🗂️ The Tenant Desk

Wednesday, September 23, 2026

12 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

Law enforcement is pushing back against the recent wave of device-code phishing platforms, with Microsoft and UK police dismantling the EvilTokens infrastructure. In today's edition, we also cover a strict 5 TB hard cap coming to OneDrive for Business, retroactive remote code execution risks in legacy SharePoint farms, and Apple's impending software fix for the iPhone 18 Pro's kernel panics.

Microsoft 365 & SharePoint

Microsoft Enforces 5 TB Hard Cap on OneDrive for Business with Pay-As-You-Go Billing Option

Microsoft issued Message Center notification MC1465765 on Wednesday, September 23, 2026, establishing a strict 5 TB storage limit per user on OneDrive for Business and retiring legacy 25 TB expansion paths. Enterprise accounts exceeding 5 TB will be placed into a read-only state between November 2026 and February 2027 until consumption drops below the limit. To accommodate high-capacity requirements, Microsoft launched a preview of Pay-as-You-Go storage billed at $0.20/GB/month through Azure subscription billing, alongside fixed capacity packs.

This policy ends historical enterprise reliance on soft storage limits and requires consultants to audit client tenants for accounts exceeding 5 TB before read-only restrictions lock user files. Organizations maintaining large archival user profiles must budget for metered Azure PAYG storage or execute immediate data migration strategies to SharePoint Embedded or cold Azure storage. Administrators should run Graph API consumption reports immediately to identify impacted users ahead of the November enforcement window.

Verified across 1 sources: Office 365 IT Pros

Microsoft Upgrades SharePoint Vulnerability CVE-2026-65660 Rating to Remote Code Execution

Technical analyses published Tuesday, September 22, 2026, detail Microsoft's retroactive re-classification of CVE-2026-65660 in SharePoint Server from a 6.5 spoofing vulnerability to an 8.8 Remote Code Execution (RCE) vulnerability. The flaw stems from unescaped quote handling in ToolPane web part markup that bypasses SafeControls allowlist checks, permitting attackers to inject malicious Register directives and execute in-memory web shells via XAML deserialization within the worker process. The update applies to SharePoint Server Subscription Edition, 2019, and 2016.

Relying on initial vendor severity ratings during vulnerability triage can leave critical enterprise infrastructure exposed to severe exploitation vectors. Because SharePoint 2016 and 2019 reached extended end-of-life in July 2026, the August security updates represent the final security patches available for those legacy on-premises farms. On-premises administrators must verify that August cumulative updates are fully deployed and accelerate migration plans to SharePoint Online or supported infrastructure.

Verified across 2 sources: pk-sharma.com · The Cyber Sec Guru

October 2026 Microsoft Deadlines Usher in Publisher Retirement and EWS Blocking

Microsoft updated documentation on Tuesday, September 22, 2026, detailing major application deprecation deadlines hitting in October 2026. Key cutoffs include a complete kill switch for Publisher 365 on October 1, the blocking of Exchange Web Services (EWS) in Exchange Online on October 1, the end of support for Office 2021 on October 13, and a feature freeze at Version 2608 for Microsoft 365 Apps running on Windows 10 and Windows Server 2022.

These firm retirement dates demand immediate operational triage to prevent workflow failures across enterprise tenants. Organizations using legacy line-of-business applications reliant on Exchange Web Services must complete their Graph API migrations immediately to avoid service interruptions. Furthermore, the feature freeze on Windows 10 establishes a clear operational divergence in Microsoft 365 app capabilities between legacy OS environments and Windows 11.

Verified across 1 sources: Office Watch

Enterprise AI

BigID Launches AgentIQ for Autonomous Data Security via Model Context Protocol

BigID announced the general availability of AgentIQ on Tuesday, September 22, 2026, an agentic security automation engine designed to execute cross-environment data discovery, breach investigation, and automated remediation. The tool decouples security operations from vendor consoles by connecting natively to foundation models including Claude, Microsoft Copilot, ChatGPT, and Google Gemini through a secure Model Context Protocol (MCP) server.

By routing natural-language security commands over MCP directly into underlying data stores, AgentIQ allows security teams to enforce remediation without navigating disparate administrative portals. This architecture eliminates manual query construction for compliance checks while establishing a standardized boundary between generative AI interfaces and backend data layers. For enterprise architects, utilizing open protocol standards like MCP provides a scalable alternative to proprietary vendor connectors when securing multi-model AI environments.

Verified across 1 sources: CIO First

Proofpoint Unveils Agentic Data and AI Security System Driven by Autonomous Agents

At Proofpoint Protect 2026 on Tuesday, September 22, 2026, Proofpoint introduced its Agentic Data and AI Security platform powered by three autonomous agents: Zero-Touch Detection, Instant Investigation, and Protection Optimization. Built on the Proofpoint Knowledge Graph, the platform introduces Semantic Business Policies to convert natural-language compliance rules into runtime controls, attempting to address survey data showing 52% of enterprise security teams lack confidence in their AI detection controls.

Autonomous AI agents operate at speeds that invalidate traditional manual log reviews and static security boundaries. Unifying intent-based access monitoring with underlying data context allows organizations to prevent unauthorized data exfiltration without blocking productivity. For enterprise AI consultants, embedding semantic controls into runtime execution paths provides a viable model for securing autonomous agent workflows interacting with sensitive business repositories.

Verified across 1 sources: InfoSec Today

Politics, Fact-Checked

Federal Noncitizen Voting Audit Yields 160 Arrests Out of 211 Million Voters

Following the whistleblower disclosures regarding DHS voter file quotas we tracked last week, Homeland Security Investigations senior official Matthew Millhollin reported on Tuesday that a federal audit of state voter rolls identified roughly 1,600 voter fraud cases and resulted in 160 arrests nationwide. The figures, released six weeks before the midterm elections, represent a tiny fraction of the nation's 211 million registered voters, contradicting official executive claims of widespread noncitizen voting. Election law experts confirmed that existing state verification safeguards effectively maintain voter roll integrity.

This official accounting provides evidence-based data regarding the actual incidence of noncitizen voter fraud, contrasting sharply with high-profile political claims used to justify administrative voting restrictions. For civic-minded leaders, the modest arrest numbers demonstrate that state-level list maintenance protocols function effectively without requiring aggressive federal intervention. Documenting these primary figures helps protect public confidence in election administration against unverified viral claims ahead of the midterms.

Verified across 1 sources: MyNorthwest

Working-Class Economy

Los Angeles City Council Approves $467 Million Funding Notice for Affordable Housing

The Los Angeles City Council voted 13-0 on Tuesday, September 22, 2026, to authorize a $467 million Notice of Funding Availability (NOFA) under the 'Homes for LA' initiative to construct and preserve affordable rental units. Scheduled for release on October 13, the capital is largely funded by Measure ULA—the city's transfer tax on high-value real estate sales—which has generated nearly $1.2 billion since April 2023 despite ongoing debates over its impact on commercial property transactions.

Municipal capital deployments funded by local transfer taxes represent a major experiment in stabilizing housing costs for lower- and middle-income urban residents. By directing nearly half a billion dollars toward dedicated affordable housing construction, Los Angeles is testing whether localized revenue tools can expand housing inventory fast enough to ease cost-of-living pressures. Tracking the execution of this capital allocation provides concrete data on the viability of municipal tax models in addressing metropolitan housing shortages.

Verified across 1 sources: MyNewsLA

Cybersecurity

Law Enforcement and Microsoft Takedown EvilTokens PhaaS Infrastructure

Adding to the wave of adversary-in-the-middle platforms we've been tracking like GhostCode and BigBear 2.0, Microsoft's Digital Crimes Unit and the UK Metropolitan Police disrupted the EvilTokens phishing-as-a-service (PhaaS) platform in a joint operation reported Tuesday. Authorities arrested two suspected administrators in London while Microsoft seized 50 websites and disabled over 150 domains. EvilTokens compromised more than 12,000 Microsoft 365 accounts globally by weaponizing automated OAuth 2.0 device code authorization flows and AI-generated lures to bypass traditional MFA and perform post-compromise Graph API reconnaissance.

While seizing this infrastructure provides immediate operational relief, security teams cannot rely solely on law enforcement disruptions because competing PhaaS kits continue to fill the void left by platforms like EvilTokens and GhostCode. Consultants must advise clients to enforce strict Conditional Access policies that explicitly restrict or disable device code authentication for non-essential users and push toward FIDO2 passkeys.

Verified across 3 sources: Dark Reading · BleepingComputer · The Register

TeamFiltration Campaign Targets Dormant M365 Service Accounts via Password Spraying

Proofpoint published research on Wednesday, September 23, 2026, detailing a campaign dubbed UNK_CondorFiltration that targeted over 5,700 Microsoft 365 accounts across 28 organizational tenants in Latin America. Using AWS EC2 nodes, threat actors executed password spraying attacks specifically against unmanaged, dormant service and functional accounts lacking multi-factor authentication. Seven accounts were successfully compromised, enabling attackers to conduct internal reconnaissance across SharePoint Online, OneDrive, and the Azure Portal.

Dormant service accounts and non-human identities without MFA enforcement remain a high-value entry point for cloud tenant reconnaissance. Because these accounts rarely generate active user telemetry, credential compromises can go unnoticed while attackers harvest sensitive documents from SharePoint and Exchange repositories. System architects must audit non-human identities, enforce strict Conditional Access baseline policies, and apply password rotation routines across all non-interactive accounts.

Verified across 2 sources: Adrian Hendry · Proofpoint

New England Beat

Massachusetts Proposes State AI Impact Dashboard Across 400 Government Use Cases

Speaking at the Massachusetts Digital Government Summit in Boston on Tuesday, September 22, 2026, Executive Office of Technology Services and Security Secretary Jason Snyder proposed creating a statewide AI dashboard. The system will track task-level productivity, educational outcomes, and workforce impacts across more than 400 active state AI use cases while establishing mandatory control standards for deployments in critical public infrastructure.

Tracking task-level metrics rather than broad employment trends offers a concrete, data-driven framework for public-sector technology governance. For regional IT consultants and enterprise architects working with state agencies, this initiative signals that future government procurement will require built-in telemetric reporting on AI usage and risk controls. Establishing standardized productivity tracking provides a clear blueprint for private sector organizations seeking to quantify AI return on investment.

Verified across 1 sources: State House News Service

Science & Space

RNA Methylation Enzyme METTL3 Protects Aging Cochlea Against Inflammatory Damage

In a study published Tuesday, September 22, 2026, in the Journal of Molecular Medicine, researchers at Sun Yat-sen University demonstrated that the RNA-modifying enzyme METTL3 acts as an anti-inflammatory regulator in the aging inner ear. The team discovered that METTL3 stabilizes NFKBIA messenger RNA via m6A modification, suppressing the NF-κB pathway and NLRP3 inflammasome activation. Restoring METTL3 activity in aged mice significantly improved auditory brainstem response thresholds and preserved cochlear hair cells.

Age-related hearing loss (presbycusis) currently lacks pharmaceutical interventions to prevent or reverse cellular degeneration, forcing reliance on auditory hardware. Identifying an epitranscriptomic mechanism that protects inner ear structures from chronic inflammation opens up possibilities for therapeutic drug development targeting mRNA modifications. While delivery challenges remain before human clinical trials can begin, this research establishes a molecular target for delaying age-related hearing decline.

Verified across 1 sources: Scienmag

Consumer Tech Quirks

Apple Confirms In-Development Software Patch for iPhone 18 Pro Face ID Panics

Yesterday we covered the technical analysis linking the iPhone 18 Pro's 'panic full' kernel reboots to iOS 27 sensor handling; today, Apple confirmed through an official in South Korea that a software update is currently in development to address the issue. The faults, which trigger full system reboots and 'panic-full' log entries, occur specifically during in-app Face ID authentication requests, indicating a software conflict within the biometric API layer rather than a permanent hardware sensor defect.

By officially confirming the software-level root cause we tracked yesterday, Apple allows technical end users to avoid unnecessary device exchanges at retail stores while awaiting the iOS update. The incident nonetheless highlights ongoing software quality assurance challenges during major mobile OS rollouts on flagship silicon architectures.

Verified across 1 sources: The Korea Herald


The Big Picture

Identity Protocol Abuse Triggers Direct Infrastructure Interdictions Law enforcement and cloud vendors are pivoting from passive endpoint detection to coordinated domain seizures and arrests to halt automated OAuth device-code phishing kits.

Uncapped Cloud Storage Gives Way to Metered Enterprise Limits Microsoft's enforcement of a 5 TB OneDrive limit signals a permanent industry turn toward metered, usage-based cloud storage pricing.

Protocol-Level Control Planes Embed Governance Directly into Model Interfaces Security vendors are adopting the Model Context Protocol to execute real-time data inspection directly between foundational models and enterprise repositories.

State Governments Shift from Broad AI Ethics Policies to Granular Task Audits Public sector oversight is moving toward tracking task-level automation metrics across active state use cases rather than enforcing high-level speculative guidelines.

Retroactive Security Classifications Force Urgent Infrastructure Patch Re-evaluations Vulnerabilities initially labeled as minor spoofing flaws are being re-rated as remote code execution risks, exposing gaps in routine patch triage.

What to Expect

2026-10-01 Microsoft Publisher 365 kill switch takes effect, disabling the application for M365 subscribers.
2026-10-01 Exchange Online begins blocking Exchange Web Services (EWS) access.
2026-10-13 Office 2021 family reaches end of support; M365 Apps on Windows 10 hit feature freeze at Version 2608.
2026-11-30 European SharePoint, Office 365 & Azure Conference (ESPC 2026) convenes in Amsterdam.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

474
📖

Read in full

Every article opened, read, and evaluated

131

Published today

Ranked by importance and verified across sources

12

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.