Microsoft Patches Critical Vulnerabilities Amid Dropbox Account Breach

Microsoft Patches Critical Vulnerabilities Amid Dropbox Account Breach

First seen 4 Sep 2026, 18:47 UTC Securityweek 57.8

Article Content

Browse articles
ThreatCluster

Microsoft has released patches for nine vulnerabilities in various cloud services, including Entra ID and Azure Cosmos DB, requiring no action from users. In a separate incident, approximately 5,000 Dropbox accounts were compromised due to a flaw in Lenovo's email verification process, allowing attackers to access accounts by registering Lenovo IDs with victims' email addresses. Winona County in Minnesota paid a ransom of $128,539.57 to restore services following a ransomware attack earlier this year. Additionally, exploit code for a high-severity vulnerability in Microsoft Exchange Server (CVE-2026-62911) has been published, affecting over 21,000 unpatched servers. The Netherlands National Cyber Security Centre has warned of the potential risks associated with this exploit. The Knight Office phishing kit has been identified as a new threat targeting Microsoft 365 and Google Workspace users, utilizing token theft techniques to bypass authentication mechanisms. The overall cybersecurity landscape remains dynamic with these developments.

Key Points: • Microsoft patched nine vulnerabilities in cloud services with no user action required. • 5,000 Dropbox accounts were compromised via a Lenovo verification flaw. • Exploit code for a critical Microsoft Exchange vulnerability has been published.

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-62911 published
A high-severity vulnerability in Microsoft Exchange Server was disclosed, affecting numerous servers.
Securityweek
2026-08-22
First public PoC for CVE-2026-62911
Proof-of-concept code for the Microsoft Exchange vulnerability was made publicly available.
Securityweek
2026-09-01
21,000 servers unpatched for Exchange flaw
The Shadowserver Foundation reported over 21,000 servers remain unpatched for the Exchange vulnerability.
Securityweek
2026-09-04
Microsoft releases cloud patches
Patches were released for vulnerabilities in multiple Microsoft cloud services, requiring no user action.
Securityweek
Date unknown
5,000 Dropbox accounts compromised
Hackers accessed Dropbox accounts by exploiting a Lenovo email verification issue, affecting 5,000 users.
Securityweek
Date unknown
Winona County paid ransomware
Winona County in Minnesota paid over $128K to a ransomware group to restore services after an attack.
Securityweek