The Week at a Glance

  • 🔴 Critical Windows kernel vulnerability requires emergency patching - A confirmed privilege escalation flaw in Windows Secure Kernel Mode (CVE-2026-85921) allows an attacker already inside your network to gain full system control; patch all Windows endpoints now.
  • 🟡 AI-assisted invoice and executive impersonation fraud is escalating - Microsoft has documented a live campaign using AI to impersonate executives and fabricate invoices targeting finance teams; your wire-transfer and payment-approval controls need review within 30 days.
  • 🟡 Passkey-themed social engineering is enabling cloud account takeovers - Attackers are tricking employees into handing over authentication credentials by posing as IT support during passkey enrollment; this is an identity verification gap with real data-exposure consequences.
  • 🟢 New AI governance controls give IT more oversight of unsanctioned AI tools - Agent 365 now lets administrators detect, block, and isolate AI agents employees are running without approval, a meaningful step toward enterprise AI governance.

Sources: Microsoft Security Response Center · Microsoft Security Blog · Microsoft Security Blog - Passkey Social Engineering


Why This Week Matters

Attackers are simultaneously targeting the operating system layer, the human layer, and the authentication layer at once, which is exactly the threat pattern that exposes organizations with incomplete Zero Trust implementations. The Windows kernel vulnerability gives an insider or a compromised endpoint full system control, while the social engineering campaigns show that even modern authentication like passkeys can be undermined when employees are manipulated before the technology can protect them. Leadership’s single most important understanding this week: technology controls only work when they cover every layer, and right now the human-awareness layer is the one being actively exploited.

Sources: Microsoft Security Blog - AI-Themed Attacks · Microsoft Security Blog - Passkey Social Engineering


Risk & Compliance

  • 🔴 Windows Secure Kernel Mode Elevation of Privilege (CVE-2026-85921): A confirmed vulnerability allows an attacker with any existing foothold on a Windows device to seize full system control locally; this has direct implications for SOC 2, HIPAA, and CMMC patch-management requirements, and patching should begin immediately.

  • 🔴 AI-assisted executive impersonation and invoice fraud: An active campaign is using AI-generated impersonation of executives to push fraudulent ACH payment requests to finance teams; this is a financial crime risk with SOC 2 and cyber insurance implications, and your out-of-band payment verification procedures should be reviewed now.

  • 🔴 Passkey-themed social engineering enabling cloud compromise: Attackers are convincing employees to hand over authentication during fake IT enrollment flows, then establishing persistent MFA access and raiding SharePoint, OneDrive, and email; this exploits an implicit-trust gap in the enrollment process and affects any organization rolling out passkeys, with relevance to HIPAA, SOC 2, and CMMC identity controls.

  • 🟡 September 2026 Exchange Server Security Updates: Organizations running on-premises Exchange Server (2016, 2019, or Subscription Edition) must apply this month’s security patches; Exchange 2016 and 2019 require active enrollment in the Period 2 Extended Security Update program to receive them, which is a compliance exposure if not already in place.

  • 🟡 Fourteen Microsoft Edge and Chromium browser vulnerabilities patched: This week’s batch includes memory corruption, unauthorized file system access, and information-leak flaws in the browser your employees use every day; organizations that do not auto-update Edge are exposed until patches are manually deployed, relevant to SOC 2 and cyber insurance patch-currency requirements.

  • 🟡 Endpoint DLP extended to previously excluded Windows folders: Microsoft Purview’s data loss prevention will begin monitoring Temp and AppData folders, areas that today are invisible to your DLP policies, arriving in December; compliance and legal teams should confirm whether current DLP policy scope aligns with HIPAA, GDPR, or state privacy law obligations before the change takes effect.

  • 🟢 Defender for Identity sensor now deployable without Defender for Endpoint (Preview): Domain controllers running Windows Server 2019 or later can now receive identity threat monitoring without a full Defender for Endpoint rollout first; this closes an implicit-trust gap on domain controllers that were previously unmonitored, with no immediate compliance deadline but meaningful Zero Trust maturity progress.

  • 🟢 Teams: Report suspicious guest invitations (November 2026): Employees will soon be able to flag unexpected or suspicious Teams guest invitations directly to IT, improving early warning for phishing and guest-abuse scenarios; awareness-only for now, with no action required before the November rollout.

Sources: Microsoft Security Response Center · Exchange Team Blog · M365 Roadmap


What Your Employees Will Notice

  • Copilot appears in a new, consistent location in classic Outlook for Windows - The Copilot entry point is moving to a single anchored location above the work surface, matching what is already visible in Word, Excel, and PowerPoint. Employees who rely on muscle memory for where to find Copilot in Outlook will notice the change immediately; a short heads-up from IT or their manager will reduce friction.
  • Copilot Notebooks on iOS now retain context between sessions - Employees using the Microsoft 365 Copilot app on iPhone can now organize AI conversations into persistent notebooks, meaning AI responses build on prior work instead of starting fresh each time. This is a meaningful workflow improvement for anyone who uses Copilot regularly on mobile.
  • Annotating sensitivity-labeled PDFs on mobile is now fully supported - Employees working with protected PDFs on iOS or Android can now add highlights, signatures, and other annotations without losing the document’s security label. Previously, annotating a protected PDF often required removing or weakening the label; that workaround is no longer necessary.
  • Planner tasks will be manageable inside Microsoft Cowork (October) - Employees will be able to view, create, and update Planner tasks from within Cowork without switching applications, with Cowork able to draft emails, schedule meetings, and post Teams updates on their behalf before writing progress back to Planner.
  • SharePoint page editing with Copilot now works by clicking and describing - Authors building or updating SharePoint intranet pages can click directly on a section and tell Copilot what to change, instead of describing both the content and its location in text. Expect communications and HR teams who manage SharePoint pages to notice and appreciate this change.

Sources: M365 Roadmap - Copilot in Classic Outlook · M365 Roadmap - Copilot Notebooks iOS · SharePoint Blog


What Your Help Desk Should Expect

  • Patching questions and reboot coordination for the Windows kernel vulnerability - IT teams applying CVE-2026-85921 patches will likely generate reboot cycles on managed endpoints; employees whose devices restart unexpectedly may contact the help desk. Volume will depend on your patch deployment speed.
  • “Where did Copilot go in Outlook?” calls - The new Copilot entry point in classic Outlook will be visible to all users when it rolls out. Employees accustomed to finding Copilot in a different location will generate orientation questions; a brief communication ahead of the change will reduce ticket volume significantly.
  • Questions about suspicious Teams guest invitation pop-ups (November) - When the new guest-invitation reporting feature arrives in November, some employees will encounter the report option and ask IT what it does or whether they should use it. Prepare a short FAQ now.
  • Exchange Server patch-related support if on-premises Exchange is in your environment - Applying the September security updates to on-premises Exchange requires planned maintenance windows; administrators should expect some mail-flow or client-connectivity questions during and after the update.
  • Passkey enrollment confusion if a security awareness campaign is launched - If your organization responds to the passkey social engineering threat with a training communication, expect employees to call in with questions about legitimate enrollment procedures. Help desk staff should be briefed on what the real IT-initiated passkey enrollment process looks like.

Sources: Microsoft Security Response Center · Exchange Team Blog · M365 Roadmap - Teams Guest Invitations


Cost & Licensing

  • Exchange Server 2016 and 2019 security patches now require ESU program enrollment - Organizations still running these older Exchange versions must be actively enrolled in Microsoft’s Period 2 Extended Security Update program to receive this month’s patches. If your organization is not enrolled, you are both unpatched and incurring an unbudgeted enrollment cost to remedy that. Finance and IT leadership should confirm enrollment status and associated fees this week.
  • Teams Rooms organizer-name privacy control requires Pro or Shared Space license - The new option to hide organizer names on Teams Panels calendar views is available only with Teams Rooms Pro or Teams Shared Space licenses. Organizations on basic Teams Rooms licenses will not have access to this control; if it is relevant to your meeting-room privacy policy, factor the license tier into planning.
  • Agent 365 AI governance controls are available now for managed-device environments - Blocking and isolating unsanctioned AI agents through Agent 365 is built on Intune policy enforcement. Organizations already licensed for Intune can begin using these controls without additional spend; organizations without Intune should factor that into their AI governance planning if shadow AI is a concern.

Sources: Exchange Team Blog · M365 Roadmap - Teams Panels · Microsoft Mechanics - Agent 365


Planning Horizon

Immediate (this week):

  • Immediate - Windows Secure Kernel Mode Elevation of Privilege (CVE-2026-85921): Authorize emergency patch deployment across all Windows endpoints; confirm with your IT or security team that patching has begun and a completion deadline is set.
  • Immediate - September 2026 Exchange Server Security Updates: If your organization runs on-premises Exchange Server, schedule the maintenance window for applying this month’s security update this week, and verify ESU program enrollment for Exchange 2016 or 2019.
  • Immediate - AI-assisted invoice fraud campaign: Brief your CFO and finance leadership on the active AI-impersonation invoice fraud campaign and confirm that out-of-band verbal verification is required for all wire transfers and payment-instruction changes above a defined threshold.

Within 30 days:

  • Within 30 days - Passkey social engineering threat briefing: Commission a targeted security awareness communication explaining what legitimate passkey and MFA enrollment looks like from IT, so employees can recognize and report fake enrollment attempts.
  • Within 30 days - Shadow AI governance with Agent 365: Decide whether to activate Agent 365 controls to inventory and selectively block unsanctioned AI tools running on managed devices; this decision requires alignment between IT, legal, and business leadership on acceptable AI use policy.
  • Within 30 days - Fourteen Microsoft Edge browser vulnerabilities patched: Confirm with IT that Edge auto-update is enforced across all managed devices; if manual deployment is required anywhere in the environment, schedule it now.
  • Within 30 days - NTLM retirement preparation: Ask IT to report on which systems and applications still depend on NTLM authentication; Windows is moving toward a Kerberos-first model, and organizations with legacy application dependencies need a migration timeline to avoid future access failures.
  • Within 30 days - Windows activation automation migration from VBScript to PowerShell: Ask IT whether any Windows activation scripts depend on the legacy VBScript method (slmgr.vbs); if so, migration planning should begin before VBScript is removed from future Windows versions.

Before December 2026:

  • Before December 2026 - Endpoint DLP coverage expanding to previously excluded Windows folders: Ask your compliance or legal team to review whether existing DLP policies need to be updated before this change takes effect, particularly for HIPAA, GDPR, or state privacy law obligations that require comprehensive sensitive-data coverage.
  • Before December 2026 - Scoped Just-in-Time Audit for Endpoint DLP: If your organization uses Purview Endpoint DLP, plan to review and configure which users or groups are in scope for just-in-time audit before the December release, to avoid generating excessive or misdirected audit output.

Sources: Microsoft Security Response Center · M365 Roadmap · Windows IT Pro Blog - NTLM


If You Take No Action

On the Windows kernel vulnerability (CVE-2026-85921): Any attacker who gains even limited access to a Windows device in your environment, whether through phishing, a compromised credential, or a lateral movement technique, can immediately escalate to full system control. This is the precise scenario that turns a contained security incident into an organization-wide breach. Delayed patching increases your exposure window and may trigger cyber insurance notification obligations if an incident occurs during that window.

On the AI-assisted invoice fraud campaign: Finance teams operating under current email-only payment approval workflows are a direct target of this campaign. A single successful impersonation can result in a fraudulent wire transfer that is difficult or impossible to reverse. Without updated out-of-band verification procedures, the control gap is open today.

On the passkey social engineering threat: If employees are not briefed on what legitimate IT-initiated authentication enrollment looks like, they remain susceptible to handing over credentials to attackers posing as IT support. Successful compromise gives attackers persistent access to SharePoint, OneDrive, and email, with potential exposure of regulated data under HIPAA, SOC 2, or state privacy laws and the associated breach notification obligations that follow.

Sources: Microsoft Security Response Center · Microsoft Security Blog - Invoice Fraud · Microsoft Security Blog - Passkey Social Engineering