🗂️ The Tenant Desk

Monday, September 7, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Microsoft has detailed the irreversible runtime architectures inside Copilot Studio, creating immediate token-budget implications for enterprise architects. In browser security, a finalized Manifest V2 deprecation timeline for Microsoft Edge establishes a firm shutdown date for legacy internal extensions.

Cross-Cutting

Google Issues Emergency Patch for Actively Exploited Chrome V8 Zero-Day

Google rolled out an emergency security update for Chrome to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript engine carrying a CVSS score of 8.8. The flaw was actively exploited in the wild prior to disclosure, prompting CISA to add it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 18, 2026. The fix applies to all downstream Chromium browsers, including Microsoft Edge, Brave, and Opera.

Active V8 exploitation allows unauthenticated attackers to execute arbitrary code simply by tricking a user into visiting a malicious webpage. Because Chromium forms the base for enterprise standard browsers like Edge, IT teams must ensure rapid deployment across client endpoints to prevent drive-by compromises. This update highlights the necessity of automated browser update policies over manual patch cycles.

Verified across 1 sources: Tech Insider

Copilot & Power Platform

Copilot Studio Restructures Around Multi-Harness Architecture and Skill Packages

Yesterday we covered the technical breakdown exposing incompatible runtime harnesses within Copilot Studio; today, new details confirm the specific capabilities of this multi-harness structure. The update introduces reusable Markdown/YAML skill definitions, 28-day cross-conversation user memory, and natural-language agent creation backed by Anthropic models. Crucially, billing for the GitHub-Copilot-Harness—which enables multi-step reasoning—begins immediately during the building and testing phase rather than at publication.

The choice of runtime harness is irreversible once an agent is created, forcing consultants to audit environment routing and token budgets before makers initiate development. Because development-phase testing under the GitHub harness incurs immediate token consumption, unmonitored prototyping can trigger rapid cost overruns across client tenants. Establishing strict Power Platform Admin Center policies and clear environment boundaries is required to keep agent sprawl and licensing expenses under control.

Verified across 1 sources: Boddenberg

OpenAI GPT-6 Astra Integrates into Copilot Studio with Computer-Use Capabilities

Microsoft confirmed the integration of OpenAI's GPT-6 Astra across Copilot, Copilot Studio, GitHub Copilot, and Microsoft Foundry. The model supports long-horizon execution and direct user-interface computer-use interactions. While disabled by default on OpenAI's enterprise side, Microsoft surfaces expose granular controls at the tenant, environment, and agent level, raising new governance considerations around prompt injection via on-screen elements and hidden reasoning chains.

Computer-use capabilities shift agentic execution from structured API calls to direct UI manipulation, rendering traditional connector-based Data Loss Prevention (DLP) rules ineffective. IT administrators must audit environment-level model settings to prevent unmonitored deployment of UI-driven agents. Implementing mandatory human-in-the-loop checkpoints is essential before granting autonomous computer-use models access to production software.

Verified across 1 sources: Power Platform Engineer

Microsoft 365 & SharePoint

Microsoft Edge Details Manifest V2 Deprecation Timeline Through April 2027

Microsoft confirmed its complete phaseout schedule for Manifest V2 (MV2) browser extensions in Microsoft Edge, aligning with Chromium industry standards. Enterprise warning rollouts begin in early January 2027, culminating in complete MV2 removal by late April 2027. Enterprise group policies like ExtensionManifestV2Availability will temporarily allow legacy extension execution before being permanently stripped.

Organizations relying on custom internal add-ons or legacy browser extensions face a firm deadline to re-architect tools to Manifest V3. Because Manifest V3 eliminates remotely hosted code and restricts webRequest APIs, line-of-business extensions will fail once policy workarounds expire in April 2027. Consultants must initiate inventory audits across client managed devices now to migrate custom extensions through the Partner Center without disrupting workflow operations.

Verified across 3 sources: Neowin · Hands On Tek · MWPro

Enterprise AI

Five Major Software Vendors Converge on Three-Layer Agent Governance Stack

Broadcom, Citrix, CrowdStrike, ServiceNow, and Genesys have independently unveiled nearly identical three-layer architecture stacks for production AI agents, focusing on connectivity, security/governance, and observability. Driven by Gartner data showing 60% of generative AI proofs-of-concept were abandoned in 2024 due to governance gaps, vendors are bundling these controls into core platforms rather than selling separate SKUs. Anthropic's Model Context Protocol (MCP) powers the connectivity layer across these solutions.

This architectural convergence indicates that ungoverned, experimental agent deployments are no longer viable for enterprise IT. By embedding governance directly into existing platforms, vendors are establishing mandatory control planes for autonomous workflows. For technical leads, this standardization simplifies security enforcement but increases vendor lock-in across observation and policy execution paths.

Verified across 1 sources: Forkast News

Politics, Fact-Checked

Trump Administration Renews Supreme Court Appeal over USPS Mail Ballot Rules

Yesterday we covered the Justice Department's emergency Supreme Court appeal seeking to lift Judge Indira Talwani's preliminary injunction against USPS mail-in voting rules. As the legal battle advances, Solicitor General John Sauer has argued that blocking the administrative rule causes operational confusion. In response, voting rights groups noted that states cannot feasibly implement the required ballot design changes and database integrations before the November midterms.

The high court's decision will directly dictate the administrative mechanics of mail-in ballot delivery for state election offices across the nation. Requiring last-minute ballot re-designs and federal portal integrations risks creating severe logistical bottlenecks as election workers begin mailing ballots to voters. The ruling serves as a major judicial test regarding federal executive authority over state-administered election infrastructure.

Verified across 3 sources: Associated Press · Democracy Docket · The New York Beat

Cybersecurity

Warlock Ransomware Attacks Target Unpatched On-Premises SharePoint Servers

A newly identified ransomware strain named Warlock is actively exploiting critical vulnerabilities in self-hosted Microsoft SharePoint instances. Attackers use crafted HTTP POST requests to deploy malicious web shells, achieving remote code execution, local privilege escalation, and lateral movement. The campaign terminates endpoint security agents, encrypts files with the .x2anylock extension, and exfiltrates corporate data using RClone across targets in essential sectors.

This active campaign reinforces the severe operational exposure faced by client tenants maintaining hybrid or on-premises SharePoint environments without aggressive patch cadence. Because the attackers leverage web shells for initial foothold and disable endpoint security tools, standard perimeter defenses are insufficient. Enterprise architects must ensure immediate application of security updates and enforce strict runtime monitoring on all public-facing SharePoint servers.

Verified across 1 sources: Cybersecurity News

Entra ID Session Hijacking and Refresh Token Theft Bypass Standard MFA

Following Friday's report that session hijacking has overtaken multi-factor authentication as the dominant attack vector, security analyses are detailing the specific mechanics in Microsoft Entra ID. Because standard Conditional Access policies evaluate access only during initial authentication, threat actors are leveraging stolen primary refresh tokens (PRTs) and OAuth-2.0 tokens to inherit active, compliant sessions for up to 90 days. Primary compromise methods include the Evilginx AiTM relays and device-code exploits we've been tracking, alongside browser infostealers like LummaC2.

This threat evolution invalidates reliance on traditional multi-factor authentication alone, as valid session tokens bypass login checks entirely. Security consultants must advise enterprise clients to deploy Token Protection, enforce Continuous Access Evaluation (CAE), and mandate phishing-resistant FIDO2 passkeys. Without post-authentication session monitoring, compromised tokens allow persistent unauthorized access to cloud resources.

Verified across 1 sources: A7

Working-Class Economy

South Korea Expands Unconditional Food Security Welfare Program Nationwide

South Korea's Ministry of Health and Welfare expanded its 'Geunyang Dream' food security safety net to all 175 basic local governments nationwide. Originally piloted in Gyeonggi Province, the initiative supplies essential groceries worth KRW 20,000 per person immediately upon request, bypassing formal administrative proof-of-poverty documentation. Backed by KRW 13.5 billion in private donations alongside public funding, the rollout has assisted over 210,000 people and connected tens of thousands to long-term social services.

Eliminating bureaucratic proof requirements allows safety-net programs to assist low-income individuals who traditionally slip through complex welfare application filters. The combination of immediate basic emergency relief and integrated public-private funding provides a working model for lowering administrative overhead in social support. Tracking this national deployment demonstrates how dignity-first policy design improves service delivery for vulnerable populations.

Verified across 1 sources: Asia Business Daily

EVs & Charging

Porsche Cayenne EV Demonstrates 349-kW Peak Intake in Fast-Charging Test

Independent testing of the Porsche Cayenne Electric at a 400-kW public charging station demonstrated a charge from 13% to 83% state-of-charge in 18 minutes using a NACS-to-CCS adapter. The session reached a measured peak power input of 349 kW, closely matching Porsche's official 16-minute 10%-to-80% claim. The vehicle relies on a double-sided battery liquid cooling system to manage severe thermal loads during high-amperage charging.

Demonstrating sustained power delivery near 350 kW validates that 800V-class battery architectures can drastically reduce highway charging stops to under twenty minutes. However, the scarcity of megawatt-class public chargers in North America means drivers will rarely achieve these peak curves on routine trips. The benchmark highlights that thermal dissipation hardware, rather than cell capacity, dictates real-world fast-charging speeds.

Verified across 1 sources: Jalopnik

New England Beat

Fall River Navigates Contentious Debate Over State Housing Density Mandates

Fall River city leaders and neighborhood groups are debating proposed state legislation under the Housing Production and Zoning Reform Act, which would override local zoning rules to allow higher residential density near transit corridors. State advocates argue the mandate is necessary to curb regional rent increases across the South Coast, while municipal officials express concern regarding infrastructure capacity, public school loads, and loss of local control.

The conflict in Fall River reflects broader legislative battles across Massachusetts as state leaders use density mandates to address the regional housing shortage. For commercial real estate developers and municipal planners, changing zoning frameworks alter property valuations and infrastructure requirements along transportation corridors. The outcome will set key precedents for how gateway cities balance local autonomy with state-directed growth goals.

Verified across 1 sources: South Coast Today

Science & Space

Microscopic Arachnoid Fenestrations Discovered as Primary Brain Waste Clearance Route

Researchers in South Korea identified microscopic 2 to 12 micrometer openings in the arachnoid membrane, named 'arachnoid fenestrations,' that act as a primary exit route for cerebrospinal fluid draining into cervical lymph nodes. Experimentally blocking these fenestrations in animal models severely impaired amyloid-beta clearance. Crucially, administering a nasal dose of vascular endothelial growth factor C (VEGF-C) in older mice restored fluid outflow to youthful levels without physically repairing the shrunken membrane holes.

Discovering this physical exit pathway resolves a long-standing anatomical question regarding how the central nervous system flushes metabolic waste. Demonstrating that VEGF-C treatment can restore fluid clearance despite structural aging opens new therapeutic avenues for neurodegenerative conditions like Alzheimer's disease. The research suggests downstream lymphatic pumping can compensate for structural degradation without requiring surgical repair.

Verified across 1 sources: Take Control


The Big Picture

Irreversible Runtime Decisions Force Front-Loaded Architectural Audits Across Copilot Studio and browser platforms, configuration choices are shifting from flexible runtime toggles to permanent, irreversible boundaries. Selecting between the GitHub Copilot Harness or standard environments instantly freezes model availability, data protection paths, and billing triggers, while browser policies like Edge's Manifest V2 sunset eliminate temporary admin workarounds.

Vendor Infrastructure Converges Around Deterministic Policy Layers Major enterprise software vendors are abandoning probabilistic LLM self-governance in favor of three-layer stacks combining Open Policy Agent (OPA) gates, ephemeral container sandboxes, and short-lived credentials. Rather than relying on system prompts, production workflows now enforce security through kernel-level behavioral monitoring and strict API proxies.

Non-Human Identity Management Bypasses Perimeter Login Controls As adversary attacks pivot to session token hijacking, refresh token replay, and rogue agent tool calls, traditional multi-factor authentication at login is proving insufficient. Security postures are shifting toward Continuous Access Evaluation (CAE), short-lived service credentials, and dedicated agent identity registries to constrain post-authentication session abuse.

Direct Administrative Interventions Target High-Frequency Household Expenses Policy initiatives are bypassing traditional bureaucratic gatekeeping to deliver direct relief for basic living costs, ranging from nationwide unconditional food security programs in South Korea to local minimum wage floors and targeted rural basic income pilots.

Public Charging Infrastructure Focuses on Peak Intake Efficiency Real-world testing of 400-kW architectures and megawatt-class charging platforms demonstrates that battery thermal management and sustained high-kw curve maintenance are eclipsing raw battery capacity as the primary drivers for long-distance EV travel.

What to Expect

2026-09-08 New Hampshire U.S. Senate primary election following Sen. Jeanne Shaheen's retirement.
2026-09-18 CISA federal agency patching deadline for actively exploited Chrome/Chromium V8 zero-day CVE-2026-85046.
2026-09-30 New England Regional Summit on Advanced Nuclear and Fusion Power at UMass Lowell hosted by Gov. Maura Healey.
2026-10-16 Public preview launch for Dataverse column-based security filtering.
2027-01-04 Microsoft Edge begins worldwide enterprise rollout of Manifest V2 extension deprecation warnings.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

337
📖

Read in full

Every article opened, read, and evaluated

106

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.