🗂️ The Tenant Desk

Sunday, September 27, 2026

11 stories · Standard format

Generated with AI from public sources. Verify before relying on for decisions.

🎧 Listen to this briefing or subscribe as a podcast →

The fallout from a critical SharePoint RCE vulnerability escalated this weekend with an emergency federal patching directive. Also on the radar: sweeping new meeting controls and hardware deprecations for Microsoft Teams, and the D.C. Circuit sides with the Pentagon over Anthropic's model guardrails.

Microsoft 365 & SharePoint

SharePoint RCE CVE-2026-65660 Sees Active Exploitation as CISA Imposes Sept 28 Deadline

Following Thursday's confirmed active exploitation of SharePoint RCE flaw CVE-2026-65660 that we covered yesterday, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Saturday, September 26, imposing a mandatory federal remediation deadline of Monday, September 28. The flaw stems from unescaped double-quotes in the ToolPane component, allowing authenticated attackers to execute arbitrary code via XamlServices.Parse() deserialization, which threat actors are chaining with older weaknesses to achieve pre-authentication RCE on unpatched farms.

As we noted when Microsoft retroactively upgraded this flaw to a Remote Code Execution rating, many on-premises IT teams initially deprioritized the patch. This emergency CISA mandate now forces weekend patching for any client maintaining hybrid or legacy SharePoint farms, as compromised application pools allow attackers to dump local credentials and pivot laterally across internal domains.

Verified across 2 sources: Decryption Digest · PGH Networks

Microsoft September 2026 Teams Release Blocks External AI Bots and Mandates Device Migration

Microsoft detailed administrative updates for Teams on Sunday, September 27, introducing tenant meeting policy toggles to block unmanaged external AI note-taking bots from joining calls. Concurrently, Microsoft announced that Android 10 and 11 Teams Rooms devices have lost official certification, starting a 12-month support clock before complete portal deprecation. Additional administrative controls include automated call queue transcription requiring Teams Premium, breakout rooms expanding to 1,000 participants, and mandatory firewall rule updates for the new teams.cloud.microsoft endpoint domain.

Unvetted external AI bots joining corporate Teams meetings represent an unmonitored data loss vector that bypasses Purview DLP and retention controls. Implementing meeting policies to restrict these bots gives administrators immediate control over meeting transcript ownership. However, the loss of certification for Android 10 and 11 room hardware forces immediate capital budget planning for client meeting space refreshes over the coming year.

Verified across 1 sources: boddenberg.de

Copilot & Power Platform

Microsoft Provisioning Copilot Autopilot Agents as Native Entra ID Directory Principals

Building on Friday's Copilot architecture overhaul and the Autopilot identity structures we tracked earlier this month, Microsoft published updated IAM documentation on Saturday, September 26. Rather than relying on legacy shared service accounts, Autopilot instances within Microsoft 365 receive permanent Entra ID identities—complete with native Exchange mailboxes, calendars, and dedicated OneDrive storage—that now execute within the newly announced serverless Copilot Managed Runtime.

Elevating autonomous AI agents to first-class Entra principals resolves historical service-account permission hacks but fundamentally alters the directory attack surface. With these agents migrating to the new Managed Runtime, M365 consultants must immediately update Identity Governance workflows, Purview lifecycle rules, and integrate Copilot Credit consumption tracking into client FinOps dashboards.

Verified across 5 sources: CloudNinjas · Data Studios · SaaS Sentinel · Inside AI · PupuWeb

Politics, Fact-Checked

Supreme Court Halts Missouri GOP Congressional Map, Reinstating 2022 Boundaries for Midterms

The U.S. Supreme Court issued an emergency unsigned order on Friday, September 25, blocking Missouri's newly enacted 2025 congressional redistricting plan and ordering the state to use its 2022 district map for the upcoming midterm elections. The ruling reverses an 8th Circuit Court of Appeals decision and aligns with a Missouri Supreme Court determination that suspended the 2025 map following a citizen veto referendum petition. The intervention preserves the current district lines in Kansas City's 5th Congressional District, preventing a 41-point partisan shift.

The Supreme Court's emergency order reflects the strict application of the Purcell principle, which discourages federal courts from altering state election rules immediately prior to voting to avoid administrative disruption. By honoring the state court's suspension of the law during an active ballot referendum, the order protects direct-democracy mechanisms against mid-decade legislative redraws. The ruling also stabilizes election logistics for local election administrators who were facing ballot re-printing deadlines.

Verified across 1 sources: LivePress

D.C. Circuit Court Upholds Pentagon Blacklisting of Anthropic Over Model Safety Guardrails

A split 2-1 panel of the D.C. Circuit Court of Appeals ruled on Friday, September 25, to uphold Defense Secretary Pete Hegseth's designation of Anthropic as a national security supply chain risk. Written by Judge Gregory Katsas, the opinion rejected Anthropic's retaliation claims, affirming broad executive discretion over defense procurement when model constraints are deemed operational risks. The decision conflicts with a separate ruling by U.S. District Judge Rita Lin in San Francisco that previously enjoined the ban under a different statute. Anthropic confirmed it is weighing an en banc appeal.

This appellate decision establishes a major precedent regarding how military agencies can treat commercial AI safety guardrails during defense procurement. The jurisdictional split between the D.C. Circuit and California federal courts creates regulatory friction for AI developers seeking government contracts while maintaining strict ethical or safety boundary policies. It signals that enforcing safety limits on defense-deployed models could be treated as a supply chain defect by military buyers.

Verified across 1 sources: Legal & RegTech Intelligence Brief

Working-Class Economy

Walmart Expands Debt-Free Career Pathways into Skilled Trucking, Tech, and Optician Roles

Walmart announced an expansion of its debt-free frontline worker upskilling initiatives on Saturday, September 26, scaling its 'Associate to Driver' and 'Associate to Technician' programs while launching a new 'Associate to Optician' pilot. The company pays hourly retail associates full wages while they earn commercial driver's licenses or technical certifications, placing commercial driving graduates into positions earning up to $115,000 in their first year. Executives noted the expansion addresses internal labor shortages in skilled trades while bypassing four-year degree requirements.

Employer-funded credentialing models provide a practical wage advancement mechanism for lower-wage hourly workers without incurring higher education debt. By linking structured skills training directly to guaranteed, high-wage internal placement, large enterprise employers are creating viable alternatives to traditional higher education. This shift underscores how corporate upskilling programs are reshaping blue-collar workforce development.

Verified across 1 sources: Fortune

Cybersecurity

Storm-3168 Cloud Attack Campaign Deletes Azure Resources via Compromised Service Principals

Microsoft detailed an intrusion campaign attributed to threat group Storm-3168 (JADEPUFFER) on Saturday, September 26, where attackers used two compromised Azure service principals to execute resource destruction across targeted tenants. Over a 15.5-hour reconnaissance window, the actors conducted over 300 read operations before systematically wiping resources across Azure Storage, SQL, Key Vault, and virtual machine services. Security research published alongside the report indicates that overprivileged non-human identities remain a widespread vulnerability across most enterprise cloud environments.

Control-plane destruction carried out through legitimate, overprivileged service principals circumvents traditional endpoint detection systems entirely. When automation credentials retain standing administrative permissions without scope limitations, a single exposed secret can result in complete cloud environment destruction. Defenders must enforce least-privilege access, mandate short-lived workload identity federation, and implement automated alerting for anomalous resource deletion calls.

Verified across 1 sources: TMCnet

EVs & Charging

CharIN Testival 2026 Highlights Interoperability Failures in ISO 15118-20 and High-Power Chargers

Industry engineering reports published from the CharIN Testival 2026 on Saturday, September 26, revealed persistent digital handshake and communication failures between electric vehicles and fast-charging hardware. Field testing at the event focused on high-power CCS configurations up to 720 kW and Megawatt Charging System (MCS) units reaching 1,000 kW for heavy-duty trucks. Engineers noted that implementing advanced ISO 15118-20 communication standards for bidirectional V2G and automated plug-and-charge frequently required multiple retry attempts to establish a stable charge session.

Initial communication handshake failures remain a leading cause of public fast-charging failure rates, undermining commercial EV adoption. As hardware output scales toward megawatt levels for commercial fleets, strict protocol adherence across diverse vehicle platforms becomes paramount. Charging site operators must enforce rigorous pre-market interoperability testing to prevent widespread network reliability issues.

Verified across 1 sources: electrive

New England Beat

MassDOT Approves $78.7M Contract for Mystic River Pedestrian Bridge Connecting Somerville and Everett

The Massachusetts Department of Transportation Board of Directors approved a $78.7 million contract on Saturday, September 26, to construct an 800-foot bicycle and pedestrian bridge across the Mystic River. The project will directly connect Assembly Row in Somerville to the Encore resort in Everett, linking into the Northern Strand Community Trail and accommodating future access for a proposed Kraft Group soccer stadium. Construction begins after local transit advocates successfully pushed state planners to expand the bridge's width and capacity.

This capital allocation resolves a longstanding multi-municipal transit bottleneck, creating non-vehicular connectivity across a major industrial water corridor. For regional planners and urban developers in Greater Boston, the project demonstrates how community transit advocacy can successfully alter state infrastructure designs to support higher pedestrian density. The bridge also integrates directly into broader land-use planning around the lower Mystic River basin.

Verified across 1 sources: The Boston Globe

Science & Space

Tel Aviv University Identifies Rare Cochlear Supporting Cells Capable of Hair Cell Transdifferentiation

In a study published in Science Advances on Saturday, September 26, researchers at Tel Aviv University identified a subpopulation of supporting Deiters' cells (tDCs) in the mammalian cochlea capable of converting into sensory hair cells. Using live imaging and single-cell multi-omics, the team demonstrated that inhibiting the Notch signaling pathway triggers these supporting cells to transdifferentiate into functional hair cells in newborn mouse tissue. The findings map the specific genetic and epigenetic profile required to induce auditory cellular regeneration.

Mammalian inner ear hair cells do not naturally regenerate, making sensorineural hearing loss irreversible once cells are damaged. Identifying a specific supporting cell subpopulation that retains transdifferentiation capacity provides a precise biological target for future gene and small-molecule therapies. While clinical applications remain years away, establishing this cellular blueprint advances inner ear regenerative medicine.

Verified across 1 sources: Hayadan

Consumer Tech Quirks

USB 3.0 Electromagnetic Bus Signaling Continues to Cause 2.4GHz Wi-Fi and Bluetooth Interference

Technical analysis published on Saturday, September 26, highlights ongoing wireless connectivity issues caused by broadband electromagnetic noise generated by USB 3.0 data transmission. Electrical signaling over USB 3.0 data lines emits noise within the 2.4 GHz to 2.5 GHz frequency spectrum, radiating from unshielded ports or cheap cables to disrupt nearby 2.4GHz Wi-Fi connections and Bluetooth peripherals. Effective mitigations include placing wireless receivers on extension cables away from active USB 3.0 ports or utilizing USB 2.0 headers for low-speed dongles.

Physical-layer radio frequency interference is frequently misdiagnosed as bad software drivers, OS bugs, or failing wireless hardware. For IT consultants and power users troubleshooting erratic peripheral lag or Wi-Fi drops near desktop hubs, recognizing bus-level RF radiation saves hours of unnecessary software reinstallations. It serves as a practical reminder of how high-speed wired standards can degrade unshielded wireless signals.

Verified across 1 sources: XDA-Developers


The Big Picture

Directory-Level Identity Enclosure Expands to Non-Human Workers As enterprise AI platforms move from session-based chat to persistent background execution, vendors are provisioning full directory principals with native Exchange, storage, and org-chart slots. Integrating AI agents into Microsoft Entra ID enforces unified DLP and conditional access, but creates a rapid expansion of non-human identities that require continuous privilege auditing.

Protocol Deserialization and Machine Credentials Drive Enterprise Risk Across both legacy on-premises web components and modern cloud automation, threat actors are bypassing perimeter defenses by abusing trusted execution vectors. From unescaped markup parsing in SharePoint to long-lived Azure service principal tokens, attackers are prioritizing administrative control-plane access over endpoint software exploits.

Emergency Judicial Orders Intervene in Pre-Election Rules Federal and state appellate dockets are delivering immediate, consequential adjustments to voting maps and regulatory frameworks as election deadlines approach. Applying principles like Purcell, high courts are actively blocking late-stage legislative map revisions while balancing state administrative burdens against federal database access.

Corporate Upskilling Programs Substitute for Higher Education Faced with persistent skilled labor shortages and rising higher education tuition, major enterprise employers are shifting investment into fully paid, debt-free credentialing pipelines. These programs target frontline workers for specialized technical and logistics roles, creating alternative economic mobility tracks outside traditional four-year degrees.

Hardware Interoperability and Physical Interference Pose Deployment Hurdles From handshake failures in high-power ISO 15118-20 EV charging protocols to physical-layer electromagnetic interference on 2.4GHz radio bands caused by USB 3.0 bus signaling, underlying physical constraints continue to degrade user experience despite mature software stacks.

What to Expect

2026-09-28 — CISA federal remediation deadline for SharePoint Server code injection vulnerability CVE-2026-65660.
2026-09-29 — VentureWell E-Team Program grant application deadline ($25,000 award).
2026-09-30 — Hard shutdown date for legacy Microsoft Project Online (PWA) interface and OData endpoints.
2026-10-01 — Retirement of legacy Microsoft Entra ID Protection user and sign-in risk policies in favor of Conditional Access.

Every story, researched.

Every story verified across multiple sources before publication.

🔍

Scanned

Across multiple search engines and news databases

332
📖

Read in full

Every article opened, read, and evaluated

106
⭐

Published today

Ranked by importance and verified across sources

11

— The Tenant Desk

🎙 Listen as a podcast

Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.

Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste
Overcast
+ button → Add URL → paste
Pocket Casts
Search bar → paste URL
Castro, AntennaPod, Podcast Addict, Castbox, Podverse, Fountain
Look for Add by URL or paste into search

Spotify isn’t supported yet — it only lists shows from its own directory. Let us know if you need it there.