This Week's Smaller Stories, Rounded Up
SecurityWeek's regular "In Other News" roundup covers stories that might not warrant standalone coverage but remain relevant to the broader threat landscape. This edition covers Microsoft's server-side cloud patches, a Dropbox account-takeover wave traced back to a Lenovo identity flaw, published exploit code for a patched Exchange Server bug, and a $1.1 billion valuation for consumer security vendor Guardio.
Microsoft Patches Nine Cloud Service Flaws
Microsoft rolled out fixes for nine vulnerabilities across its cloud portfolio, including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. All fixes were deployed server-side — no customer action is required.
Exchange Server Exploit Code Published
Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability that Microsoft patched in its August update. The Netherlands' National Cyber Security Centre flagged the release, and Shadowserver Foundation reported that as of September 1, more than 21,000 Exchange servers remain unpatched and exposed.
| Field | Details |
|---|---|
| CVE | CVE-2026-62911 |
| Vendor | Microsoft Exchange Server |
| Patched | August 2026 |
| Unpatched servers (Sept 1) | 21,000+ (Shadowserver) |
| Status | Public exploit code available |
Dropbox Notifies ~5,000 Users After Lenovo ID Abuse
Dropbox notified approximately 5,000 users that attackers compromised their accounts by abusing a weakness in Lenovo's email-verification process. Attackers registered Lenovo IDs using victims' email addresses, then used those Lenovo credentials to gain access to the victims' linked Dropbox accounts. Dropbox says it has closed all unauthorized sessions and revoked the associated access.
Guardio Valued at $1.1 Billion
Consumer-focused cybersecurity vendor Guardio has reached a $1.1 billion valuation, reflecting continued investor interest in browser and consumer-endpoint protection products.
Also Noted
- A newly identified adversary-in-the-middle (AitM) phishing kit, dubbed Knight Office, is targeting Microsoft 365 and Google Workspace credentials.
- Malicious code was served through a Coder module registry compromise.
- Searzhudin Tamirlanovich Aktulaev was charged with delivering malware to freelance platform users.
Why It Matters
| Story | Takeaway |
|---|---|
| Microsoft cloud patches | Server-side fixes reduce admin burden but underscore the constant flow of cloud-service CVEs |
| Exchange exploit code | 21,000+ unpatched servers with public exploit code is an active, high-priority exposure window |
| Dropbox / Lenovo | Third-party identity verification gaps can undermine unrelated services that trust them for account linking |
| Knight Office kit | AitM phishing kits continue to erode the value of password-only M365/Workspace logins |