<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Firewall Technical IT Insights</title>
    <description>The latest articles on DEV Community by Firewall Technical IT Insights (@firewall-technical).</description>
    <link>https://dev.to/firewall-technical</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4142359%2Fc2c72466-7dec-4f6b-8946-4373dad66bd8.jpg</url>
      <title>DEV Community: Firewall Technical IT Insights</title>
      <link>https://dev.to/firewall-technical</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/firewall-technical"/>
    <language>en</language>
    <item>
      <title>When Security Tools Become the Target: What Recent Cyber Alerts Tell Us</title>
      <dc:creator>Firewall Technical IT Insights</dc:creator>
      <pubDate>Fri, 02 Oct 2026 21:24:00 +0000</pubDate>
      <link>https://dev.to/firewall-technical/when-security-tools-become-the-target-what-recent-cyber-alerts-tell-us-593m</link>
      <guid>https://dev.to/firewall-technical/when-security-tools-become-the-target-what-recent-cyber-alerts-tell-us-593m</guid>
      <description>&lt;p&gt;In September 2026, the Canadian Centre for Cyber Security published a cluster of alerts about vulnerabilities in three different security products: a Forcepoint firewall platform, an F5 remote-access gateway, and Cisco's identity and access-control system. These are separate products with separate jobs, made by separate vendors. What connects them is their position in the network. Each one sits in a trusted spot, deciding what traffic is allowed, who gets access, and which devices are recognized.&lt;/p&gt;

&lt;p&gt;These alerts do not describe every threat facing Canadian businesses, and three advisories do not prove that attacks are becoming more advanced. What they do illustrate is a strategy worth understanding: attackers look for weaknesses in the very systems organizations rely on to enforce security. Even if your business does not use these particular products, it likely depends on tools that perform at least some of the same jobs, so the broader lesson still applies.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The Short Version: Firewalls, access gateways, and identity platforms are built to protect business networks, but they are also complex software that needs maintenance. When a vulnerability appears, businesses need to identify affected products, apply the vendor's updates, check for signs of compromise, and confirm that their other security layers are still in place.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why Would Attackers Target Security Products?
&lt;/h2&gt;

&lt;p&gt;Security systems are appealing targets for a simple reason: they hold a trusted, high-leverage position. A weakness in one of them can give an attacker more than a single foothold.&lt;/p&gt;

&lt;p&gt;Depending on the product and how it is exploited, a successful attacker might be able to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Bypass a rule meant to block access&lt;/li&gt;
&lt;li&gt;Compromise an internet-facing gateway&lt;/li&gt;
&lt;li&gt;Change identity or access settings&lt;/li&gt;
&lt;li&gt;Gain a useful position for reaching other systems&lt;/li&gt;
&lt;li&gt;Blend in with activity inside a trusted part of the network&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Put simply, instead of trying every locked door, an attacker may look for a weakness in the system that controls the locks. This does not mean every vulnerability leads to a full breach. The real impact depends on the product, its configuration, how exposed it is, and whether the weakness is actually exploited.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Do the Three Recent Alerts Involve?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Forcepoint Security Engine (NGFW) | Enforces firewall and network-security policies | Certain traffic may bypass expected policy enforcement | Upgrade to a vendor-supported fixed release &lt;/li&gt;
&lt;li&gt;F5 BIG-IP APM | Controls remote and application access | Specially crafted traffic may allow remote code execution and full system compromise | Active exploitation reported by F5&lt;/li&gt;
&lt;li&gt;Cisco ISE and ISE-PIC | Manages user, device, and network access | Attackers may bypass authentication, gain admin access, or change configuration and identity data | CVE-2026-76460 confirmed actively exploited by Cisco&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Forcepoint (CVE-2026-12974)
&lt;/h3&gt;

&lt;p&gt;The Forcepoint alert describes a security-policy bypass, meaning traffic that a firewall rule should stop might get through under certain conditions. The Cyber Centre lists the affected Forcepoint Security Engine versions and advises applying updates as they become available. &lt;/p&gt;

&lt;p&gt;The Cyber Centre alert does not identify confirmed active exploitation, but affected organizations should still review their versions and apply Forcepoint’s fixes. &lt;/p&gt;

&lt;h3&gt;
  
  
  F5 BIG-IP APM (CVE-2026-94127)
&lt;/h3&gt;

&lt;p&gt;F5 BIG-IP APM acts as a gateway for remote and application access. This flaw only affects systems configured a specific way, with both an APM access policy and an OAuth profile on the same virtual server. On those systems, specially crafted traffic could let an unauthenticated attacker, meaning someone without a valid login, run their own code and potentially take over the device. F5 has reported that this vulnerability is being exploited in the wild, so affected organizations should treat it as urgent.&lt;/p&gt;

&lt;h3&gt;
  
  
  Cisco ISE and ISE-PIC (CVE-2026-20192, CVE-2026-76423, CVE-2026-76460)
&lt;/h3&gt;

&lt;p&gt;Cisco ISE helps decide which users and devices are trusted on a network. The three flaws could allow authentication bypass, administrative access, exposure of sensitive data, and configuration changes. Cisco has confirmed that one of them, CVE-2026-76460, is being actively exploited. Cisco states there are no workarounds that fully resolve the issues, so installing the fixed software is required.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Buying a Strong Security Product Is Not the End of the Job
&lt;/h2&gt;

&lt;p&gt;Reputable vendors regularly find and correct vulnerabilities in their products. That is a normal part of maintaining complex software, not a sign that the products are poor. The risk shows up when no one is clearly responsible for the ongoing work these tools require.&lt;/p&gt;

&lt;p&gt;In many businesses, it is unclear who owns:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Keeping an inventory of security products and their versions&lt;/li&gt;
&lt;li&gt;Watching vendor and government advisories&lt;/li&gt;
&lt;li&gt;Deciding whether a specific configuration is affected&lt;/li&gt;
&lt;li&gt;Testing and installing updates&lt;/li&gt;
&lt;li&gt;Checking that integrations still work afterward&lt;/li&gt;
&lt;li&gt;Reviewing logs for signs of earlier exploitation&lt;/li&gt;
&lt;li&gt;Confirming that management interfaces are properly restricted&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Key Takeaway: A security product can watch the network, but someone still needs to watch the security product.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why Patching May Not Be the Whole Response
&lt;/h2&gt;

&lt;p&gt;When an actively exploited vulnerability affects your environment, installing the update is necessary but may not be the end of it. A patch closes a known weakness. It does not tell you whether someone already used that weakness before you patched.&lt;/p&gt;

&lt;p&gt;If active exploitation has occurred, logs, accounts, policies, configurations, and API activity may need review. In some cases, as the Cyber Centre advises for the Cisco vulnerabilities, suspected compromise may require affected nodes to be reimaged and restored from known-good backups, because an attacker with elevated access may have removed evidence of their activity. Any update should be followed by a check that it actually took effect, and if there are signs of a problem, a proper incident investigation.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Patching vs. Investigation: Patching fixes the vulnerable software. Investigation looks for evidence that someone may have used the vulnerability before it was fixed. Serious, actively exploited flaws can call for both.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Should Businesses Review Now?
&lt;/h2&gt;

&lt;p&gt;This is useful even if you do not use Forcepoint, F5, or Cisco ISE, because the same questions apply to whatever firewalls, gateways, and access controls you do run.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Identify the firewalls, gateways, VPNs, identity systems, and remote-access tools your organization uses.&lt;/li&gt;
&lt;li&gt;Record their current software versions and support status.&lt;/li&gt;
&lt;li&gt;Confirm who receives vendor and government security notifications.&lt;/li&gt;
&lt;li&gt;Restrict management interfaces to trusted administrators and networks.&lt;/li&gt;
&lt;li&gt;Apply security updates based on urgency and exposure, prioritizing anything under active exploitation.&lt;/li&gt;
&lt;li&gt;Review logs when an actively exploited vulnerability affects your environment.&lt;/li&gt;
&lt;li&gt;Keep current configuration backups and tested recovery procedures.&lt;/li&gt;
&lt;li&gt;Segment important systems so one compromised control does not expose everything.&lt;/li&gt;
&lt;li&gt;Confirm who is responsible for acting outside normal business hours.&lt;/li&gt;
&lt;li&gt;Periodically test that your security controls still work as intended.&lt;/li&gt;
&lt;/ol&gt;

&lt;blockquote&gt;
&lt;p&gt;Pro Tip: If your business cannot quickly say which firewall, VPN, or access-control version it runs, close that visibility gap before the next urgent advisory arrives. You cannot patch or defend what you have not inventoried.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  How Ongoing IT Support Helps
&lt;/h2&gt;

&lt;p&gt;For many small and medium businesses, the challenge is not buying another security product. It is making sure the tools already in place are current, correctly configured, and actively watched. That is ongoing work, and it is often the first thing to slip when a small team is busy.&lt;/p&gt;

&lt;p&gt;This is one of the roles a &lt;a href="https://www.firewalltechnical.com/managed-it-services/" rel="noopener noreferrer"&gt;managed IT and cybersecurity partner&lt;/a&gt; can fill: maintaining a current technology inventory, following relevant advisories, separating the alerts that affect your environment from those that do not, applying updates safely, reviewing configurations and management access, monitoring for suspicious activity, and investigating when something looks wrong. Firewall Technical provides this kind of managed IT and cybersecurity support to Ottawa businesses, helping them keep their networks and security systems current and respond when an advisory calls for action.&lt;/p&gt;

&lt;p&gt;Security products remain necessary, and well-known vendors are not immune to vulnerabilities. What turns an installed product into an actively managed security control is the maintenance and monitoring behind it. Every business should be able to answer one simple question: who is watching the tools that watch your network?&lt;/p&gt;

&lt;p&gt;If you are not sure who is monitoring your firewall, remote-access tools, or other critical security systems, call Firewall Technical at 613-288-5805. A short review can clarify what is in place, who is maintaining it, and where more attention may be needed.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Citations:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.cyber.gc.ca/en/alerts-advisories/forcepoint-security-advisory-av26-960" rel="noopener noreferrer"&gt;Forcepoint security advisory&lt;/a&gt; (AV26-960), Canadian Centre for Cyber Security&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127" rel="noopener noreferrer"&gt;Vulnerability impacting F5 BIG-IP Access Policy Manager&lt;/a&gt;, CVE-2026-94127 (AL26-022), Canadian Centre for Cyber Security&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.cyber.gc.ca/en/alerts-advisories/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460" rel="noopener noreferrer"&gt;Vulnerabilities impacting Cisco Identity Services Engine&lt;/a&gt;, CVE-2026-20192, CVE-2026-76423, CVE-2026-76460 (AL26-021), Canadian Centre for Cyber Security&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T" rel="noopener noreferrer"&gt;Cisco Identity Services Engine Hardening Release&lt;/a&gt;: September 2026, Cisco (supporting advisory)&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
    </item>
    <item>
      <title>Is Your On-Premises SharePoint Server Still Putting Your Business at Risk?</title>
      <dc:creator>Firewall Technical IT Insights</dc:creator>
      <pubDate>Fri, 25 Sep 2026 06:40:00 +0000</pubDate>
      <link>https://dev.to/firewall-technical/is-your-on-premises-sharepoint-server-still-putting-your-business-at-risk-4fj3</link>
      <guid>https://dev.to/firewall-technical/is-your-on-premises-sharepoint-server-still-putting-your-business-at-risk-4fj3</guid>
      <description>&lt;p&gt;If your business still runs SharePoint on a server in your own office or data centre, a wave of attacks from 2025 is worth understanding. They targeted a weakness in on-premises Microsoft SharePoint, and they revealed something every business owner should take to heart: closing the original hole does not always remove an attacker who has already slipped inside. Canada’s national cyber security agency documented the whole story in detail, and the lessons reach well beyond SharePoint.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Happened With the SharePoint ToolShell Vulnerabilities?
&lt;/h2&gt;

&lt;p&gt;In mid-2025, attackers began exploiting a chain of flaws in on-premises Microsoft SharePoint Server, known collectively as ToolShell (tracked as CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771). *The Canadian Centre for Cyber Security investigated one of these compromises and published a thorough account of what it found.&lt;/p&gt;

&lt;p&gt;According to the Cyber Centre, the earliest signs of exploitation appeared roughly 12 days before the vulnerabilities were publicly disclosed on July 19, 2025. In other words, some servers were already compromised before most organizations even knew there was a problem to fix. Rather than leaving the obvious traces that early guidance told defenders to look for, the attackers loaded custom code straight into the server’s memory, which made the intrusion much harder to detect with routine checks.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Did You Know: A vulnerability being “disclosed” on a certain date does not mean that is when attacks started. In this case, exploitation was already underway almost two weeks earlier. That gap is exactly why waiting for headlines before acting can leave a business exposed.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why This Matters for Small and Medium Businesses
&lt;/h2&gt;

&lt;p&gt;It is tempting to read a story like this and assume it only concerns large enterprises with sizable IT departments. Small and medium businesses should not dismiss the risk so quickly. The Cyber Centre noted that the organization in its investigation followed strong security practices and still could not have prevented the initial break-in, because the weakness lived in the software itself.&lt;/p&gt;

&lt;p&gt;For a small or medium business, one exposed server can become a doorway to far more than a single application. In this case, the attackers used their foothold to steal stored credentials, copy password databases for later cracking, search connected file shares for sensitive documents, query the company directory for user and administrator accounts, and even try to reach the internal email system. A single vulnerable server rarely stays a single-server problem.&lt;/p&gt;

&lt;p&gt;This pattern is not unique to SharePoint. According to Ottawa-based *Field Effect’s 2026 Cyber Threat Outlook, more than 80% of the incidents the firm investigated in 2025 involved cloud identity compromise. In many of those incidents, attackers used valid or stolen credentials rather than breaking through another technical barrier. The SharePoint investigation illustrates how a software vulnerability can quickly become a broader identity and access problem once credentials are exposed.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Pro Tip: If your team has ever thought “we installed the update, so we are covered,” treat that as a prompt to ask a harder question: could someone have gotten in before the update, and what would they have been able to reach from that one server?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Why Installing the Patch May Not Be Enough
&lt;/h2&gt;

&lt;p&gt;Here is the part that surprises many business owners. Applying the security update is necessary, but on its own it may not be enough to make the problem go away.&lt;/p&gt;

&lt;p&gt;During the SharePoint attacks, intruders extracted the server’s cryptographic keys early on. As both the Cyber Centre and Microsoft warned, once those keys are stolen, patching alone does not lock the attacker back out. They can keep regaining access until the keys are rotated and the server is restarted. The attackers in this case also planted a second entry point on a different server that was not even running SharePoint, then went quiet for about two weeks before returning to test whether their access still worked.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Key Takeaway: A security update can close the original door, but it cannot automatically remove an attacker who is already inside. Recovering from a compromise means assuming they may have made copies of your keys and hidden other ways back in, then acting accordingly.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Are You Running SharePoint Online or SharePoint Server?
&lt;/h2&gt;

&lt;p&gt;This distinction matters, because only one of the two was affected. SharePoint Server is the on-premises version: you install it on hardware you own and manage, and your team is responsible for patching and securing it. SharePoint Online is part of Microsoft 365, hosted in Microsoft’s cloud, where Microsoft maintains the underlying infrastructure and applies fixes like these for you. The ToolShell vulnerabilities affected on-premises SharePoint Server, not SharePoint Online.&lt;/p&gt;

&lt;p&gt;If you are not certain which one your business relies on, that is worth confirming today. Many organizations run a mix, especially if they moved to Microsoft 365 but left an older on-premises server quietly running in the background. Those forgotten servers are often the least monitored and the most exposed.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to Do If You Rely on On-Premises SharePoint
&lt;/h2&gt;

&lt;p&gt;If your business runs SharePoint Server, or any other business-critical software on your own hardware, a handful of concrete steps meaningfully reduce your exposure:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Apply the latest security updates from Microsoft without delay.&lt;/li&gt;
&lt;li&gt;Rotate credentials and cryptographic keys, then restart affected servers, so stolen secrets can no longer be reused.&lt;/li&gt;
&lt;li&gt;Review server and access logs for unusual activity, especially sign-ins from unexpected locations.&lt;/li&gt;
&lt;li&gt;Run regular vulnerability scans and server audits so new weaknesses surface before an attacker finds them.&lt;/li&gt;
&lt;li&gt;Monitor network traffic for signs of movement between servers, which is often the first clue that a single compromise is spreading.&lt;/li&gt;
&lt;li&gt;Keep tested, isolated backups so you can recover cleanly if the worst happens.&lt;/li&gt;
&lt;li&gt;If you suspect a system has been compromised, bring in a professional incident response investigation rather than assuming a patch has settled the matter.
Multifactor authentication also provides an important additional barrier around the accounts an intruder may try to steal. It should be used wherever available, particularly for administrator accounts and remote access. &lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  How Managed IT Support Lowers the Risk
&lt;/h2&gt;

&lt;p&gt;Most small and medium businesses do not have the time or the in-house expertise to watch for threats around the clock, and that is precisely the gap attackers count on. A story like the SharePoint attacks is not meant to frighten you into buying something. It is meant to show that maintaining business-critical software on your own servers takes more than installing updates when you remember to.&lt;/p&gt;

&lt;p&gt;This is where a &lt;a href="https://www.firewalltechnical.com/it-security/" rel="noopener noreferrer"&gt;managed IT and cybersecurity partner&lt;/a&gt; earns its place. Proactive patch management keeps known weaknesses closed. Continuous server and network monitoring catches unusual behaviour early, when it is still contained. Layered protection limits how far any single compromise can spread. And a tested incident response plan means that if something does slip through, there is a calm, practiced process ready rather than a scramble.&lt;/p&gt;

&lt;p&gt;For a typical Ottawa professional services firm running a small on-premises environment alongside Microsoft 365, that combination can reduce the risk of prolonged downtime, data exposure, and an expensive recovery effort. &lt;/p&gt;

&lt;p&gt;If you are not sure whether your on-premises servers are properly protected, call Firewall Technical at 613-288-5805. A short conversation can help clarify what you are running, where the most important risks may be, and what should happen next. &lt;/p&gt;

&lt;p&gt;Citations:&lt;br&gt;
&lt;a href="https://www.cyber.gc.ca/en/news-events/threat-detection-sharepoint-vulnerabilities" rel="noopener noreferrer"&gt;Canadian Centre for Cyber Security&lt;/a&gt;&lt;br&gt;
&lt;a href="https://fieldeffect.com/blog/field-effect-threat-report" rel="noopener noreferrer"&gt;Field Effect’s 2026 Cyber Threat Outlook&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
