Microsoft patches cloud flaws; Dropbox breach; Guardio $1.1B
Microsoft applied server-side fixes for nine cloud flaws, Dropbox reported about 5,000 accounts accessed via Lenovo login verification, and Guardio raised $40 million at a $1.1 billion valuation.
Microsoft applied server-side fixes for nine vulnerabilities across its cloud services, removing the need for customers to install updates. Affected services include Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language and Discovery Studio. The company described the work as corrective updates addressing issues found across its cloud stack.
Dropbox disclosed that roughly 5,000 accounts were accessed after attackers abused an email verification process tied to Lenovo login integration. Attackers registered Lenovo IDs using victims’ email addresses and then used Lenovo’s verification flow to access Dropbox accounts linked to those addresses. Dropbox closed unauthorized sessions, revoked access tokens where needed and notified affected users. The company did not specify whether additional account data was exposed beyond the sessions flagged.
Guardio completed a $40 million funding round that values the consumer security firm at about $1.1 billion. Guardio offers browser-based tools aimed at blocking scams that lead to identity theft, including fraudulent web redirects and phishing pages. The company said the new capital will support product development and expansion of its fraud-prevention services.
Other security developments this week include publication of exploit code for CVE-2026-62911, a high-severity Microsoft Exchange Server flaw patched in August. Internet scanning groups reported more than 21,000 Exchange servers remain unpatched and exposed. Security researchers identified a new adversary-in-the-middle phishing kit called Knight Office that captures access tokens to steal authenticated sessions from Microsoft 365 and Google Workspace accounts, bypassing passwords and multifactor checks.
A developer platform’s module registry briefly served malicious downloader code after its infrastructure was altered, delivering a credential stealer to some users who downloaded affected modules. Plex released updates for its Media Server and Desktop applications to address multiple security flaws and urged users to apply the patches. Winona County, Minnesota, paid a ransom of $128,539.57 following a January ransomware incident; the county experienced a second attack in April. A Russian national has been charged in the U.S. with distributing malware to about 80,000 freelancers between 2016 and 2017. Separately, an Israeli AI security company raised $30 million and announced a new detection product.
Security practitioners note that server-side patches can close attack paths without manual updates but recommend organizations verify configurations and monitor for unusual activity. They also advise reviewing third-party login integrations and enforcing stronger verification where federated or shared email identifiers are used.








