The MSP Security Gap

Turn security gaps into sales opportunities with weekly attack scenarios

Turn security gaps into sales opportunities with weekly attack scenarios

Two weeks' notice. Then the downloads.

The scenario:

An account manager at a mid-size accounting firm handed in their notice on a Friday. Standard two weeks, no drama, a reasonably amicable departure by every outward sign.

Nobody adjusted their system access that day, because the process for that was tied to the actual last day of employment, still two weeks out.  

How it unfolds:

Over the following ten days, the departing employee downloaded a large volume of client files to a personal cloud storage account, spread across enough sessions and small enough batches that no single event triggered an alert.

They were not planning anything malicious in a legal sense. They believed the client relationships they had built were partly theirs to take to a new employer, a belief that is common and still a serious data exposure regardless of intent.

The firm did not find out until a client at the new employer mentioned having received outreach that referenced information only the accounting firm should have had. 

The warning signs:

  • A noticeable increase in file access or downloads from one user's account in the weeks following a resignation 


  • Access to client files outside that person's usual working pattern, including files unrelated to their current active projects 


  • Uploads to a personal cloud storage or email service from a company device, especially in volume 

Stop it:

  • Reduce access immediately upon resignation notice to what is needed for a clean handoff, not what the role has always had 


  • Monitor for unusual data movement from any account in a known notice period, treating it as a standard part of offboarding rather than an accusation 


  • Have a clear, communicated policy about what data belongs to the firm and what a departing employee is and is not permitted to take, reviewed at the exit interview, not assumed 

    -

    P.S. Most exfiltration during a notice period is not planned in advance. It happens because access does not shrink the moment intent to leave becomes known, and two weeks is a long time to hold full access while thinking about what comes next.


    Behavioral monitoring that flags a change in access pattern, not only a known bad actor, is what catches this before it becomes a client conversation nobody wants to have.

Patch first this week:



Four entries this week, and the first one is your own toolbox. Here is what to check across your client base. 

  1. ConnectWise ScreenConnect: files pushed and run through a live remote session 


Product: ConnectWise ScreenConnect, the remote support and access client. 

Who runs it: you do, or your peers do. This is the tool sitting on every endpoint you support. The flaw is in the client, not the server. 

The action: update every ScreenConnect client to version 26.6.5 or later. Do not stop at the server. Walk the client estate and confirm the version on each machine, then review recent session logs for file transfers nobody requested. 

The urgency: CVE-2026-84869 is rated CVSS 9.9. A condition in the client lets files be transferred and executed through an active remote session without authorization or host confirmation. Huntress documented three separate incidents where attackers used ScreenConnect to push a malicious VBScript to newly connected machines, which is how a support tool turns into a distribution channel. ConnectWise published its bulletin on September 8. CISA added the flaw to the Known Exploited Vulnerabilities catalog on September 11 with a federal deadline of September 14, which has already passed by the time this email lands. If your clients are still on an older build, treat that as exposure you are carrying on their behalf. 


  1. Cisco Secure Firewall Management Center: unauthenticated root on the box that manages the firewalls 


Product: Cisco Secure Firewall Management Center, the on-premises console for Cisco firewalls. 

Who runs it: mid-market and enterprise clients with Cisco firewall estates, and any client whose previous provider left an FMC appliance behind. 

The action: apply the fixed release named in Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. Take the FMC web interface off any interface reachable from the internet and restrict it to a management network. Then check for unexpected local accounts and review the box for signs of prior access. 

The urgency: CVE-2026-20079 is rated CVSS 10.0 by Cisco. An unauthenticated attacker sends crafted HTTP requests and gets root on the underlying operating system, which means control of the console that pushes policy to every firewall behind it. Cisco updated its advisory to confirm exploitation attempts starting in August 2026, and the flaw has been tied publicly to Qilin ransomware activity. CISA added it to the KEV catalog on September 9 with a federal deadline of September 12. That deadline is gone. Anything still unpatched should be handled as a possible compromise rather than a queued job. 


  1. Fortinet FortiOS and FortiSwitchManager: crafted requests to the cw_acd daemon 


Product: Fortinet FortiOS, which runs FortiGate firewalls, plus FortiSwitchManager and FortiSASE. 

Who runs it: a large share of your SMB client base. FortiGate is one of the most common firewalls in the mid-market. 

The action: upgrade to FortiOS 7.6.4, 7.4.9, 7.2.12 or 7.0.18 or later, depending on your branch. FortiSwitchManager needs 7.2.7 or 7.0.6 or later. Refer to Fortinet advisory FG-IR-25-084 for the exact target for each install. 

The urgency: CVE-2025-25249 is a heap-based buffer overflow rated CVSS 7.3 that lets a remote unauthenticated attacker run code through specially crafted requests. Affected branches run from FortiOS 6.4.0 through 7.6.3, which covers a lot of firewalls that have been sitting untouched. Fortinet published the fix in January 2026. CISA only confirmed exploitation and added it to the KEV catalog on September 9, with a federal deadline of September 12 that has now passed. The gap between patch availability and confirmed exploitation is exactly the window attackers work in. 


  1. MikroTik RouterOS: an SSH username that hands back an admin session 


Product: MikroTik RouterOS, on MikroTik routers and switches. 

Who runs it: smaller clients, branch sites, and anyone who inherited a cheap router from a previous provider. MikroTik shows up in budget-conscious deployments and in places nobody has looked at in years. 

The action: update to RouterOS 6.49.21, 7.23.4 or 7.24.2 or later, released September 3. If you cannot patch today, restrict or disable SSH, the web interfaces and the bandwidth-test service so they are not reachable from the internet. After patching, check the log for the flagged marker the new builds write when they find configuration changes that should not be there. 

The urgency: CVE-2026-86060 is a privilege escalation flaw rated CVSS 9.2, where an SSH username beginning with a disallowed character returns a session with full administrative rights. CVE-2026-67277, rated CVSS 8.8, lets unauthenticated connections reach the bandwidth-test service and leak kernel memory or crash the device. Chained together, the pair is being used to take over routers with no credentials at all. CERT Polska named the chain MikroTrick and reported active exploitation. CISA added both CVEs on September 10 with a federal deadline of September 13, already behind us. A compromised edge router gives an attacker a view of everything behind it, so patching alone is not enough. Check the configuration.