Skip to content
In Other News: Microsoft's Cloud Patches, Hacked Dropbox Accounts, Guardio's $1.1B Valuation

In Other News: Microsoft's Cloud Patches, Hacked Dropbox Accounts, Guardio's $1.1B Valuation

Securityweek September 4, 2026

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment.

Here are this week’s highlights:

Microsoft releases cloud patches

Microsoft has released patches for nine vulnerabilities in Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. The fixes were deployed server side and require no action from Microsoft’s customers.

Project Watershed 250: cybersecurity capabilities for Texas water utilities

White House and Texas’ Governor have launched Project Watershed 250, a federal-private sector effort to provide water and wastewater utilities in Texas with access to free cyber defense resources and harded then against cyberattacks from China, Iran, and other hostile foreign adversaries.

Minnesota county paid $128K to ransomware group

Winona County in Minnesota reportedly paid a $128,539.57 ransom to restore services and protect personal information affected by a January 2026 ransomware attack. In April, the county fell victim to a second ransomware attack, claimed by the InterLock gang, but it is unclear who was responsible for the January incident.

Exploit published for Exchange flaw affecting over 21,000 servers

Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August, the Netherlands National Cyber Security Centre warns . On September 1, The Shadowserver Foundation, observed over 21,000 servers that have not been patched.

5,000 Dropbox accounts compromised via Lenovo login integration

Dropbox has notified approximately 5,000 users that hackers compromised their accounts by abusing an issue with Lenovo’s email verification process. The attackers registered Lenovo IDs using the victim’s email addresses and then accessed their Dropbox accounts. Dropbox says it closed all unauthorized sessions and access.

Knight Office phishes for Microsoft 365 and Google Workspace credentials

A newly identified adversary-in-the-middle (AitM) phishing kit has been targeting Microsoft 365 and Google Workspace users to steal their account credentials, Huntress reports . Knight Office relies on token theft, a popular technique that provides attackers with an already-authenticated session that completely bypasses password requirements and MFA mechanims.

Plex releases security updates

The popular streaming service Plex this week announced the release of Plex Media Server 1.43.3 and Plex Desktop 1.115.0 with patches for multiple security vulnerabilities, urging users to update their instances as soon as possible. No details on the bugs have been shared, and the CVEs have not been assigned yet.

Guardio valued at $1.1 billion

Guardio is valued at $1.1 billion following a new funding round of $40M. Guardio protects people from the AI-driven scams that lead to identity theft. Today’s bad actors prefer to walk into a network with credentials rather than being forced to break in.

Coder’s module registry website served malware

A threat actor hacked Coder’s Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was served through Coder’s module registry website to a subset of users, for a short period of time. Users who downloaded the malicious code were infected with a credential stealer, Coder notes .

Russian charged in US for serving malware to 80,000 freelancers

Searzhudin Tamirlanovich Aktulaev, 40, of Russia, has been charged in the US with exploiting the online message platform of a freelance employment company in California to deliver malware to 80,000 freelance users between June 2016 and November 2017. Aktulaev was arrested in Cyprus last year. The indictment was filed in 2021 and unsealed on Monday, when Aktulaev appeared in court, after being extradited to the US.

Lasso Security raises $30 million

Israeli AI security company Lasso Security has raised $30 million in a funding round led by ClearSky, with additional support from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. The company has just announced LEAP, an AI guardrail that promises top-tier detection accuracy on CPUs.

Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

Related: In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware...

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON...

Artificial Intelligence

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached...

Artificial Intelligence

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records.

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion...

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data...

In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting

Noteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the...