[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fs_oEqHqsAdgRBjDVi3h6VF1TQTYygs4TX1Anho3kgBE":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"c2b80267-8d6d-4014-b034-d17be38c2a5f","In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation","in-other-news-microsoft-s-cloud-patches-hacked-dropbox-accounts-guardio-s-1-1b-v-f44fd1","Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.","This roundup covers multiple security incidents including Microsoft patching vulnerabilities in several cloud services, and a ransomware attack on a Minnesota county that resulted in a $128K payment. Additionally, 5,000 Dropbox accounts were compromised due to an integration issue with Lenovo, and exploit code was published for a critical Microsoft Exchange Server flaw affecting thousands of unpatched servers.","Microsoft patches cloud services, Dropbox accounts hacked, and a county pays ransom.","SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Microsoft releases cloud patches Microsoft has released patches for nine vulnerabilities in Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. The fixes were deployed server side and require no action from Microsoft’s customers. Project Watershed 250: cybersecurity capabilities for Texas water utilitiesAdvertisement. Scroll to continue reading. White House and Texas’ Governor have launched Project Watershed 250, a federal-private sector effort to provide water and wastewater utilities in Texas with access to free cyber defense resources and harded then against cyberattacks from China, Iran, and other hostile foreign adversaries. Minnesota county paid $128K to ransomware group Winona County in Minnesota reportedly paid a $128,539.57 ransom to restore services and protect personal information affected by a January 2026 ransomware attack. In April, the county fell victim to a second ransomware attack, claimed by the InterLock gang, but it is unclear who was responsible for the January incident. Exploit published for Exchange flaw affecting over 21,000 servers Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August, the Netherlands National Cyber Security Centre warns. On September 1, The Shadowserver Foundation, observed over 21,000 servers that have not been patched. 5,000 Dropbox accounts compromised via Lenovo login integration Dropbox has notified approximately 5,000 users that hackers compromised their accounts by abusing an issue with Lenovo’s email verification process. The attackers registered Lenovo IDs using the victim’s email addresses and then accessed their Dropbox accounts. Dropbox says it closed all unauthorized sessions and access. Knight Office phishes for Microsoft 365 and Google Workspace credentials A newly identified adversary-in-the-middle (AitM) phishing kit has been targeting Microsoft 365 and Google Workspace users to steal their account credentials, Huntress reports. Knight Office relies on token theft, a popular technique that provides attackers with an already-authenticated session that completely bypasses password requirements and MFA mechanims. Plex releases security updates The popular streaming service Plex this week announced the release of Plex Media Server 1.43.3 and Plex Desktop 1.115.0 with patches for multiple security vulnerabilities, urging users to update their instances as soon as possible. No details on the bugs have been shared, and the CVEs have not been assigned yet. Guardio valued at $1.1 billion Guardio is valued at $1.1 billion following a new funding round of $40M. Guardio protects people from the AI-driven scams that lead to identity theft. Today’s bad actors prefer to walk into a network with credentials rather than being forced to break in. Coder’s module registry website served malware A threat actor hacked Coder’s Cloudflare infrastructure and added unauthorized IP addresses that hosted malicious code. The code was served through Coder’s module registry website to a subset of users, for a short period of time. Users who downloaded the malicious code were infected with a credential stealer, Coder notes. Russian charged in US for serving malware to 80,000 freelancers Searzhudin Tamirlanovich Aktulaev, 40, of Russia, has been charged in the US with exploiting the online message platform of a freelance employment company in California to deliver malware to 80,000 freelance users between June 2016 and November 2017. Aktulaev was arrested in Cyprus last year. The indictment was filed in 2021 and unsealed on Monday, when Aktulaev appeared in court, after being extradited to the US. Lasso Security raises $30 million Israeli AI security company Lasso Security has raised $30 million in a funding round led by ClearSky, with additional support from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. The company has just announced LEAP, an AI guardrail that promises top-tier detection accuracy on CPUs. Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Related: In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug Written By SecurityWeek News Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from SecurityWeek News Palo Alto Networks Acquires AI Agent Platform ConsoleIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker SanctionsOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugVirtual Event Today: CodeSecCon – Secure Your Code and ApplicationsWebinar Today: Rethinking Cyber Defense for AI-Speed AttacksIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities Latest News HPE Patches Critical RCE Vulnerabilities in AOS-CXOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersSangoma Switchvox Vulnerabilities Exploited in the Wild12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverCatch Raises $5 Million for AI Executive Assistant With GuardrailsVMware Workstation and Fusion Updates Patch Critical VulnerabilityGoogle Patches 6th Chrome Zero-Day of 2026Nvidia Is Buying AI Platform Hugging Face for $13 Billion Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for On","https:\u002F\u002Fwww.securityweek.com\u002Fin-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F10\u002Fcybersecurity-news.jpg","2026-09-04T16:18:30+00:00","2026-09-04T18:00:21.330123+00:00",7,[18,21,24,26,28,30],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Entra ID","product",{"name":25,"type":23},"Azure Cosmos DB",{"name":27,"type":23},"Power Automate",{"name":29,"type":23},"Copilot Studio",{"name":31,"type":23},"Azure Active Directory B2C","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[56],{"type":57,"value":58,"context":59},"cve","CVE-2026-62911","Microsoft Exchange Server vulnerability"]