In other news: Microsoft’s cloud patches, hacked Dropbox accounts, Guardio’s $1.1 billion worth

In other news: Microsoft’s cloud patches, hacked Dropbox accounts, Guardio’s .1 billion worth

Weekly from SecurityWeek Cybersecurity News Summary provides a succinct overview of key developments that may not be covered entirely in isolation but are nonetheless relevant to the broader threat landscape.

This curated summary highlights key stories about vulnerability disclosures, new attack vectors, policy updates, industry reports and other notable events to help readers maintain a comprehensive awareness of the evolving cybersecurity environment.

Here are this week’s highlights:

Microsoft releases cloud patches

Microsoft has released Patches for nine vulnerabilities in Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language and Discovery Studio. The fixes were deployed server-side and do not require any action from Microsoft customers.

Project Watershed 250: Cybersecurity Capabilities for Texas Water Utilities

Advertising. Scroll to continue reading.

The White House and the governor of Texas did started Project Watershed 250, a federal and private sector initiative to provide water and wastewater utilities in Texas access to free cyber defense resources and then protect them against cyberattacks from China, Iran and other hostile foreign adversaries.

Minnesota County paid $128,000 to the ransomware group

Winona County, Minnesota allegedly paid a $128,539.57 ransom to restore services and protect personal data affected by a ransomware attack in January 2026. In April, the county fell victim to a second ransomware attack claimed by the InterLock gang. However, it is unclear who was responsible for the January incident.

Exploit released for Exchange flaw affecting over 21,000 servers

Exploit code has been released for CVE-2026-62911, a high-level Microsoft Exchange Server vulnerability that was patched by the Dutch National Center for Cybersecurity in August warns. On September 1st, the Shadowserver Foundation observed over 21,000 servers that have not been patched.

5,000 Dropbox accounts were compromised via the Lenovo login integration

Dropbox has notified About 5,000 users have learned that hackers compromised their accounts by exploiting an issue with Lenovo’s email verification process. The attackers registered Lenovo IDs using victims’ email addresses and then accessed their Dropbox accounts. Dropbox says it has closed all unauthorized sessions and access.

Knight Office fishes for Microsoft 365 and Google Workspace credentials

A newly identified Adversary-in-the-Middle (AitM) phishing kit has targeted Microsoft 365 and Google Workspace users to steal their account credentials, Huntress Reports. Knight Office relies on token theft, a popular technique that allows attackers an already authenticated session that completely bypasses password requirements and MFA mechanisms.

Plex releases security updates

The popular streaming service Plex this week announced the release of Plex Media Server 1.43.3 and Plex Desktop 1.115.0 with patches for multiple vulnerabilities, encouraging users to update their instances as soon as possible. No details about the bugs have been disclosed and the CVEs have not yet been assigned.

Guardio is valued at $1.1 billion

guard Is worth $1.1 billion after a new round of financing of $40 million. Guardio protects people from AI-driven scams that lead to identity theft. Today’s criminals prefer to use credentials to break into a network rather than be forced to break in.

Malware was deployed on Coder’s module registration website

A threat actor hacked Coder’s Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was made available to a subset of users for a short period of time through Coder’s module registration website. Users who downloaded the malicious code were infected with a credential stealer. Coder notes.

Russe faces charges in the US for distributing malware to 80,000 freelancers

Searzhudin Tamirlanovich Aktulaev, 40, from Russia, was charged in the US, exploiting the online messaging platform of a freelance employment company in California to distribute malware to 80,000 freelance users between June 2016 and November 2017. Aktulaev was arrested in Cyprus last year. The indictment was filed in 2021 and was quashed on Monday when Aktulaev appeared in court after being extradited to the United States.

Lasso Security raises $30 million

Israeli AI security company Lasso security has raised $30 million in a funding round led by ClearSky, with additional support from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. The company has just announced LEAP, an AI guardrail that promises world-class detection accuracy on CPUs.

Related: In other news: Log4j RCE scare, Minimus shutdown, Iranian hacker sanctions

Related: In other news: Zombie card attack, T-Mobile cuts cable to stop hackers, GitHub denies AI-caused bug

Leave a Reply

Your email address will not be published. Required fields are marked *