Sober Thoughts. Drunk Posts.

Another “Sunday Newsletter” With Threats That Don’t Take Days Off

Another “Sunday Newsletter” With Threats That Don’t Take Days Off

Another zero-day patched just in time for no one to notice. Yep, it is Sunday, September 27, 2026, and the security ecosystem is doing what it always does: handing you a stack of problems, then acting surprised when your environment still has the “temporarily-unpatched” corner that attackers love to sleep in.

This week’s top story chaos is simple. Microsoft SharePoint flaw CVE-2026-65660 is now exploited in attacks, with CISA adding it to the KEV catalog and setting a September 28 patching deadline. Because nothing says “we take security seriously” like a clock starting that is basically already behind schedule.

The Only Real KEV Catalog That Matters Is Your Reality

For the uninitiated: KEV listings exist for a reason. They identify vulnerabilities that are known to be actively exploited, which means your threat model is not theoretical. It is not “someday.” It is not “we’ll get to it after the next change window.” It is not “let’s wait for the vendor to clarify.” It is attackers doing reconnaissance like it is their job (because it is).

And the timeline? A patching deadline of September 28 means either you already fixed it, or you are doing the classic IT routine: staring at tickets, asking for approvals, and hoping the internet behaves while you do paperwork. Meanwhile, the bad guys are not reading your ticketing system. They are reading SharePoint.

Why Vendors and CISOs Keep Selling “Resilience” Like It Is a Feature

Let’s talk about the favorite industry pastime: vendors shipping complexity faster than defenders can patch it, then CISOs proudly announcing “risk management” dashboards while the actual risk is sitting right there in your SharePoint farm. The best part is the predictability. Once a CVE hits KEV, the pattern is always the same: exploit drops, defenders scramble, and then someone writes a retrospective memo titled something like “Lessons Learned” with zero measurable changes.

You can pour the scotch, shake the rum, and do a little scotch-and-sanity ritual all you want, but the solution is still boring: patch, verify, and hunt.

What You Should Do Instead of Buying Another Tool

Since CVE-2026-65660 is already exploited, stop treating this like a “monitoring” problem. If you have SharePoint systems in scope, act like you are on a live fire drill:

First, patch immediately (or isolate and mitigate if patching is impossible right now). Second, confirm the update is actually applied across all relevant instances. Third, check for suspicious activity in SharePoint related logs and any integrated components. Fourth, review access paths – because attackers love the legitimate routes you left wide open.

Also, do not rely on “we have EDR.” Attackers do not need to bypass EDR if they just go where they are invited. Security that assumes perfect defense is just hope wearing a press release tie.

If you want the original details, start here: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks.

Tags :
Sober Thoughts. Drunk Posts.
Share This :