Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
Entra Tenant Governance surfaces shadow tenants, Purview DSPM for AI hits GA, and computer-using agents in Copilot Studio are production-ready — a feature-dense week with meaningful capability unlocks across identity, data, and automation.
Teams Live Events dies June 30 — migrate now. Exchange Server OWA has an active XSS CVE. Meanwhile, Purview ships posture reporting, Copilot Studio goes fully agentic with computer-use GA, and Entra tackles shadow tenant sprawl.
CVE-2026-42897 demands immediate patch action on all on-prem Exchange deployments, while Teams Live Events hits its June 30 retirement deadline — but this week also delivers real capability unlocks across AI agent governance, Purview posture reporting, and Entra multi-tenant visibility.
Global Secure Access hits a GA trifecta this week with iOS client, cloud firewall for remote networks, and file-type content filtering all shipping. Pair that with Purview DLP sync dropping from 2 hours to 30 minutes and the Intune Data Warehouse v1 connector retirement, and there's real work to do.
Dirty Frag is being actively exploited on Linux endpoints. Storm-2949 proves credentials alone are enough to wipe a cloud environment. Know what needs action now.
Two hard June deadlines, hotpatch going default across all eligible devices, and Agent 365 is now the live control plane for AI governance. This week has teeth.