Breaking
SecurityConfirmed

Windows 2026 Bug Patch? No, the Cloud

Microsoft's cloud patches, Dropbox account breaches, and Guardio's $1.1B funding round headline this week's security news.

··1 hour ago·5 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

Microsoft's server-side patches, a surge in phishing kits, and a major funding round for an AI-driven security firm are among the developments captured in this week's cybersecurity roundup. The collection highlights vulnerabilities, attack methods, and policy moves that didn't warrant standalone coverage but are shaping the threat landscape.

Microsoft's Cloud Patching Spree

Microsoft has released patches for nine vulnerabilities spanning its cloud services, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. These fixes were deployed server-side, requiring no action from customers.

This approach reflects a growing trend among cloud providers to update services directly, rather than issuing client-side patches. The vulnerabilities targeted varied services, but the lack of required action simplifies the remediation process for users.

Texas Water Utilities Get Cyber Boost

The White House and Texas Governor have launched Project Watershed 250, a federal-private sector initiative to equip water and wastewater utilities in Texas with free cyber defense resources. The program aims to harden these critical infrastructure providers against cyberattacks from China, Iran, and other hostile foreign adversaries.

This public-private partnership underscores the increasing focus on securing essential services that often lack robust cybersecurity measures. The initiative provides tangible support to protect public health and safety.

Minnesota County Pays Six-Figure Ransom

Winona County in Minnesota reportedly paid a ransom of $128,539.57 to restore services and protect personal information after a January 2026 ransomware attack. In April, the county experienced a second ransomware attack, claimed by the InterLock gang, though the January attack's perpetrators remain unclear.

The payment highlights the difficult choices faced by local governments when critical systems are compromised. Despite the payment, the county suffered a subsequent attack, suggesting that paying ransoms may not guarantee long-term security.

Exchange Flaw Exploited, Thousands Unpatched

Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August. The Netherlands National Cyber Security Centre warns that as of September 1, The Shadowserver Foundation observed over 21,000 servers that remain unpatched.

The publication of exploit code increases the urgency for organizations to apply the available patches. The presence of thousands of vulnerable servers suggests a significant risk of widespread exploitation in the near term.

Dropbox Account Breach via Lenovo Integration

Dropbox has notified approximately 5,000 users that hackers compromised their accounts by exploiting an issue with Lenovo's email verification process. The attackers registered Lenovo IDs using the victims' email addresses and then accessed their associated Dropbox accounts. Dropbox says it closed all unauthorized sessions and access.

This incident illustrates the risks of third-party integrations and the importance of monitoring account activity. Users affected by such breaches are often left vulnerable to further attacks if they reuse passwords or lack multi-factor authentication.

Knight Office Phishing Kit Targets Cloud Credentials

A newly identified adversary-in-the-middle (AitM) phishing kit has been targeting Microsoft 365 and Google Workspace users to steal their account credentials, according to Huntress. Dubbed Knight Office, the kit relies on token theft, a technique that provides attackers with an already-authenticated session, bypassing passwords and multi-factor authentication (MFA).

Knight Office relies on token theft, a popular technique that provides attackers with an already-authenticated session that completely bypasses password requirements and MFA mechanims.

— Huntress, as reported in SecurityWeek

This method allows attackers to impersonate legitimate users without needing to break through traditional security barriers. The rise of such sophisticated phishing kits highlights the evolving nature of credential theft.

Guardio Reaches $1.1 Billion Valuation

Guardio, a company that protects people from AI-driven scams leading to identity theft, is now valued at $1.1 billion following a new funding round. The company's focus on credential-based attacks reflects a broader shift among cybercriminals toward using stolen credentials rather than forcing their way into networks.

This funding round underscores investor confidence in AI-powered security solutions, particularly those addressing the growing threat of identity-based attacks.

Malware Served via Coder's Module Registry

A threat actor hacked Coder's Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was served through Coder's module registry website to a subset of users for a short period. Users who downloaded the malicious code were infected with a credential stealer, Coder notes.

The compromise of a trusted software distribution channel is a stark reminder that even reputable platforms can be abused. Such attacks can have wide-reaching consequences, as users may unwittingly install backdoors into their systems.

Russian Charged in Freelancer Malware Scheme

Searzhudin Tamirlanovich Aktulaev, 40, of Russia, has been charged in the US with exploiting the online message platform of a freelance employment company in California to deliver malware to 80,000 freelance users between June 2016 and November 2017. Aktulaev was arrested in Cyprus last year. The indictment, filed in 2021, was unsealed on Monday when Aktulaev appeared in court after extradition to the US.

This case highlights the long reach of cybercriminals and the persistence of law enforcement in pursuing them across borders. The scale of the attack—affecting tens of thousands of freelancers—shows how vulnerable remote workers can be to targeted malware distribution.

Lasso Security Raises $30 Million

Israeli AI security company Lasso Security has raised $30 million in a funding round led by ClearSky, with additional support from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. The company has announced LEAP, an AI guardrail that promises top-tier detection accuracy on CPUs.

The funding will likely bolster Lasso Security's ability to develop and deploy its AI-driven security solutions. The announcement of LEAP indicates a focus on providing high-performance AI security that can operate on standard hardware, widening its potential adoption.

Key Numbers in This Week's News

  • $128,539.57: Ransom paid by Winona County
  • 21,000+: Unpatched Exchange servers observed
  • 5,000: Dropbox accounts compromised
  • 80,000: Freelancers affected in the malware scheme

Why It Matters

This week's developments could mean organizations face an evolving threat landscape where cloud patches require vigilance despite being server-side, and phishing kits like Knight Office can bypass MFA, raising the stakes for adopting advanced authentication methods. The persistence of ransomware payments and the compromise of software supply chains suggest that attackers are adapting, and defenders must prioritize patching, monitoring, and user education. The influx of funding for AI-driven security firms like Guardio and Lasso Security points to a future where AI plays a central role in countering AI-powered attacks, a shift that could redefine how security is approached.

#microsoft#cloud#patches#ransomware#phishing#funding

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories