Security1 distinct publisher2 min readPublished
The nine flaws Microsoft fixed in Entra ID, Cosmos DB and six other services never reached a patch queue. The week's real remediation cost sat instead with 21,000 exposed Exchange servers and one Minnesota county.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A fix deployed server side never enters an operator's change process: no window to book, no rollback plan to write [2]. It also leaves the operator nothing to show an auditor. Nine bugs across eight Microsoft services went out that way [3], and the remediation labor stayed with the vendor [2].
The labor bill sat elsewhere. Exploit code is now public for CVE-2026-62911, a high-severity Exchange Server flaw patched in August, which the Netherlands National Cyber Security Centre is flagging [4]. Shadowserver's September 1 count put more than 21,000 servers still unpatched [5]. Each of those is hardware somebody owns, which means a change ticket and a reboot window per host, done by staff who have other work.
Winona County, Minnesota is the money case. It reportedly paid $128,539.57 to restore services and protect personal information after a January 2026 attack [6]. In April it was ransomed again, that time claimed by InterLock, and who ran the January intrusion has not been established [7]. Three months separate the payment from the second incident [8]. The reported payment bought recovery [6]. The county remained in the target pool afterward [7].
Three of the week's account compromises involved no software flaw at all [13]. Huntress reports an adversary-in-the-middle kit called Knight Office working against Microsoft 365 and Google Workspace and stealing tokens, which hands the attacker an authenticated session and sidesteps both the password and MFA [10]. Dropbox told roughly 5,000 users that attackers registered Lenovo IDs against the victims' email addresses and used that to reach their Dropbox accounts [11]. Coder's Cloudflare infrastructure was altered to point at attacker-controlled IPs, and its module registry served a credential stealer to a subset of users [12]. In the Dropbox case, the trust relationship abused was Lenovo's email verification, not anything the Dropbox account holder configured [11].
Project Watershed 250 puts Texas water and wastewater utilities in reach of free cyber defense resources, positioned by the White House and the state's governor against China, Iran and other foreign adversaries [9]. Free access, rather than budget, is the delivery vehicle, which is a statement about what those asset owners can pay. As reported, the program arrives without named private participants and without a count of utilities in scope [14].
Ranked by verification strength, evidence, and original report placement.
Microsoft released patches for nine vulnerabilities in Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure Active Directory B2C, Fabric, Azure AI Language, and Discovery Studio.
The Microsoft fixes were deployed server side and require no action from Microsoft's customers.
Exploit code has been published for CVE-2026-62911, a high-severity Microsoft Exchange Server vulnerability patched in August, the Netherlands National Cyber Security Centre warns.
On September 1, the Shadowserver Foundation observed over 21,000 servers that have not been patched against the Exchange flaw.
In April, Winona County fell victim to a second ransomware attack, claimed by the InterLock gang, but it is unclear who was responsible for the January incident.
The White House and Texas' Governor launched Project Watershed 250, a federal-private sector effort to give water and wastewater utilities in Texas access to free cyber defense resources and harden them against cyberattacks from China, Iran and other hostile foreign adversaries.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers3 distinct publishers
security
August's 398-CVE Patch Tuesday moves the bottleneck to the test bench1 distinct publisher
security
ONCD stakes Texas water security on six months of donated vendor red teaming4 distinct publishers
security
Passkey enrollment becomes a persistence trick: $10,000 kit outlives the password reset3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet relaying other people's disclosures
Nothing in this story is reported twice. The items that hold up are the ones where SecurityWeek names who made the observation — the Dutch national cyber security centre on the published Exchange exploit, Shadowserver on the 21,000 unpatched servers, Huntress on the Knight Office kit, Dropbox and Coder on their own breaches. The Winona County payment is the weakest link: an exact figure to the cent, hedged as 'reportedly', with no originating report named. Microsoft's nine flaws arrive with eight service names and no CVE identifiers, which leaves severity and reach unverifiable.
Concrete counts, mostly of exposure
For a weekly digest the deployment facts are unusually countable. Shadowserver's 21,000 is a measured population of live servers, not a risk estimate, and Dropbox's roughly 5,000 notified users is a number the company arrived at itself. Plex shipped two named builds. Set against that, the Microsoft fixes have no observable footprint at all — server-side means there is no version string to check, so the item with the largest nominal service list is the one nobody can measure.
Exposure under-sold
The prose is drier than its own facts. A public exploit plus 21,000 unpatched mail servers gets three sentences and the same weight on the page as a $30 million funding round. The single line that leans is Microsoft's 'requires no action', which reads as reassurance precisely because no CVE detail is offered to test it, and the derived pattern across the week — three compromises that ran on stolen credentials or sessions rather than a software bug — is left for the reader to notice.
Interested parties telling their own version
Almost every item originates with someone who gains from the framing. Microsoft's server-side account turns nine cloud flaws into a customer non-event. Huntress named the phishing kit it found. Dropbox and Coder are disclosing their own incidents, on their own timing, each closing with the remediation they performed. And the funding items carry vendor copy straight through — Lasso's guardrail 'promises top-tier detection accuracy on CPUs' — with no test attached. The exception is the Exchange item, where a national CERT and a nonprofit scanner have no product to sell.
Moderate, and uneven item by item
My confidence tracks the attribution rather than the story as a whole. Where a named organisation stands behind a figure — Shadowserver's count, Dropbox's notification total — I would act on it now. Where the verb is 'reportedly', as with the county's payment, I would wait for the county's own record. The Microsoft item sits in a third category: plausible, unfalsifiable from outside, and by its own logic nothing a customer can do anything about.