B&C Solutions Group

B&C Solutions Group Managed IT support for small businesses across Hagerstown, MD and the surrounding region. Serving MD, PA, VA, WV & DC. bcsolutionsgroup.net

Microsoft 365, network infrastructure, cybersecurity, and hands-on technical support.

07/13/2026

πŸ›‘οΈ Windows Defender Patch Alert
Microsoft just patched "RoguePlanet" (CVE-2026-50656) β€” a Defender flaw that let attackers escalate to full SYSTEM access. It affected fully patched Windows 10 & 11 machines.
The good news: it updates automatically. Just make sure your Malware Protection Engine is version 1.1.26060.3008 or newer.
πŸ“Œ Check it: Windows Security β†’ Virus & threat protection β†’ check for updates.
Stay patched, stay safe. πŸ”’

https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/?utm_campaign=44478539-SecurityWeek%20Debrief&utm_medium=email&_hsmi=427849789&utm_content=427850625&utm_source=hs_email

🚨 FortiSandbox under active attack right nowThree vulnerabilities β€” including one Fortinet only patched last week β€” are ...
06/17/2026

🚨 FortiSandbox under active attack right now
Three vulnerabilities β€” including one Fortinet only patched last week β€” are actively being exploited. All carry a 9.1 severity score. Two have been exploitable since April.
If your Fortinet gear isn't current, the patch window already closed.
Flat-rate clients don't have to track this themselves β€” we do it for you, no extra charge.
πŸ“ž 301-301-1229 | bcsolutionsgroup.net

Swapped Smithsburg for Hagerstown β€” bigger market, matches your $150/endpoint Hagerstown-area rate anyway.

https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html

Attackers are exploiting three Fortinet FortiSandbox flaws, including one patched last week, risking auth bypass and command ex*****on.

πŸ”’ It's Patch Tuesday β€” and this month Microsoft fixed 200 vulnerabilities.200. In a single month. Nearly 40 of them rate...
06/10/2026

πŸ”’ It's Patch Tuesday β€” and this month Microsoft fixed 200 vulnerabilities.

200. In a single month. Nearly 40 of them rated Critical, affecting Windows, Office, Outlook, Exchange, and Azure. Three were already publicly known before the patch dropped β€” meaning attackers had a head start.

This happens every single month. New vulnerabilities, new patches, new window of exposure for businesses that aren't keeping up.
Patch management isn't glamorous β€” but it's one of the most effective things you can do to reduce your attack surface. Unpatched systems are low-hanging fruit, and attackers know it.
πŸ“ž B&C Solutions Group handles patching for our clients automatically β€” so you're not the last one to know.
πŸ‘‰ bcsolutionsgroup.net | 301-301-1229


https://www.securityweek.com/microsoft-patches-200-vulnerabilities/

Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.

🚨 If your business uses Veeam for backups, this needs your attention today.A critical vulnerability (CVE-2026-44963, CVS...
06/09/2026

🚨 If your business uses Veeam for backups, this needs your attention today.
A critical vulnerability (CVE-2026-44963, CVSS 9.4) in Veeam Backup & Replication allows any authenticated domain user to execute remote code on your backup server. Ransomware groups have a history of targeting Veeam specifically β€” because taking out your backups before deploying ransomware is part of the playbook.
A patch is available. If you or your IT provider hasn't applied it yet, that's the conversation to have right now.
Your backup solution should be your last line of defense β€” not another attack surface.
πŸ“ž B&C Solutions Group β€” flat-rate managed IT that keeps your systems patched and your backups protected.
πŸ‘‰ bcsolutionsgroup.net | 301-301-1229


https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html

Veeam fixes CVE-2026-44963 RCE in 12 builds, blocking authenticated domain users from attacking backup servers.

⚠️ Windows has an unpatched vulnerability β€” and Microsoft won't fix it.A newly disclosed flaw in the Windows Search URI ...
06/03/2026

⚠️ Windows has an unpatched vulnerability β€” and Microsoft won't fix it.
A newly disclosed flaw in the Windows Search URI handler lets attackers steal your network credentials with nothing more than a malicious link in an email or webpage. Click it, and your NTLMv2 hash is handed to the attacker β€” potentially opening the door to your entire network.
Researchers reported it. Microsoft reviewed it. Their response? It doesn't meet the bar for a patch.
When vendors leave vulnerabilities open, your perimeter becomes your last line of defense β€” and if that fails, you need something watching from the inside. This is exactly why EDR/MDR matters. It's not just about blocking threats at the edge, it's about detecting and responding when something gets through.
πŸ“ž B&C Solutions Group provides managed endpoint detection and response so threats don't go unnoticed β€” even the ones vendors won't patch.
πŸ‘‰ bcsolutionsgroup.net | 301-301-1229


https://thehackernews.com/2026/06/unpatched-windows-search-uri.html

Unpatched Windows search: URI flaw leaks NTLMv2 hashes via SMB requests; disclosed April 2026, enabling relay attacks.

⚠️ Fortinet Users β€” Patch This NowAttackers are actively exploiting a critical vulnerability in FortiClient EMS (CVE-202...
05/28/2026

⚠️ Fortinet Users β€” Patch This Now
Attackers are actively exploiting a critical vulnerability in FortiClient EMS (CVE-2026-35616, CVSS 9.1) to silently steal credentials from managed endpoints across entire organizations.
Here's what makes this one especially nasty: the malware was disguised as a legitimate Fortinet software update and delivered through FortiClient's own management infrastructure. Employees saw what looked like a normal patch β€” and clicked it.
Once in, it harvested saved passwords, session cookies, and credit card info from browsers across every managed endpoint β€” without triggering standard alerts.
This is a textbook example of a supply chain-style attack using trusted tools against you. If you run FortiClient EMS and haven't updated to version 7.4.7, you're exposed right now.
If you're not sure where your Fortinet environment stands, that's a problem. Patch management and endpoint monitoring aren't optional β€” they're the difference between a near miss and a breach.
πŸ“ž B&C Solutions Group handles this for our clients so they don't have to find out the hard way. Flat-rate IT for small and mid-sized businesses.
πŸ‘‰ bcsolutionsgroup.net | 301-301-1229

https://thehackernews.com/2026/05/threat-actors-exploit-critical.html

FortiClient EMS flaw CVE-2026-35616 enabled malware delivery via fake updates, risking credential theft across endpoints.

🚨 Another Healthcare Data Breach β€” 266,000 Patients AffectedRadiology Associates of Richmond, one of the oldest private ...
05/26/2026

🚨 Another Healthcare Data Breach β€” 266,000 Patients Affected
Radiology Associates of Richmond, one of the oldest private radiology practices in the U.S., just disclosed that a cyberattack compromised the personal and protected health information of over 266,000 current and former patients β€” including potential exposure of Social Security numbers.
What makes this worse? This is their second major breach in two years. The attack happened in July 2025, but notifications didn't go out until May 2026 β€” nearly 10 months later.
This is exactly why proactive cybersecurity isn't optional for healthcare organizations. The longer a breach goes undetected, the more damage it causes β€” and the harder it is to recover trust.
If your practice handles patient data, you need more than good intentions. You need layered security, monitoring, and a team that catches threats before they become headlines.
πŸ“ž B&C Solutions Group helps small and mid-sized businesses stay protected and HIPAA-compliant. Flat-rate IT β€” no surprise bills, no ticket meters.
πŸ‘‰ Learn more: bcsolutionsgroup.net | 301-301-1229


https://www.hipaajournal.com/radiology-associates-of-richmond-data-breach/

Radiology Associates of Richmond in Virginia, one of the oldest, continuously operating private radiology practices in the United States, has announced Radiology Associates of Richmond has announced another major data breach. The protected health information of more than 266,000 individuals was comp...

🚨 New threat just dropped β€” and your firewall won't save you.A newly disclosed vulnerability called UnderminR affects 88...
05/23/2026

🚨 New threat just dropped β€” and your firewall won't save you.
A newly disclosed vulnerability called UnderminR affects 88 million domains β€” including 51% of websites in the US. Attackers are using it to route malicious traffic through trusted, legitimate domains, making it nearly invisible to standard DNS filtering, signature-based tools, and even most behavior detection.
Think of it like a criminal using a trusted company's delivery van to smuggle contraband. The van looks legit. The route looks normal. Traditional security doesn't flag it.

A secured perimeter is your first line of defense. But it can't be your only one.
βœ… EDR/MDR solutions monitor what's happening on your endpoints and inside your network β€” not just at the gate.
βœ… Behavioral analysis catches anomalies even when traffic looks clean on the surface.
βœ… 24/7 managed detection means someone is watching when these "trusted" connections start doing things they shouldn't.
If your business is relying on a firewall and antivirus to stay protected in 2026, this is your wake-up call.
B&C Solutions Group offers flat-rate managed IT that includes real endpoint protection β€” not checkbox security.
πŸ“ž 301-301-1229
🌐 bcsolutionsgroup.net


https://www.securityweek.com/underminr-vulnerability-lets-attackers-hide-malicious-connections-behind-trusted-domains/

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.

🚨 Windows Defender was just exploited β€” again.A newly discovered vulnerability (CVE-2026-41091) in Microsoft Defender is...
05/22/2026

🚨 Windows Defender was just exploited β€” again.
A newly discovered vulnerability (CVE-2026-41091) in Microsoft Defender is actively being used by attackers to gain full control of Windows machines. It's already on CISA's "patch now" list.
Here's the thing β€” Defender is a solid baseline. Microsoft has genuinely improved it over the years. But "baseline" isn't enough when attackers are actively targeting it.
At B&C Solutions Group, we protect our managed clients with enterprise-grade EDR/MDR β€” purpose-built endpoint detection and response that doesn't just scan for known threats. It watches behavior in real time, stops attacks as they happen, and can roll back damage automatically if something gets through.
The difference between antivirus and EDR/MDR isn't a sales pitch β€” it's the difference between finding out you were breached and stopping it before it matters.
If your business is running on Windows Defender alone, let's talk.
πŸ“ž 301-301-1229
🌐 bcsolutionsgroup.net

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/

On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks.

05/22/2026

Address

105 United Court
Smithsburg, MD
21783

Alerts

Be the first to know and let us send you an email when B&C Solutions Group posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share