Microsoft Releases Cloud Security Updates, Dropbox Accounts Hacked
This week’s cybersecurity roundup highlights Microsoft’s cloud security patches, a significant Dropbox breach, and Guardio's impressive funding milestone.

This week’s cybersecurity news has seen notable movements, from major software updates to alarming security breaches. SecurityWeek’s weekly roundup highlights important developments in the cybersecurity sector that continue to shape the landscape of threats and defenses.
Microsoft Releases Cloud Security Patches
In a significant update, Microsoft has released patches for nine vulnerabilities across its cloud service platforms including Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio. These vulnerabilities posed risks to cloud infrastructures but have now been addressed through server-side changes that require no action from customers.
Project Watershed 250: Enhancing Cybersecurity for Texas Water Utilities
In a collaborative effort, the White House and Texas’ Governor have initiated Project Watershed 250. This federal-private sector initiative aims to bolster the cybersecurity capabilities of Texas water utilities, offering access to free cyber defense resources. The initiative is particularly designed to protect against cyber threats from nations such as China and Iran.
Ransomware Attack on Winona County
Winona County in Minnesota has reportedly paid a ransom of $128,539.57 to restore services following a ransomware attack in January 2026. This incident highlights the growing trend of ransomware threats against local government organizations. Notably, Winona County was previously targeted in April by the InterLock gang, which raises questions about the adequacy of their cybersecurity defenses against repeat intrusions.
Exchange Server Exploit Puts Thousands at Risk
The Netherlands National Cyber Security Centre has issued a warning regarding a published exploit code for CVE-2026-62911, a notable vulnerability in Microsoft Exchange Server that was patched in August. Over 21,000 servers are reported to remain unpatched, leaving them vulnerable to attacks that can exploit this security gap.
Data Breach Affecting 5,000 Dropbox Accounts
This week, Dropbox disclosed that close to 5,000 user accounts were compromised following an issue related to email verification in Lenovo’s login process. Attackers utilized stolen email addresses to create unauthorized Lenovo accounts, subsequently gaining access to the affected users' Dropbox data. In response, Dropbox has initiated precautions including the closure of all unauthorized access sessions.
New Phishing Attacks via Knight Office
An emerging phishing campaign using the Knight Office kit has been identified, specifically targeting users of Microsoft 365 and Google Workspace. This kit employs a unique adversary-in-the-middle strategy to corrupt token theft, allowing hackers to bypass traditional password requirements and multi-factor authentication (MFA) systems.
Plex Media Server Security Updates
Plex has unveiled updates including Plex Media Server 1.43.3 and Plex Desktop 1.115.0, addressing multiple undisclosed vulnerabilities. Users are urged to update their software as soon as possible, although specific details on the security bugs have yet to be disclosed.

Guardio Secures $40 Million in Funding
Guardio, a cybersecurity firm specializing in protection against AI-driven scams that contribute to identity theft, has raised $40 million, lifting its valuation to $1.1 billion. This funding is expected to bolster its efforts in enhancing digital safety for users who are increasingly targeted by sophisticated cybercriminal tactics.
Malware Distributed through Coder’s Module Registry
A security incident involving Coder saw the compromise of its module registry where hackers introduced unauthorized IP addresses that served malicious software. Users who downloaded the tainted code were affected by a credential-stealing malware, signifying a serious breach in software supply chain security.
Russian Malware Operator Charged in the US
Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national, has been charged in the United States for delivering malware to around 80,000 freelance users via the online message platform of a California-based employment company. His arrest in Cyprus followed an indictment filed in 2021, which was unsealed recently after his extradition to the U.S.
Lasso Security's Growth with New Investment
Lasso Security, an Israeli AI security firm, has successfully raised $30 million in funding, primarily led by ClearSky. This investment will support its development of LEAP, an innovative AI guardrail designed to deliver high detection accuracy on CPUs, an essential component in the modern cybersecurity landscape shaped by artificial intelligence innovations.
Key Takeaways
- Microsoft patched nine vulnerabilities across its cloud platforms, improving security without requiring customer action.
- Winona County paid over $128,000 to a ransomware group to restore services after a cyberattack.
- Over 21,000 Microsoft Exchange servers remain unpatched, vulnerable to a high-severity flaw.
- Dropbox compromised about 5,000 accounts due to flaws in Lenovo’s email verification process.
- Guardio raised $40 million to counter AI-driven scams and bolster cybersecurity efforts.
The events of this week underscore the persistent and evolving threats in the cybersecurity landscape. Organizations and individuals must remain vigilant, as malicious actors continue to find innovative ways to exploit vulnerabilities and compromise systems. As we look ahead, continued adaptation and investment in security resources will be crucial for enhancing protections across sectors.
Frequently Asked Questions
