In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Microsoft recently released patches for nine vulnerabilities affecting various cloud services, including Azure Cosmos DB and Power Automate. Meanwhile, hackers have been targeting Dropbox users through a Lenovo login integration issue, with around 5,000 accounts compromised so far. Additionally, a new phishing kit has emerged, designed to steal Microsoft 365 and Google Workspace credentials.

The patch release from Microsoft is significant because it addresses multiple vulnerabilities across several of its cloud services. These patches were deployed server-side, meaning customers don’t need to take any action to apply the fixes. However, it’s essential for organizations to regularly review their security configurations to ensure they’re up-to-date and protected against potential threats.

Another concerning development is the compromise of around 5,000 Dropbox accounts through an issue with Lenovo’s email verification process. Hackers registered Lenovo IDs using victims’ email addresses and then accessed their Dropbox accounts. This highlights the importance of implementing robust login protocols and verifying user identities to prevent such attacks.

A newly identified phishing kit has been targeting Microsoft 365 and Google Workspace users to steal account credentials. The attackers use token theft, a technique that allows them to bypass password requirements and multi-factor authentication mechanisms. This phishing kit is yet another example of how adversaries are constantly evolving their tactics to evade detection.

In related news, Plex announced the release of security updates for its Media Server and Desktop applications. While no details on the bugs have been shared, users are urged to update their instances as soon as possible to ensure they’re protected against potential vulnerabilities.

Furthermore, Guardio has raised $40 million in a new funding round, valuing the company at $1.1 billion. Guardio’s AI-powered technology protects people from identity theft by detecting and preventing scams that lead to malicious activity.

As we’ve seen this week, cybersecurity threats are constantly evolving, with new vulnerabilities being discovered and exploited by attackers. This highlights the importance of staying informed about the latest security developments and taking proactive measures to protect yourself and your organization against potential threats.

In light of these recent events, it’s essential for users to remain vigilant and take steps to protect themselves from phishing attacks, such as verifying login credentials and being cautious when clicking on links or downloading attachments. Additionally, organizations should regularly review their security configurations to ensure they’re up-to-date and protected against potential threats. By staying informed and proactive, we can better mitigate the risks posed by these evolving cybersecurity threats.


Source: SecurityWeek — 2026-09-04