SecurityWeek’s weekly cybersecurity information roundup presents a concise overview of essential developments that won’t obtain full standalone protection but stay related to the broader risk panorama.
This curated abstract highlights key tales throughout vulnerability disclosures, rising assault strategies, coverage updates, business studies, and different noteworthy occasions to assist readers keep a well-rounded consciousness of the evolving cybersecurity surroundings.
Listed below are this week’s highlights:
Microsoft releases cloud patches
Microsoft has launched patches for 9 vulnerabilities in Entra ID, Azure Cosmos DB, Energy Automate, Copilot Studio, Azure Energetic Listing B2C, Material, Azure AI Language, and Discovery Studio. The fixes had been deployed server aspect and require no motion from Microsoft’s prospects.
Venture Watershed 250: cybersecurity capabilities for Texas water utilities
White Home and Texas’ Governor have launched Venture Watershed 250, a federal-private sector effort to supply water and wastewater utilities in Texas with entry to free cyber protection assets and harded then towards cyberattacks from China, Iran, and different hostile overseas adversaries.
Minnesota county paid $128K to ransomware group
Winona County in Minnesota reportedly paid a $128,539.57 ransom to revive companies and defend private data affected by a January 2026 ransomware assault. In April, the county fell sufferer to a second ransomware assault, claimed by the InterLock gang, however it’s unclear who was accountable for the January incident.
Exploit printed for Trade flaw affecting over 21,000 servers
Exploit code has been printed for CVE-2026-62911, a high-severity Microsoft Trade Server vulnerability patched in August, the Netherlands Nationwide Cyber Safety Centre warns. On September 1, The Shadowserver Basis, noticed over 21,000 servers that haven’t been patched.
5,000 Dropbox accounts compromised by way of Lenovo login integration
Dropbox has notified roughly 5,000 customers that hackers compromised their accounts by abusing a difficulty with Lenovo’s electronic mail verification course of. The attackers registered Lenovo IDs utilizing the sufferer’s electronic mail addresses after which accessed their Dropbox accounts. Dropbox says it closed all unauthorized classes and entry.
Knight Workplace phishes for Microsoft 365 and Google Workspace credentials
A newly recognized adversary-in-the-middle (AitM) phishing package has been focusing on Microsoft 365 and Google Workspace customers to steal their account credentials, Huntress studies. Knight Workplace depends on token theft, a preferred approach that gives attackers with an already-authenticated session that utterly bypasses password necessities and MFA mechanims.
Plex releases safety updates
The favored streaming service Plex this week introduced the discharge of Plex Media Server 1.43.3 and Plex Desktop 1.115.0 with patches for a number of safety vulnerabilities, urging customers to replace their situations as quickly as attainable. No particulars on the bugs have been shared, and the CVEs haven’t been assigned but.
Guardio valued at $1.1 billion
Guardio is valued at $1.1 billion following a brand new funding spherical of $40M. Guardio protects folks from the AI-driven scams that result in id theft. At the moment’s unhealthy actors want to stroll right into a community with credentials somewhat than being compelled to interrupt in.
Coder’s module registry web site served malware
A risk actor hacked Coder’s Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was served by means of Coder’s module registry web site to a subset of customers, for a brief time period. Customers who downloaded the malicious code had been contaminated with a credential stealer, Coder notes.
Russian charged in US for serving malware to 80,000 freelancers
Searzhudin Tamirlanovich Aktulaev, 40, of Russia, has been charged within the US with exploiting the net message platform of a contract employment firm in California to ship malware to 80,000 freelance customers between June 2016 and November 2017. Aktulaev was arrested in Cyprus final 12 months. The indictment was filed in 2021 and unsealed on Monday, when Aktulaev appeared in court docket, after being extradited to the US.
Lasso Safety raises $30 million
Israeli AI safety firm Lasso Safety has raised $30 million in a funding spherical led by ClearSky, with extra assist from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Information. The corporate has simply introduced LEAP, an AI guardrail that guarantees top-tier detection accuracy on CPUs.
Associated: In Different Information: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions









