Microsoft Cloud Patches, Dropbox Account Compromises, and Project Watershed 250 Highlight Security News
Microsoft has released server-side patches for multiple cloud services, while approximately 5,000 Dropbox accounts were compromised due to a Lenovo ID integration flaw. Additionally, a new federal-private sector initiative aims to bolster Texas water utility cybersecurity.

Microsoft has issued server-side patches for nine vulnerabilities affecting a range of its cloud services, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. These fixes require no action from customers, as they were deployed remotely.
In a separate incident, Dropbox has alerted around 5,000 users that their accounts were compromised. The attackers exploited a weakness in Lenovo's email verification process, using compromised Lenovo IDs to gain unauthorized access to Dropbox accounts. Dropbox has since closed all identified unauthorized sessions and access points.
On the policy and initiative front, the White House and the Governor of Texas have launched 'Project Watershed 250.' This collaborative effort between federal and private sectors aims to provide water and wastewater utilities in Texas with free cyber defense resources. The initiative is designed to harden these critical infrastructure entities against cyberattacks originating from hostile foreign adversaries, including those from China and Iran.
This week's security landscape also saw a published exploit for CVE-2026-62911, a critical Microsoft Exchange Server vulnerability that was patched in August. The Netherlands National Cyber Security Centre warned that over 21,000 servers remain unpatched, leaving them susceptible to attackers who can replay captured NTLM credentials to impersonate users.
Further highlighting the threat to cloud services, a new adversary-in-the-middle (AitM) phishing kit, dubbed 'Knight Office,' has been observed targeting Microsoft 365 and Google Workspace users. This kit employs token theft, a technique that bypasses password requirements and multi-factor authentication by stealing already-authenticated sessions.
Plex, the popular streaming service, has also released security updates for its Media Server and Desktop applications to address multiple vulnerabilities, though specific details and CVE assignments are pending. Meanwhile, the cybersecurity firm Guardio has achieved a valuation of $1.1 billion following a $40 million funding round, underscoring the growing market for solutions protecting users from AI-driven scams and credential theft.
Other notable events include a ransomware payment of over $128,000 by Winona County, Minnesota, following a January attack, with a second ransomware incident claimed by the InterLock gang occurring in April. Additionally, Coder's module registry website was compromised, serving malware to a subset of users, and a Russian national has been charged in the US for distributing malware to approximately 80,000 freelancers between 2016 and 2017.