Copilot Notebooks, the AI-powered workspace for brainstorming and drafting, is now available across all Microsoft 365 commercial licenses. Not just the premium tiers. All of them.
That’s actually a meaningful shift. The standalone Copilot for Microsoft 365 add-on was $30 per user per month — a number that made a lot of small business owners close the browser tab pretty quickly. Microsoft has been on an aggressive push to embed AI into every layer of 365, and bringing Copilot Notebooks down to the base license is how they get adoption numbers up and switching costs higher. They want you dependent on it. That’s not a conspiracy theory, that’s just how platform lock-in works, and Microsoft is very good at it.
The update also introduces something called Copilot Cowork, which lets you build custom workflow automations inside Microsoft 365 Teams. That one requires IT admin approval to activate — it doesn’t just turn on. Which is the right call, because handing workflow automation to an organization without any guardrails is how you get very creative, very expensive mistakes.
Personally, I use Claude extensively for my own work right now, and I’ve been moving a lot of my agentic workflows to Grok because the price-to-performance ratio is hard to argue with. Claude still has an edge for programming tasks, in my view. The Microsoft update is powered by both GPT and Claude models, which is interesting — I’d want to know which Claude model specifically, but that detail wasn’t in the release.
The practical thing to do before your next software renewal: log into your Microsoft 365 admin center and check what Copilot features are now available to you. If you’ve been paying for a standalone AI writing or workflow tool, you may already have something comparable included in what you’re already paying for. Worth checking before the next invoice hits.
Anyway. That’s the show for this week — three stories, all of them with something real to do on the other side of reading them. Stay patched, segment your networks, and check your admin accounts. I’ll be back at it next Thursday.
— Albert
Questions about anything we covered today? Schedule a free IT consultation and we’ll walk through it with your business in mind.
