GRC PATH| Threat Intel
Weekly · since 2026
For owners who have to know

Cyber threats,
decoded.

A weekly five-minute brief on the cyber risks that could actually take your business off-line, written for the person who signs the checks. No jargon. No alarmism. Just: what changed this week, what it costs you to ignore it, and what to ask your IT person on Monday.

You shouldn't have to learn a second language to run your company.

Every Monday, dozens of new security flaws hit the public. Most are noise. A handful aren't. The ones that aren't can shut down your operations, expose your customer data, or hand your bank logins to a stranger, and they will not call ahead.

This brief reads every public security advisory, throws out the noise, and emails you a five-minute summary on what your business should actually do. Each item is rated, in plain English, by how much it should cost you to ignore it.

It is written by a working cybersecurity practitioner, not a marketing team. Forward it to your IT person, your managed service provider, or your insurance broker. That is the entire job of this email.

What lands in your inbox.

Each item carries one of three urgency labels. That is the whole rating system.

Patch now
Attackers are using this right now. If you are exposed, you have hours, not days. Forward to IT today.
Patch soon
Serious flaw, schedule the fix into this week's change window. Ask your IT person to confirm completion in writing.
Watch
No immediate action required. Keep on the radar in case it escalates next week.
Sample of this week's brief Live

What's on Monday's brief.

Top three items from the brief dated 2026-07-20. Subscribers see the full list of eight, including what to ask your IT person and the patches by version number.

01 Vendor advisory Patch now

Your company's document and file-sharing system got hit again

Microsoft SharePoint, the system many businesses use to share documents and manage internal sites, has a new flaw that lets an attacker with a basic editing account on the site remotely take it over completely. This is a separate problem from the SharePoint issue Microsoft's regular monthly update fixed this same week, meaning SharePoint has now had two serious problems surface in the same short window. Security researchers confirmed attackers are already using it, and they are stealing a specific set of security keys from the server that let them keep access even after you patch. If you run SharePoint on your own servers, rather than through Microsoft 365 online, this is a direct and immediate risk to every document and internal site stored there. Because attackers are stealing persistence keys, patching alone may not be enough if you were already exploited.

Cost of ignoring
Full takeover of your document management and internal collaboration system, with a real chance attackers already have a way back in even after patching, since they steal server keys as part of the attack (CVE-2026-58644).
What to ask IT
If you host SharePoint on your own servers, apply Microsoft's July 14 security update today. If SharePoint is hosted entirely through Microsoft 365 online, Microsoft handles this patch for you, but confirm with your IT provider that no on-premises SharePoint servers exist anywhere in the business. Because attackers are known to steal persistence keys, ask your IT provider to check for signs of prior compromise, not just apply the patch.
Time pressure
Tonight.
Legal exposure
SharePoint sites often hold contracts, HR records, financial documents, and customer data. A confirmed takeover with key theft for persistence is the kind of incident that typically requires a forensic review before you can honestly say the system is clean, and if any regulated data (health records, financial account numbers, employee SSNs) lived on the affected server, breach notification clocks likely start from when you knew or should have known, not from when you finish cleanup.
02 Vendor advisory Patch now

A remote-access device used to let employees work from home was fully hijacked

SonicWall SMA1000, a device many businesses use to let employees securely connect to the office network from home or on the road, has two flaws that attackers are chaining together to take complete control of the device with no login required. SonicWall confirmed real incidents where this has already happened. If your business uses a SonicWall SMA1000 appliance for remote access, this is as serious as it gets, an attacker gets full control of the exact device that decides who can reach your internal network from outside.

Cost of ignoring
Complete compromise of the gateway that controls remote access to your internal network, giving an attacker the same level of access as any employee working from home, without needing a password.
What to ask IT
If you or your IT provider run a SonicWall SMA1000 appliance, update it to the latest platform-hotfix version today. If you are not certain whether your remote-access setup uses this specific device, ask your IT provider directly and treat it as urgent until you get an answer.
Time pressure
Tonight.
Legal exposure
A remote-access gateway sits directly between the outside world and every system your employees can reach from home, including anything holding customer or financial data. If this device was compromised before you patched, a forensic review is warranted, and depending on what internal systems were reachable through it, this can trigger the same notification obligations as a direct breach of those systems.
03 Vendor advisory Patch now

A security appliance meant to catch malware had its own hole exploited

Fortinet FortiSandbox, a security tool that inspects files for hidden malware before they reach your network, has three flaws that let an attacker run commands on it without logging in at all. Fortinet's government cybersecurity partner confirmed these are being actively used in attacks right now. This only applies if your business or IT provider uses a FortiSandbox appliance as part of your security stack. If you do, the irony is real, the tool meant to catch malware became the entry point for it.

Cost of ignoring
An attacker gaining a foothold inside your security infrastructure itself, which can be used to disable detection, move deeper into the network, or plant malware that your own defenses are now blind to (CVE-2026-39808, CVE-2026-25089, CVE-2026-39813).
What to ask IT
If FortiSandbox is part of your security setup, confirm with your IT provider today that the April and June fixes from Fortinet have been applied. If they have not, treat the device as compromised and involve your IT security team immediately.
Time pressure
Tonight.

Get the brief, every Monday.

One short email. Plain English. The threats that matter, the cost of ignoring, the question to ask your IT person.

Single click subscribes you. Your first brief lands the next Monday. Unsubscribe in any issue.