LevelBlue, the world’s largest pure-play provider of managed security services, today announced a strategic partnership with Fortra, a global leader in cybersecurity solutions. This collaboration integrates Fortra’s best-in-class solutions with LevelBlue’s elite managed services, delivering a comprehensive security offering designed to combat the evolving threat landscape.
The partnership marks a major milestone in LevelBlue’s mission to deliver world-class, proactive cybersecurity and secure what’s next for its clients, while also representing a significant step forward in Fortra’s evolution as a channel-first company focused on empowering resellers, service providers, and distributors to deliver its solutions.
As part of this long-term partnership, LevelBlue will acquire the managed services of Fortra’s Alert Logic Managed Detection and Response (MDR), Extended Detection and Response (XDR), and Web Application Firewall (WAF) solutions. LevelBlue’s expanded MDR platform, strengthened through recent acquisitions, will provide Alert Logic’s client base with access to a larger global footprint, broader threat telemetry, and accelerated detection and response across complex environments. In parallel, Fortra will become one of LevelBlue’s leading cybersecurity partners, making its best-in-class software and platforms available to LevelBlue’s global client base.
Fortra’s technologies complement and extend LevelBlue’s existing strengths across data security, brand protection, email security, and offensive security, adding additional depth, optionality, and specialization for LevelBlue clients. Together, LevelBlue and Fortra will provide clients with greater choice, broader coverage across the attack surface, and improved security outcomes, all delivered through LevelBlue’s managed services model.
This partnership further reinforces LevelBlue’s position as the global pure-play leader in MDR and managed cybersecurity services, while underscoring Fortra’s role as a global leader in cybersecurity software and solutions. Following the launch of Fortra’s new partner program, Fortra Protect, last year, the partnership with LevelBlue further illustrates Fortra’s commitment to work with the world’s best service providers and channel experts to serve cyber clients.
LevelBlue, an innovator in cloud-based, AI-driven managed security services, continues to expand its leadership as the world’s largest pure-play MSSP, offering one of the most comprehensive portfolios spanning managed security, offensive security, incident response, threat intelligence, and MDR. This scale and breadth enables clients and partners to accelerate threat detection, streamline security operations, reduce cyber risk, and continuously mature their cybersecurity posture, now with even more choice and value through Fortra’s complementary technologies.
Santander served as the exclusive financial advisor to LevelBlue in this transaction and Stephens served as the exclusive financial advisor to Fortra/Alert Logic.
March Patch Tuesday Commentary From Fortra
Posted in Commentary with tags Fortra on March 10, 2026 by itnerdBy Tyler Reguly, Associate Director, Security R&D, Fortra
I’m sure that everyone will be talking about CVE-2026-26118 today. After all, it contains those magical three letters MCP – Must Create Panic! The old adage has changed a little these days to become, “AI sells,”, so that’s what everyone needs to talk about. The reality is that there’s an update available, this was never publicly disclosed, and Microsoft lists exploitation as less likely. So, instead of trying to create panic, I’m going to keep a level head and say that this is a great reminder for all CSOs to make sure they know how AI is being used within their organization. Instead of worrying about a single CVE that we don’t really need to talk about, look at your organizations AI policy, look at your tooling, and look at how your data is flowing. If you know that, you’re fine. If not, shadow AI might be the actual reason that you need to panic and that’s not a Patch Tuesday thing, that’s just an everyday thing.
Let’s agree to call this the month of no 0-days. I’m sure some people will try to call the two publicly disclosed vulnerabilities 0-days, but they’re wrong… and let’s just leave it at that. Instead, let’s talk about how even the publicly disclosed vulnerabilities are pretty much nothingburgers this month. We have CVE-2026-21262, which is a privilege escalation in SQL Server, but you have to already be an authenticated SQL user to exploit this. The other, CVE-2026-26127, is a .NET denial of service. Neither of these are very important. Neither of them should stress anybody out.
In total this month, we have 83 Microsoft CVEs and 10 non-Microsoft CVEs and I don’t see a lot of reasons for people to stress. The only CVE above an 8.8 is CVE-2026-21536, a 9.8 in Microsoft Devices Pricing Program, a vulnerability that is marked as no customer action required because it is already updated. The messaging this month should be, “Apply your patches after you finish your testing cycles.” There’s nothing that requires rushing patches, nothing that requires panic… this is just a nice, quiet Patch Tuesday (and I definitely won’t regret using the Q-word).
The only thing that people may want to pay close attention to is the Azure vulnerabilities. As I’ve mentioned before, the cloud ecosystem doesn’t really handle patching well… it’s a relatively immature process and the way that Microsoft handles these products really demonstrates that. The CVE impacting Azure Linux Virtual Machines (CVE-2026-23665) or the multiple CVEs impacting Azure IoT Explorer require pretty non-standard patching mechanisms and those may require a little additional effort from IT teams. CSOs should ensure that they have solid asset inventories around the deployment of cloud related systems and tools, so that admins know where these things exist and when they need to be fixed. This is the best way to empower your sys admins and security teams on a quiet month like this.
Leave a comment »