Active zero-day exploitation of a critical SharePoint vulnerability has on-premises administrators scrambling today. We also unpack a federal court ruling restoring White House press credentials, Microsoft's new deterministic security engine for AI agents, and California's aggressive new uptime mandates for public EV chargers.
Following Microsoft's retroactive RCE re-classification of SharePoint vulnerability CVE-2026-65660 that we covered earlier this week, security researchers confirmed on Thursday that the flaw is now under active exploitation in the wild. Attackers combine an anonymous delivery bug with an ObjectDataProvider gadget wrapped inside an ExpandedWrapper container to bypass type-checking routines in the ToolPane markup pipeline. The exploit utilizes LosFormatter XamlServices deserialization to drop in-memory web shells without writing files to disk. While Microsoft issued patches in August 2026 across SharePoint Server 2013, 2016, 2019, and Subscription Edition, unpatched on-premises farms remain fully exposed.
Why it matters
This active exploit vector bypasses traditional disk-based antivirus detection by operating entirely within memory under service account context. For consultants supporting hybrid or regulated client environments where on-premises SharePoint farms still handle legacy document routing, patching cannot wait for standard maintenance windows. Unauthenticated remote code execution allows immediate network pivot and credential dumping, making total anonymous access shutdown or emergency KB deployment mandatory.
Microsoft issued Message Center notification MC1470878 detailing new data location controls for commercial tenants in Germany, France, Norway, Sweden, and Switzerland. Administrators have until December 14, 2026, to set the 'Store Microsoft 365 customer data in-country' preference in the M365 Admin Center under Org Settings. By default, the setting is set to disabled, which allows Microsoft to balance tenant storage across the broader EU Data Boundary. Missing the December deadline initiates potential cross-border migration, with a mandatory six-month waiting window required to reverse the move.
Why it matters
For consultants serving European life-sciences and financial services clients, this silent default setting poses an immediate regulatory risk under strict national data residency mandates. If tenant admins fail to flip the toggle to enabled before December 14, underlying SharePoint, Teams, Exchange, and Copilot data can be shifted into regional EU datacenters outside national borders. Checking this Admin Center toggle should be added to every European tenant audit checklist immediately.
Expanding on the multi-cloud Agent 365 governance rollout we've been tracking this week, Microsoft officially integrated n8n as an ecosystem partner on Thursday. This allows custom workflow-driven agents built on n8n to run directly inside Teams, Outlook, Word, and SharePoint. The architecture provisions third-party n8n runtimes with dedicated Entra ID identities, bringing non-human automation under centralized tenant observability, audit logging, and security policy enforcement. Credentials remain in preview through the Frontier program with pricing yet to be finalized.
Why it matters
Enterprise IT teams regularly fight shadow AI automation built on open-source runtimes like n8n that bypass corporate access policies. Incorporating these external engines directly into Agent 365 solves a major architectural friction point by assigning native Entra ID non-human identities to outside workflows. Consultants can now offer clients a clear pattern to standardize and log custom open-source automations alongside native Copilot Studio agents without sacrificing tenant security boundary controls.
Microsoft released FIDES (Flow Integrity Deterministic Enforcement System) as an experimental security middleware layer in version 1.3.0 of Agent Framework on Thursday, September 24. FIDES enforces deterministic information-flow control by tagging data with integrity (trusted/untrusted) and confidentiality (public/private/user_identity) metadata. As agents process tool calls, FIDES automatically propagates these labels; if an untrusted data source attempts to invoke a privileged tool execution, the middleware intercepts the call, executing pre-set policy rules or triggering a human approval prompt.
Why it matters
Prompt injection remains an inherent vulnerability when relying on LLMs to self-police input data vs instructions. By enforcing integrity boundaries in deterministic code surrounding the model, FIDES provides an architectural circuit breaker that stops untrusted external input from executing privileged tenant actions. For solution architects, this offers a concrete Python and .NET implementation pattern to secure autonomous agents reading uncontrolled sources like public webhooks or external email.
U.S. District Judge Timothy J. Kelly issued a 14-day temporary restraining order on Thursday, September 24, ordering the Trump administration to immediately reinstate White House press credentials for journalists from MS NOW, CNN, and Politico. The order follows a joint lawsuit filed after the administration revoked hard passes over reporting on Iran diplomacy and military logistics. Justice Department attorneys argued credentialing is a revocable privilege tied to national security, but Judge Kelly noted the government provided no evidence linking the outlets' reporting to security risks or classified leaks. Reporting also revealed that key background details cited in the government's filings originated from Vice President JD Vance during a background press call.
Why it matters
The ruling establishes a firm judicial limit on executive authority to unilaterally strip press access based on unfavorable coverage or background leaks. By finding that the administration failed to show any concrete national security nexus, the court reinforces due-process protections against viewpoint discrimination. The inclusion of background briefings by administration officials in the evidentiary record highlights the legal difficulty of claiming security breaches when reporting aligns with official background statements.
The New York City Council passed Intro. 248 on Thursday, September 24, requiring the Department of Social Services to integrate Fair Fares half-fare transit discount enrollment into existing SNAP and cash assistance paperwork via a single opt-in checkbox. While eligibility for Fair Fares was expanded to 200% of the federal poverty level, bureaucratic hurdles left only 380,000 of the 1 million eligible residents enrolled as of March 2026.
Why it matters
Administrative friction remains a primary reason low-income workers fail to receive public benefits they qualify for. By removing separate application portals and piggybacking on established food-assistance workflows, this policy offer a model for municipal governments looking to increase program adoption without inflating administrative budgets.
Building on yesterday's coverage of the EvilTokens takedown, newly released details show the joint operation—which included Cloudflare alongside Microsoft and UK police—seized 50 websites and 150 domains. The phishing-as-a-service platform charged $1,500 upfront plus $500 monthly and compromised over 12,000 inboxes across 10,000 organizations. Once authenticated via OAuth device authorization flows, the platform deployed AI modules to parse inboxes, map permission trees, and automate business email compromise scams without needing user passwords.
Why it matters
This takedown highlights how quickly adversary-in-the-middle kits have weaponized legitimate input-constrained hardware flows to bypass standard multi-factor authentication. Because device code prompts occur on real Microsoft authentication endpoints, end-user training fails to spot the lure. Enterprise administrators must immediately audit Entra ID Conditional Access policies to block unused OAuth device code flows across all primary user groups.
Security researchers at LevelBlue SpiderLabs published details on Thursday, September 24, regarding Microsoft's public Self-Service Password Reset (SSPR) portal yielding distinct responses for valid versus invalid email addresses without requiring authentication. The flaw allows attackers to confirm active user accounts and enumerate their registered verification channels. LevelBlue released 'ResetSpy,' a Python tool automating this reconnaissance process. While Microsoft removed legacy CAPTCHAs in August 2026 in favor of backend rate-limiting, administrative accounts retain SSPR functionality even when disabled for general users.
Why it matters
Unauthenticated account enumeration allows threat actors to map target organizations and select precise spear-phishing channels without triggering sign-in alarms. Because administrative SSPR portals remain active even when general SSPR is turned off, privileged accounts face targeted exposure. Security teams must restrict SSPR visibility, enforce phishing-resistant FIDO2 keys for administrative roles, and audit Entra logs for abnormal verification checks.
California began enforcing a strict compliance framework under Assembly Bill 631 on Thursday, September 24, requiring publicly assisted EV fast chargers to maintain 97% annual uptime. The regulation mandates physical, contactless credit card readers on all new installations, eliminating mandatory app downloads, and requires clear per-kilowatt-hour pricing displays before charging starts. Municipalities must also streamline standard parking lot charging permit approvals down to five business days.
Why it matters
California's shift from expanding station counts to enforcing hardware reliability sets a national regulatory standard for EV charging networks. Mandatory physical card readers address a persistent pain point for non-Tesla EV owners stuck at broken or app-gated public stalls. Enforceable uptime metrics force charging operators to fix broken hardware quickly or risk losing state grant funding.
A research brief published by the Federal Reserve Bank of Boston on Thursday, September 24, demonstrates that Massachusetts job growth expanded by just 0.6 percent from mid-2022 to mid-2026, trailing the 3.8 percent national average. Economists Riley Sullivan and Jeffrey Thompson found the lag is driven by a sharp contraction in construction, healthcare, and professional services—the exact sectors responsible for two-thirds of state job growth during the 2010s. The report estimates Massachusetts missed out on 215,000 jobs relative to national trends as pre-pandemic growth patterns normalized.
Why it matters
This research counters popular narratives that attribute regional economic stagnation purely to residential housing costs, showing instead that core knowledge and healthcare sectors are normalizing after unsustainable decade-long booms. For New England business leaders and technology firms, the data highlights that high-value scientific R&D remains highly productive even as broader headcount expansion slows down across technical services.
Samsung secured FDA clearance on Friday, September 25, to deploy over-the-counter medical hearing aid functionality for the Galaxy Buds 3 Pro and 4 Pro. Scheduled for a software update in late 2026, the system incorporates an in-app medical-grade audiometric test, targeted frequency amplification, and beamforming microphones designed for mild to moderate hearing impairment.
Why it matters
Transforming ubiquitous consumer earbuds into FDA-cleared hearing aids lowers cost barriers and social stigma for individuals with mild-to-moderate hearing loss. By embedding clinical-grade frequency calibration directly into standard consumer hardware, Samsung accelerates the convergence of mainstream electronics and assistive health tech.
Adding to the regressions we've tracked stemming from September's KB5124008 update—which previously broke USB audio and Hyper-V features—Microsoft acknowledged on Thursday that the patch also breaks the Windows File History backup feature. The bug triggers KERNELBASE.dll and FileHistory.exe crashes when backing up to external drives or network shares. Microsoft released optional cumulative updates KB5124006 and KB5124010 containing targeted fixes, with a full fix scheduled for the October 13 Patch Tuesday release.
Why it matters
Silent backup failures leave power users and small offices exposed to data loss without obvious error dialogs until a file recovery attempt fails. Technical support professionals should check client Event Viewers for FileHistory.exe crashes and push the optional cumulative update manually if automated local backups have stalled.
Deterministic Governance Replaces Prompt-Based Boundary Rules As autonomous AI agents gain execution capabilities across tenant boundaries, systems like Microsoft's FIDES and WSO2's Agent Manager move enforcement from probabilistic model prompts to strict middleware architecture.
Identity-Layer Interdictions Target Post-MFA Exploitation With threat actors abusing OAuth device flows and SSPR portals, security teams and law enforcement are executing direct infrastructure takedowns and enforcing least-privilege non-human identity controls in Entra ID.
Municipalities Shift from Raw Land Supply to Administrative Streamlining Cities from New York to Elk Grove are turning to streamlined enrollment, down-payment assistance, and transit-access fixes rather than relying solely on private developer zoning variances to ease working-class cost pressure.
Enforceable Uptime Metrics Redefine EV Fast-Charging Policy State regulators and fleet managers are discarding vendor-reported availability averages in favor of 97% operational uptime mandates and physical credit card reader requirements.
Commercial Hearables Cross into Medical-Grade Assistive Tech FDA clearance for Galaxy Buds and software expansions in smart eyewear mark a structural turn toward software-defined over-the-counter hearing healthcare that bypasses traditional clinical distribution.
What to Expect
2026-10-01—MBTA automated camera enforcement begins public education phase on Boston SL4 and SL5 bus routes
2026-10-01—SpaceX Crew-13 NASA mission scheduled for liftoff from Cape Canaveral
2026-10-13—Microsoft October Patch Tuesday security release scheduled to address Windows 11 File History backup regressions
2026-12-14—Deadline for European Microsoft 365 administrators to configure in-country data residency preferences before default regional EU migration
How We Built This Briefing
Every story, researched.
Every story verified across multiple sources before publication.
🔍
Scanned
Across multiple search engines and news databases
386
📖
Read in full
Every article opened, read, and evaluated
139
⭐
Published today
Ranked by importance and verified across sources
12
— The Tenant Desk
🎙 Listen as a podcast
Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.
Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste