🗂️ The Tenant Desk

Tuesday, September 8, 2026

11 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Today on The Tenant Desk: Microsoft confirms a hard data cutoff for the imminent Project Online retirement, while security teams battle a new wave of MFA-bypass attacks weaponizing Teams external chats and SharePoint device-code flows.

Microsoft 365 & SharePoint

Project Online Hard Shutdown Scheduled for September 30, 2026

Following the September 30, 2026, retirement date for Project Online we've been tracking, new technical guidance confirms Microsoft will not provide a read-only access mode or extension window. All tenant data access will cease immediately upon the deadline, requiring organizations to migrate project portfolios, custom OData feeds, and master schedules to Planner Premium, Project Server Subscription Edition, or Dynamics 365 Project Operations.

Because Planner Premium enforces strict structural constraints on custom metadata fields and task depth compared to legacy SharePoint-backed PPM environments, simple 1:1 migrations are impossible for complex project portfolios. Migration plans must include a full three-tier export of project files, underlying site content, and custom reporting schema. M365 consultants must immediately inventory tenant OData dependencies to prevent reporting failures when the underlying API endpoints go dark.

Verified across 1 sources: Boddenberg

Microsoft Teams Updates Mandate Device Portal Shifts and Endpoint Migration

Microsoft issued an enterprise roadmap update on Monday, September 7, 2026, requiring all management of Teams Rooms on Android, panels, and IP phones to transition from Teams Admin Center to the Teams Rooms Pro Management Portal by September 30, 2026. The update also confirms the retirement of Teams Live Chat on October 5 and enforces client URL shifts toward teams.cloud.microsoft.

Network and identity administrators must update proxy configurations and perimeter firewall rules to permit traffic to the teams.cloud.microsoft root domain prior to the migration deadline. Failure to re-align network boundaries will cause device management disconnections and authentication failures across room hardware. The transition shifts device administration strictly into the Pro licensing layer.

Verified across 1 sources: Empowering.Cloud

Politics, Fact-Checked

South Africa Promulgates 36-Hour Disinformation Code for Local Elections

The Electoral Commission of South Africa gazetted the Disinformation Code on Friday, September 4, 2026, binding political parties and candidates ahead of the November 4 municipal elections. The code mandates that false or misleading statements be publicly retracted within 36 hours of discovery, requires explicit labeling of AI-generated synthetic content and political ads, and establishes sanctions ranging from fines to deregistration for coordinated bot networks or doxing.

This gazetted regulation sets a concrete precedent by establishing a legally enforced, fast-turnaround timeline for political actors to correct digital falsehoods. By legally mandating synthetic media labeling and integrating the Real411 monitoring platform, the rule shifts election integrity enforcement from platform self-regulation to statutory candidate liability. The legal mechanics offer a clear framework for civic technologists tracking how electoral law adapts to AI-driven campaigns.

Verified across 3 sources: IOL · Inside Politic · Politicsweb

Cybersecurity

SynkLoader Teams Phishing Attack Weaponizes Azure Storage and Token Privileges

Adding to the Entra ID session hijacking and token theft we covered yesterday, security researchers analyzed SynkLoader on Monday, September 7, 2026, revealing a modular malware loader family distributed through Microsoft Teams external chats where actors impersonate IT help desk staff using onmicrosoft.com domains. Victims are tricked into installing a malicious PowerShell Cleaner MSI hosted on Microsoft Azure storage, unpacking an in-memory Python loader that steals credentials via a fake lock screen and establishes persistent reverse proxy access while executing a 64-privilege token adjustment burst.

Using trusted Microsoft 365 tenant domains and Azure storage endpoints allows adversaries to neutralize standard perimeter security and network reputation checks. The combination of native collaboration lures with aggressive, single-burst token privilege adjustments makes endpoint detection difficult for standard AV solutions. Enterprise defenders must enforce strict Conditional Access policies for external Teams collaboration and begin monitoring Windows Security Event ID 4703 to catch anomalous token modifications.

Verified across 1 sources: r3vhunter-research-blog

Helix Extortion Group Targets SharePoint via Vishing and Device Code Flows

Building on the device-code exploits and vishing campaigns we've been tracking from groups like 'codemado' and 'Pink', security analysts reported on Tuesday, September 8, 2026, that a data extortion cluster named Helix is targeting Microsoft SharePoint tenants. Attackers phone employees posing as managers to trick them into executing device code authentication schemes, allowing the group to register rogue authenticator apps, systematically enumerate SharePoint sites via script queries from IP 179.43.185.230, and exfiltrate document libraries for extortion.

The campaign demonstrates how threat groups exploit human trust and built-in Entra ID authentication protocols to bypass MFA without dropping endpoint malware. For SharePoint architects, the immediate takeaway is that permissive default device code settings pose a direct risk to document repositories. Disabling device code flows tenant-wide and limiting SharePoint data access to verified, compliant devices are critical steps to prevent automated exfiltration.

Verified across 1 sources: CISO Advisor

OWAReaper Implant Exploits On-Premises Exchange for Browser-Resident Mailbox Theft

Following the active exploitation of Exchange Server authentication bypasses we covered recently, security researchers published a post-mortem on Monday, September 7, 2026, detailing an active campaign exploiting CVE-2026-42897, a stored cross-site scripting flaw in on-premises Outlook Web Access (OWA). The exploit executes malicious JavaScript inside an authenticated browser session to deploy 'OWAReaper,' a browser-resident implant that steals session tokens, intercepts Exchange API calls, and alters mailbox permissions for long-term persistence without writing files to disk.

OWAReaper invalidates standard remediation playbooks like server patching or workstation reimaging because it operates entirely within authenticated web sessions and modifies server-side Exchange permissions. On-premises Exchange environments remain high-value targets for persistent access, forcing hybrid identity administrators to perform deep permission audits and token revocations after applying patches. Treating internet-exposed OWA endpoints as Tier-0 assets with strict browser session timeout limits is necessary to mitigate token theft.

Verified across 1 sources: Bulwark Black

BigBear 2.0 Phishing Platform Bypasses MFA Across 258 Microsoft 365 Tenants

Alongside the NovaCookies and codemado adversary-in-the-middle kits we tracked last month, security researchers from CloudSEK reported on Monday, September 7, 2026, that the BigBear 2.0 phishing-as-a-service platform has compromised over 5,000 Microsoft 365 credentials across 258 organizations. The service employs 42 VPS nodes running Evilginx2-based proxies to capture session tokens and uses custom inline JavaScript to disrupt FIDO2/WebAuthn prompts in the browser, forcing users onto weaker fallback authentication.

BigBear 2.0 illustrates how adversary-in-the-middle platforms actively downgrade browser authentication flows to sidestep hardware security key enforcement. By stripping WebAuthn parameters via injected scripts, the kit renders partial passkey rollouts vulnerable if fallback factors remain active. Administrators must enforce strict Conditional Access policies that explicitly block non-compliant browser sessions and legacy authentication flows.

Verified across 2 sources: BleepingComputer · News4Hackers

EVs & Charging

Versinetic Study Reveals 96% of UK EV Chargers Affected by Firmware Bugs

A study published by EV charging consultancy Versinetic on Tuesday, September 8, 2026, reveals that 96% of surveyed UK charging network professionals experienced firmware-related session failures over the past 12 months. Additionally, 57% reported that firmware issues delayed commercial hardware launches, driving 59% of operators to make signed firmware updates and cybersecurity their top 3-to-5-year engineering priority.

The data confirms that charging network unreliability is increasingly a software lifecycle problem rather than a physical hardware failure. As public charging operators scale distributed networks, unvalidated over-the-air firmware updates are creating widespread handshake errors and requiring costly manual truck rolls to reset bricked hardware. Establishing cryptographically signed firmware pipelines and automated rollback mechanisms is becoming mandatory for maintaining uptime.

Verified across 2 sources: CIE · Versinetic

New England Beat

Boston Opens 19-Story Downtown Supportive Housing Tower at 41 LaGrange Street

St. Francis House and the Planning Office for Urban Affairs hosted a ribbon-cutting ceremony on Tuesday, September 8, 2026, for a 19-story residential tower at 41 LaGrange Street in downtown Boston. The development introduces 126 units of permanent supportive housing and affordable apartments tailored for households transitioning out of homelessness, backed by municipal tax credits and state housing funds.

The project represents a high-density model for downtown infill development, combining permanent supportive services directly within a high-cost urban core. By pairing non-profit shelter operations with state-level affordable housing financing, the initiative offers a template for municipalities attempting to address chronic homelessness without displacing residents to peripheral neighborhoods.

Verified across 1 sources: PR Newswire

Science & Space

Generative Autoencoder Maps Novel Periodic Orbits in Earth-Moon Mechanics

Researchers from the University of Strathclyde and Polytechnic University of Madrid, working under the ESA-backed OrbitGPT initiative, published findings on Monday, September 7, 2026, using a variational autoencoder (VAE) to discover 10,420 valid periodic orbits in the Earth-Moon system. Trained on NASA's catalogue of 44,112 initial states, the AI model compresses trajectory dynamics into a latent space to generate mathematically verified orbital paths.

Traditional astrodynamics relies on computationally expensive numerical continuation methods that scale slowly when designing multi-body space missions. Proving that generative AI architectures can output mathematically rigorous celestial mechanics solutions enables mission planners to instantly calculate novel trajectories for cislunar satellites and Lagrange point stations. This approach significantly reduces the initial trade-space search time for complex orbital logistics.

Verified across 1 sources: Scienmag

Consumer Tech Quirks

Apple Opens Interop 2027 Submissions to Address Cross-Browser Rendering Bugs

Apple's WebKit team opened public GitHub submissions on Tuesday, September 8, 2026, for Interop 2027, the joint web standards effort alongside Google, Microsoft, and Mozilla. The announcement coincides with the Safari 27 beta release, which includes over 1,000 layout bug fixes and a refactored rendering engine. Standard proposals require automated web platform tests and close on September 23, 2026.

Cross-browser engine discrepancies in CSS grid, container queries, and event handling continue to drive up web app maintenance costs and cause unexpected layout breaks for end users. The Interop process forces browser vendors to commit to matching compliance benchmarks rather than implementing divergent proprietary features. Web developers can submit concrete rendering test cases directly to influence which cross-platform bugs get prioritized for browser engine patches next year.

Verified across 1 sources: PiunikaWeb


The Big Picture

Legacy Service Retirements Demand Immediate Data Strategy Audits Hard shutdown dates for platforms like Project Online reflect a broader shift across cloud providers toward eliminating backward compatibility. Enterprise architects must map hidden OData dependencies and API limits to prevent reporting failures.

Adversaries Target Collaboration Infrastructure for Initial Access Threat groups are increasingly shifting away from email-based lures to leverage trusted internal tools like Microsoft Teams and Azure storage, bypassing traditional boundary security controls.

Multi-Model Orchestration Enters Low-Code AI Development Integrating frontier models from multiple vendors side by side within Copilot Studio forces organizations to govern AI workloads through granular tool approval gates and separate compliance logging.

Election Authorities Codify Rapid Response Standards for Synthetic Media Regulatory bodies are introducing legally binding time limits to correct digital election disinformation, establishing strict platform and candidate accountability ahead of upcoming municipal votes.

Regional Densification Projects Shift Focus to Supportive and Affordable Inventory Municipal infrastructure projects in major metropolitan areas are increasingly pairing structural zoning adjustments with targeted non-profit partnerships to address acute housing deficits.

What to Expect

2026-09-23 Public submission deadline for Interop 2027 cross-browser standards project
2026-09-30 Microsoft Teams device management transitions to Teams Rooms Pro Management Portal
2026-09-30 Final retirement deadline for legacy Project Online cloud services
2026-10-05 Retirement date for legacy Microsoft Teams Live Chat capability
2026-11-04 South Africa local government elections held under newly gazetted Disinformation Code

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

379
📖

Read in full

Every article opened, read, and evaluated

105

Published today

Ranked by importance and verified across sources

11

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.