Microsoft Cloud Fixes, Dropbox Account Breach and Guardio Funding Lead Security Roundup

Microsoft has addressed nine security flaws affecting a range of cloud products, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure AI Language and Fabric. The company deployed...

Microsoft has addressed nine security flaws affecting a range of cloud products, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure AI Language and Fabric. The company deployed the fixes on the server side, meaning customers do not need to install updates themselves.

Separately, the Netherlands’ National Cyber Security Centre warned that public exploit code is available for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August. Shadowserver data indicated that more than 21,000 potentially affected Exchange servers remained unpatched as of September 1.

Dropbox said roughly 5,000 customer accounts were accessed after attackers took advantage of a weakness in Lenovo’s email-verification process. According to the company, the attackers created Lenovo identities using victims’ email addresses and used the integration to enter Dropbox accounts. Dropbox said it terminated unauthorized sessions and remediated the issue.

Phishing and software supply-chain concerns

Researchers at Huntress reported a new adversary-in-the-middle phishing toolkit, dubbed Knight Office, that targets Microsoft 365 and Google Workspace accounts. Rather than relying only on stolen passwords, the kit is designed to capture session tokens, potentially allowing attackers to bypass multifactor authentication by hijacking an authenticated browser session.

Coder also disclosed an incident involving its Cloudflare environment. An intruder allegedly added unauthorized IP addresses that distributed malicious code through the company’s module registry for a limited time. Coder said impacted downloads contained credential-stealing malware.

Plex released Plex Media Server 1.43.3 and Plex Desktop 1.115.0, urging users to update promptly. The company said the releases address several security issues, although technical details and CVE identifiers were not yet available.

Public-sector activity and investment

Texas and the White House launched Project Watershed 250, an initiative intended to provide free cyber-defense support to water and wastewater organizations in the state. The program is aimed at improving resilience against threats linked to hostile foreign actors.

Winona County, Minnesota, reportedly paid approximately $128,540 following a January ransomware incident. The county later experienced another attack claimed by the InterLock ransomware group.

In the private sector, consumer protection company Guardio announced a $40 million funding round that placed its valuation at $1.1 billion. Israeli AI security firm Lasso Security also reported raising $30 million to expand its AI security and guardrail offerings.