Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
EWS retirement hits its final phase with a hard October 2026 deadline, Intune Suite advanced capabilities land in M365 E3/E5 by August 1, and three Entra ID legacy auth controls are heading for retirement — this week is heavy on deadlines and migration obligations.
CVE-2026-42897 demands immediate patch action on all on-prem Exchange deployments, while Teams Live Events hits its June 30 retirement deadline — but this week also delivers real capability unlocks across AI agent governance, Purview posture reporting, and Entra multi-tenant visibility.
Global Secure Access hits a GA trifecta this week with iOS client, cloud firewall for remote networks, and file-type content filtering all shipping. Pair that with Purview DLP sync dropping from 2 hours to 30 minutes and the Intune Data Warehouse v1 connector retirement, and there's real work to do.
Dirty Frag is being actively exploited on Linux endpoints. Storm-2949 proves credentials alone are enough to wipe a cloud environment. Know what needs action now.
Two hard June deadlines, hotpatch going default across all eligible devices, and Agent 365 is now the live control plane for AI governance. This week has teeth.