AI Security AI安全 6h ago Updated 3h ago 更新于 3小时前 38

In Other News: Microsoft's Cloud Patches, Hacked Dropbox Accounts, Guardio's $1.1B Valuation 其他新闻:微软云补丁、Dropbox账户被黑、Guardio估值达11亿美元

Microsoft patched nine vulnerabilities across Entra ID, Azure services, and Copilot Studio, all deployed server-side requiring no customer action A new AitM phishing kit called Knight Office targets Microsoft 365 and Google Workspace users via token theft, bypassing MFA entirely Project Watershed 250 launched by the White House and Texas governor to harden water utilities against state-sponsored cyberattacks from China and Iran Israeli AI security startup Lasso Security raised $30M and launched Microsoft发布9个云产品安全补丁(Entra ID、Azure Cosmos DB、Power Automate、Copilot Studio等),修复已服务器端部署无需用户操作 白宫与德克萨斯州启动Project Watershed 250,为水务和废水处理设施提供免费网络防御资源,抵御中国、伊朗等外国对手攻击 Knight Office新型AitM钓鱼工具针对Microsoft 365和Google Workspace,通过令牌窃取技术完全绕过密码和MFA认证 Lasso Security融资3000万美元推出LEAP AI护栏,在CPU上实现顶级检测精度防护AI驱动的身份盗窃诈骗

55
Hot 热度
60
Quality 质量
50
Impact 影响力

Analysis 深度分析

TL;DR

  • Microsoft patched nine vulnerabilities across Entra ID, Azure services, and Copilot Studio, all deployed server-side requiring no customer action
  • A new AitM phishing kit called Knight Office targets Microsoft 365 and Google Workspace users via token theft, bypassing MFA entirely
  • Project Watershed 250 launched by the White House and Texas governor to harden water utilities against state-sponsored cyberattacks from China and Iran
  • Israeli AI security startup Lasso Security raised $30M and launched LEAP, an AI guardrail with top-tier CPU-based detection accuracy
  • Over 21,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911 after exploit code was publicly released

Why It Matters

This roundup highlights the accelerating convergence of AI and cybersecurity threats, from AI-driven scams enabling credential theft to AI-powered guardrails emerging as a defensive countermeasure. For AI practitioners, the Lasso Security funding and LEAP announcement signal growing investment in AI security infrastructure, while the Knight Office phishing campaign demonstrates how token theft techniques are becoming weaponized at scale against enterprise SaaS platforms.

Technical Details

  • Microsoft Cloud Patches: Nine vulnerabilities patched across Entra ID, Azure Cosmos DB, Power Automate, Copilot Studio, Azure AD B2C, Fabric, Azure AI Language, and Discovery Studio; all fixes deployed server-side with zero customer action required
  • Knight Office AitM Campaign: Adversary-in-the-middle phishing kit steals authentication tokens from Microsoft 365 and Google Workspace, bypassing both password requirements and MFA by capturing already-authenticated sessions
  • CVE-2026-62911: High-severity Microsoft Exchange Server vulnerability with publicly available exploit code; Shadowserver Foundation observed 21,000+ unpatched servers as of September 1
  • LEAP AI Guardrail: Lasso Security's new product promises top-tier detection accuracy running on CPUs, designed to protect against AI-driven identity theft scams
  • Supply Chain Attack via Coder: Threat actor compromised Coder's Cloudflare infrastructure to inject malicious IP addresses into the module registry, delivering credential stealer malware to a subset of users

Industry Insight

  • The rise of token theft-based AitM attacks like Knight Office represents a fundamental shift in phishing strategy, rendering traditional MFA defenses insufficient and pushing organizations toward zero-trust architectures and continuous authentication monitoring
  • The $30M funding for Lasso Security and Guardio's $1.1B valuation reflect surging investor confidence in AI-native security solutions, suggesting the market will increasingly favor AI-powered threat detection over traditional signature-based approaches
  • The unpatched Exchange vulnerability affecting 21,000+ servers underscores the critical importance of automated patch management and vulnerability prioritization frameworks in enterprise environments

TL;DR

  • Microsoft发布9个云产品安全补丁(Entra ID、Azure Cosmos DB、Power Automate、Copilot Studio等),修复已服务器端部署无需用户操作
  • 白宫与德克萨斯州启动Project Watershed 250,为水务和废水处理设施提供免费网络防御资源,抵御中国、伊朗等外国对手攻击
  • Knight Office新型AitM钓鱼工具针对Microsoft 365和Google Workspace,通过令牌窃取技术完全绕过密码和MFA认证
  • Lasso Security融资3000万美元推出LEAP AI护栏,在CPU上实现顶级检测精度防护AI驱动的身份盗窃诈骗
  • 供应链攻击持续活跃:Coder模块注册表被入侵分发凭证窃取恶意软件,俄罗斯黑客利用自由职业平台向8万用户分发恶意软件被起诉

为什么值得看

本文汇总了近期关键网络安全事件,涵盖云服务商漏洞修复、政府主导的关键基础设施保护计划、新型钓鱼攻击手法及AI安全融资动态,为从业者提供全面的威胁态势感知。

技术解析

  • Microsoft云漏洞修复:涉及Entra ID、Azure Cosmos DB、Power Automate、Copilot Studio、Azure AD B2C、Fabric、Azure AI Language和Discovery Studio等9个产品的漏洞,补丁已服务器端部署,用户无需手动操作
  • Knight Office AitM钓鱼:采用adversary-in-the-middle技术窃取Microsoft 365和Google Workspace的认证令牌,可完全绕过密码要求和多因素认证(MFA)机制
  • Lasso Security LEAP AI护栏:以色列AI安全公司推出的产品,主打在CPU上实现顶级检测精度,用于防护AI驱动的身份盗窃诈骗
  • 供应链攻击模式:Coder事件显示攻击者入侵Cloudflare基础设施,通过模块注册表向用户分发凭证窃取恶意软件;另一案例显示利用自由职业平台消息系统向8万用户分发恶意软件

行业启示

  • 关键基础设施(如水务设施)正成为国家级别网络防御的重点保护对象,联邦-私营合作模式将成为趋势
  • AI安全赛道持续升温,Guardio估值达11亿美元、Lasso Security获3000万美元融资,反映市场对AI驱动威胁防护的强烈需求
  • 供应链安全和第三方集成风险日益突出,Lenovo登录集成导致Dropbox账户被入侵、Coder模块注册表被劫持等事件警示企业需加强第三方服务的安全审计

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Policy 政策