Securityweek
Microsoft Patches Critical Vulnerabilities Amid Dropbox Account Breach
Article Content
Microsoft has released patches for nine vulnerabilities in various cloud services, including Entra ID and Azure Cosmos DB, requiring no action from users. In a separate incident, approximately 5,000 Dropbox accounts were compromised due to a flaw in Lenovo's email verification process, allowing attackers to access accounts by registering Lenovo IDs with victims' email addresses. Winona County in Minnesota paid a ransom of $128,539.57 to restore services following a ransomware attack earlier this year. Additionally, exploit code for a high-severity vulnerability in Microsoft Exchange Server (CVE-2026-62911) has been published, affecting over 21,000 unpatched servers. The Netherlands National Cyber Security Centre has warned of the potential risks associated with this exploit. The Knight Office phishing kit has been identified as a new threat targeting Microsoft 365 and Google Workspace users, utilizing token theft techniques to bypass authentication mechanisms. The overall cybersecurity landscape remains dynamic with these developments.
Key Points: • Microsoft patched nine vulnerabilities in cloud services with no user action required. • 5,000 Dropbox accounts were compromised via a Lenovo verification flaw. • Exploit code for a critical Microsoft Exchange vulnerability has been published.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.